[ubuntu/resolute-proposed] vim 2:9.1.2141-1ubuntu3 (Accepted)

Hlib Korzhynskyy hlib.korzhynskyy at canonical.com
Tue Apr 14 07:40:44 UTC 2026


vim (2:9.1.2141-1ubuntu3) resolute; urgency=medium

  * SECURITY UPDATE: NULL pointer dereference in the NFA regex engine.
    - debian/patches/CVE-2026-32249.patch: Add range_endpoint and if checks
      in src/regexp_nfa.c. Add tests in src/testdir/test_regexp_utf8.vim.
    - CVE-2026-32249
  * SECURITY UPDATE: Command injection in glob.
    - debian/patches/CVE-2026-33412.patch: Add newline to SHELL_SPECIAL in
      src/os_unix.c.
    - CVE-2026-33412
  * SECURITY UPDATE: Command injection in tabpanel.
    - debian/patches/CVE-2026-34714.patch: Add check_restricted check_secure
      if check in src/autocmd.c. Add P_MLE in src/optiondefs.h. Add tests in
      src/testdir/test_autocmd.vim and src/testdir/test_tabpanel.vim.
    - CVE-2026-34714
  * SECURITY UPDATE: Command injection in modeline.
    - debian/patches/CVE-2026-34982.patch: Add check_secure in src/map.c. Add
      P_MLE in src/optiondefs.h. Add tests in src/testdir/test_modeline.vim.
    - debian/patches/CVE-2026-34982-post1.patch: Remove failing test and add
      more s:modeline_fails in src/testdir/test_modeline.vim.
    - CVE-2026-34982

Date: Tue, 31 Mar 2026 16:50:02 -0230
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Signed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/vim/2:9.1.2141-1ubuntu3
-------------- next part --------------
Format: 1.8
Date: Tue, 31 Mar 2026 16:50:02 -0230
Source: vim
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 2:9.1.2141-1ubuntu3
Distribution: resolute
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
Changes:
 vim (2:9.1.2141-1ubuntu3) resolute; urgency=medium
 .
   * SECURITY UPDATE: NULL pointer dereference in the NFA regex engine.
     - debian/patches/CVE-2026-32249.patch: Add range_endpoint and if checks
       in src/regexp_nfa.c. Add tests in src/testdir/test_regexp_utf8.vim.
     - CVE-2026-32249
   * SECURITY UPDATE: Command injection in glob.
     - debian/patches/CVE-2026-33412.patch: Add newline to SHELL_SPECIAL in
       src/os_unix.c.
     - CVE-2026-33412
   * SECURITY UPDATE: Command injection in tabpanel.
     - debian/patches/CVE-2026-34714.patch: Add check_restricted check_secure
       if check in src/autocmd.c. Add P_MLE in src/optiondefs.h. Add tests in
       src/testdir/test_autocmd.vim and src/testdir/test_tabpanel.vim.
     - CVE-2026-34714
   * SECURITY UPDATE: Command injection in modeline.
     - debian/patches/CVE-2026-34982.patch: Add check_secure in src/map.c. Add
       P_MLE in src/optiondefs.h. Add tests in src/testdir/test_modeline.vim.
     - debian/patches/CVE-2026-34982-post1.patch: Remove failing test and add
       more s:modeline_fails in src/testdir/test_modeline.vim.
     - CVE-2026-34982
Checksums-Sha1:
 8cadbb0fc340fff48dcfbd923c575feefe67cb2c 3037 vim_9.1.2141-1ubuntu3.dsc
 6b03f2aa83c3484976f08a95e94720b420927641 218476 vim_9.1.2141-1ubuntu3.debian.tar.xz
 4e9c5370dafba960080b141acdee661cb4dc9fe3 17380 vim_9.1.2141-1ubuntu3_source.buildinfo
Checksums-Sha256:
 21b7e9cb8c017545b369f43ccdff588d9c925b949badbcb292e969c9fe7f6e80 3037 vim_9.1.2141-1ubuntu3.dsc
 5373ccad9744cbb59818b644ea6ba766ebc7b19eb5ea02ea58c3cd8e157983c7 218476 vim_9.1.2141-1ubuntu3.debian.tar.xz
 9eb1b59e1d3801b2cadb0271cd9abec64549402a2671fbd0582f3df1c6b1e6e9 17380 vim_9.1.2141-1ubuntu3_source.buildinfo
Files:
 4f193466d749e41a2e0894ae5e56f3bc 3037 editors optional vim_9.1.2141-1ubuntu3.dsc
 149aeb55db1bfde98e0e4e1955eb0b71 218476 editors optional vim_9.1.2141-1ubuntu3.debian.tar.xz
 f727ed46f81eef1facaacfc278fcd1b7 17380 editors optional vim_9.1.2141-1ubuntu3_source.buildinfo
Original-Maintainer: Debian Vim Maintainers <team+vim at tracker.debian.org>


More information about the Resolute-changes mailing list