[CLSA-2026:1779912818] Fix CVE(s): CVE-2026-42307
Type:
security
Severity:
Low
Release date:
2026-05-27 20:13:49 UTC
Description:
* SECURITY UPDATE: OS command injection in the netrw plugin via crafted sftp:// or file:// URLs - debian/patches/CVE-2026-42307.patch: OS command injection in the netrw plugin via crafted sftp:// or file:// URLs - CVE-2026-42307
Updated packages:
  • vim_8.1.0875-5+deb10u6+tuxcare.els19_amd64.deb
    sha:f473cf20bc5da294e3684b901490fe426fa8de27
  • vim-athena_8.1.0875-5+deb10u6+tuxcare.els19_amd64.deb
    sha:f43cd59d47b9999f620951fb58fb5baf0567487a
  • vim-common_8.1.0875-5+deb10u6+tuxcare.els19_all.deb
    sha:4784e8d4c8ddb82c62ff593813d599612dd112dc
  • vim-doc_8.1.0875-5+deb10u6+tuxcare.els19_all.deb
    sha:593fa79018698c47548aa6c58c411318a1c17a76
  • vim-gtk_8.1.0875-5+deb10u6+tuxcare.els19_amd64.deb
    sha:e94c1000bbb00caff8f300d121d577ee33131020
  • vim-gtk3_8.1.0875-5+deb10u6+tuxcare.els19_amd64.deb
    sha:1f4f3025446f4d90bddcb1f828b5c8a5adbb329b
  • vim-gui-common_8.1.0875-5+deb10u6+tuxcare.els19_all.deb
    sha:10ffe3c3f69ef6c8db71b612e605897c56f8e424
  • vim-nox_8.1.0875-5+deb10u6+tuxcare.els19_amd64.deb
    sha:0f514cda037985ca83e2a29ff5bfe4f9ed490930
  • vim-runtime_8.1.0875-5+deb10u6+tuxcare.els19_all.deb
    sha:177aa1cdfae646a284c46450fcfb0b238b2aaa5f
  • vim-tiny_8.1.0875-5+deb10u6+tuxcare.els19_amd64.deb
    sha:ce6db427490cccca18864d58a3d81c5565d9a712
  • xxd_8.1.0875-5+deb10u6+tuxcare.els19_amd64.deb
    sha:fa631ef539b82cd965481ba11364f6f6d247532a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.