Hi everyone,
For vim/trixie, I coordinated with the Vim maintainer and fixed the following
CVEs:
- CVE-2026-41411
- CVE-2026-42307
- CVE-2026-43961
- CVE-2026-44656
- CVE-2026-45130
- CVE-2026-46483
- CVE-2026-47162
- CVE-2026-47167
- CVE-2026-52858
- CVE-2026-52859
- CVE-2026-52860
- CVE-2026-55693
- CVE-2026-55892
- CVE-2026-55895
- CVE-2026-57452
- CVE-2026-57455
- CVE-2026-57456
- CVE-2026-59856
- CVE-2026-59857
- CVE-2026-59858
I also confirmed that CVE-2026-57451 and CVE-2026-57453 do not affect the
version of vim in trixie.
The final package draft is available at
https://salsa.debian.org/lgarrett/vim/-/tree/debian/trixie and has been sent to
the vim maintainer for review.
Thanks to our sponsors for making this work possible, and to Freexian for
coordinating these efforts!
Regards,
Lee Garrett,
Debian LTS Team