This bug was fixed in the package vim - 2:9.1.0016-1ubuntu7.19

---------------
vim (2:9.1.0016-1ubuntu7.19) noble-security; urgency=medium

  * SECURITY REGRESSION: Incomplete fix for CVE-2026-28417 (LP: #2163785)
    - debian/patches/CVE-2026-28417-pre1.patch: Add NetrwValidateHostname in
      runtime/autoload/netrw.vim
    - debian/patches/CVE-2026-28417.patch: Add fixes to NetrwValidateHostname
      in runtime/autoload/netrw.vim
  * SECURITY UPDATE: Use-after-free on json decode error.
    - debian/patches/CVE-2026-73071.patch: Report the position from the
      current reader in src/json.c.
    - CVE-2026-73071
  * SECURITY UPDATE: Heap buffer overflow in set_sofo().
    - debian/patches/CVE-2026-73072.patch: Reset sl_sal_first in
      src/spellfile.c.
    - CVE-2026-73072
  * SECURITY UPDATE: Heap overflow when adding > 65535 text properties.
    - debian/patches/CVE-2026-73074.patch: Verify that the number of text
      properties falls within the limit in src/errors.h and src/textprop.c.
    - CVE-2026-73074
  * SECURITY UPDATE: Code execution via VimballRecord file.
    - debian/patches/CVE-2026-73076.patch: Forbid arbitrary commands, fix
      broken directory deletion code, and refactor code in
      runtime/autoload/vimball.vim
    - CVE-2026-73076
  * SECURITY UPDATE: Arbitrary code execution via keyword lookup.
    - debian/patches/CVE-2026-73077.patch: For powershell, quote the commands
      using single quotes, for sh/zsh pass the argument as a separate list
      item to term_start()/system() in runtime/ftplugin/ps1.vim, ../sh.vim,
      and ../zsh.vim.
    - CVE-2026-73077
  * SECURITY UPDATE: Code injection in netrw via bookmarks.
    - debian/patches/CVE-2026-73078.patch: Escape the '|' explicitly in
      runtime/autoload/netrw.vim.
    - CVE-2026-73078

 -- Kyle Kernick <[email protected]>  Tue, 18 Aug 2026 14:09:09
-0600

** Changed in: vim (Ubuntu)
       Status: In Progress => Fix Released

** CVE added: https://cve.org/CVERecord?id=CVE-2026-73071

** CVE added: https://cve.org/CVERecord?id=CVE-2026-73072

** CVE added: https://cve.org/CVERecord?id=CVE-2026-73074

** CVE added: https://cve.org/CVERecord?id=CVE-2026-73076

** CVE added: https://cve.org/CVERecord?id=CVE-2026-73077

** CVE added: https://cve.org/CVERecord?id=CVE-2026-73078

** Changed in: vim (Ubuntu)
       Status: In Progress => Fix Released

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163785

Title:
  Fix for CVE-2026-28417 is incomplete

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/vim/+bug/2163785/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to