This bug was fixed in the package vim - 2:8.2.3995-1ubuntu2.35
---------------
vim (2:8.2.3995-1ubuntu2.35) jammy-security; urgency=medium
* SECURITY REGRESSION: Incomplete fix for CVE-2026-28417 (LP: #2163785)
- debian/patches/CVE-2026-28417-pre1.patch: Add NetrwValidateHostname in
runtime/autoload/netrw.vim
- debian/patches/CVE-2026-28417.patch: Add fixes to NetrwValidateHostname
in runtime/autoload/netrw.vim
* SECURITY UPDATE: Use-after-free on json decode error.
- debian/patches/CVE-2026-73071.patch: Report the position from the
current reader in src/json.c.
- CVE-2026-73071
* SECURITY UPDATE: Heap buffer overflow in set_sofo().
- debian/patches/CVE-2026-73072.patch: Reset sl_sal_first in
src/spellfile.c.
- CVE-2026-73072
* SECURITY UPDATE: Heap overflow when adding > 65535 text properties.
- debian/patches/CVE-2026-73074.patch: Verify that the number of text
properties falls within the limit in src/errors.h and src/textprop.c.
- CVE-2026-73074
* SECURITY UPDATE: Code execution via VimballRecord file.
- debian/patches/CVE-2026-73076.patch: Forbid arbitrary commands, fix
broken directory deletion code, and refactor code in
runtime/autoload/vimball.vim
- CVE-2026-73076
* SECURITY UPDATE: Arbitrary code execution via keyword lookup.
- debian/patches/CVE-2026-73077.patch: For powershell, quote the commands
using single quotes, for zsh pass the argument as a separate list
item to term_start()/system() in runtime/ftplugin/ps1.vim and
../zsh.vim.
- CVE-2026-73077
* SECURITY UPDATE: Code injection in netrw via bookmarks.
- debian/patches/CVE-2026-73078.patch: Escape the '|' explicitly in
runtime/autoload/netrw.vim.
- CVE-2026-73078
-- Kyle Kernick <[email protected]> Tue, 18 Aug 2026 15:47:19
-0600
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163785
Title:
Fix for CVE-2026-28417 is incomplete
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/vim/+bug/2163785/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs