stable

vim-9.2.148-1.fc42

FEDORA-2026-1885157e34 created by zdohnal 4 months ago for Fedora 42

patchlevel 148


Security fixes for CVE-2026-28417, CVE-2026-28418, CVE-2026-28419, CVE-2026-28420, CVE-2026-28421, CVE-2026-28422


Security fix for CVE-2026-32249

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-1885157e34

This update has been submitted for testing by zdohnal.

4 months ago

This update's test gating status has been changed to 'waiting'.

4 months ago

This update's test gating status has been changed to 'waiting'.

4 months ago

This update has obsoleted vim-9.2.112-2.fc42, and has inherited its bugs and notes.

4 months ago

This update's test gating status has been changed to 'failed'.

4 months ago

This update has been pushed to testing.

4 months ago
karma

This update's test gating status has been changed to 'waiting'.

4 months ago

This update's test gating status has been changed to 'passed'.

4 months ago

zdohnal edited this update.

4 months ago
User Icon gilwooden provided feedback 4 months ago
karma

This update can be pushed to stable now if the maintainer wishes

4 months ago
User Icon filiperosset commented & provided feedback 4 months ago
karma

no regresions noted

This update has been submitted for stable by bodhi.

4 months ago

This update has been pushed to stable.

4 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
3
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
4 months ago
in testing
4 months ago
in stable
4 months ago
modified
4 months ago
approved
4 months ago
BZ#2443455 CVE-2026-28417 vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin
0
0
BZ#2443474 CVE-2026-28421 vim: Vim: Denial of service and information disclosure via crafted swap file
0
0
BZ#2443475 CVE-2026-28422 vim: Vim: Integrity impact due to stack-buffer-overflow via wide terminal statusline rendering
0
0
BZ#2443481 CVE-2026-28418 vim: Vim: Information disclosure via heap-based buffer overflow in Emacs-style tags file parsing
0
0
BZ#2443482 CVE-2026-28419 vim: Vim: Information disclosure and denial of service via malformed tags file
0
0
BZ#2443484 CVE-2026-28420 vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator
0
0
BZ#2443790 CVE-2026-28417 CVE-2026-28418 CVE-2026-28419 CVE-2026-28420 CVE-2026-28421 CVE-2026-28422 vim: various flaws [fedora-all]
0
0
BZ#2447110 CVE-2026-32249 vim: NFA regex engine NULL pointer dereference
0
0
BZ#2447359 CVE-2026-32249 vim: NFA regex engine NULL pointer dereference [fedora-all]
0
0

Automated Test Results