安全公告详情

NS-SA-2026-0010

2026-03-04 16:02:48

简介

important: vim/lvm2 security update

严重级别

important

主题

An update for vim/lvm2 is now available for NewStart CGSL MAIN 6.06.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

vim:
lvm2:


Security Fix(es):
vim: It was found that the `:source!` command was not restricted by the sandbox mode. If modeline was explicitly enabled, opening a specially crafted text file in vim could result in arbitrary command execution.(CVE-2019-12735)
vim: bugfix
lvm2: The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.(CVE-2010-2526)
lvm2: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 6.06.01B6.

影响组件

  • vim
  • lvm2

影响产品

  • CGSL MAIN 6.06 (SP)

更新包

{"fix":[{"product":"CGSL MAIN 6.06 (SP)","pkgs":[{"binary":["vim-common-8.0.1763-19.0.1.zncgsl6_6.4.x86_64.rpm","vim-enhanced-8.0.1763-19.0.1.zncgsl6_6.4.x86_64.rpm","vim-filesystem-8.0.1763-19.0.1.zncgsl6_6.4.noarch.rpm","vim-minimal-8.0.1763-19.0.1.zncgsl6_6.4.x86_64.rpm"],"source":"vim-8.0.1763-19.0.1.zncgsl6_6.4.src.rpm"},{"binary":["device-mapper-1.02.181-3.0.1.zncgsl6_6.2.t2.0.x86_64.rpm","device-mapper-event-1.02.181-3.0.1.zncgsl6_6.2.t2.0.x86_64.rpm","device-mapper-event-libs-1.02.181-3.0.1.zncgsl6_6.2.t2.0.x86_64.rpm","device-mapper-libs-1.02.181-3.0.1.zncgsl6_6.2.t2.0.x86_64.rpm","lvm2-2.03.14-3.0.1.zncgsl6_6.2.t2.0.x86_64.rpm","lvm2-libs-2.03.14-3.0.1.zncgsl6_6.2.t2.0.x86_64.rpm"],"source":"lvm2-2.03.14-3.0.1.zncgsl6_6.2.t2.0.src.rpm"}]}]}

CVE

参考