new file mode 100644
@@ -0,0 +1,89 @@
+From 2f628d8104958fa7421664f792ca6d4f7a39a10f Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Fri, 17 Jul 2026 09:11:42 +0900
+Subject: [PATCH] patch 9.2.0845: [security]: arbitrary Ex command execution
+ during C omni-completion
+
+Problem: [security]: arbitrary Ex command execution during C
+ omni-completion (Threonine)
+Solution: Match tags typeref literally to block Ex command injection
+ (Yasuhiro Matsumoto).
+
+Escaping only "/" and "\" left the typeref able to break out of the
+:vimgrep pattern without a "/": an unclosed "[" makes vimgrep's pattern
+skipping fail, and the parser then treats a following "|" as a command
+separator, so the tag value runs as Ex commands during C omni-completion.
+Match the field literally with \V so no regex metacharacter can affect
+pattern parsing.
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-cx73-phcg-3j5g
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+CVE: CVE-2026-73073
+Upstream-Status: Backport [https://github.com/vim/vim/commit/2f628d8104958fa7421664f792ca6d4f7a39a10f]
+Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+---
+ runtime/autoload/ccomplete.vim | 5 ++++-
+ src/testdir/test_plugin_ccomplete.vim | 26 ++++++++++++++++++++++++++
+ 2 files changed, 30 insertions(+), 1 deletion(-)
+
+diff --git a/runtime/autoload/ccomplete.vim b/runtime/autoload/ccomplete.vim
+index 248d6f2e60..5a48581dcf 100644
+--- a/runtime/autoload/ccomplete.vim
++++ b/runtime/autoload/ccomplete.vim
+@@ -592,8 +592,11 @@ def StructMembers( # {{{1
+ if complete_check()
+ return []
+ endif
++ # Match "typename" literally (\V): escaping alone is not enough, as e.g.
++ # an unclosed "[" makes vimgrep's pattern skipping fail and the rest of
++ # the tag value is then parsed as Ex commands.
+ execute 'silent! keepjumps noautocmd '
+- .. n .. 'vimgrep ' .. '/\t' .. escape(typename, '/\') .. '\(\t\|$\)/j '
++ .. n .. 'vimgrep ' .. '/\t\V' .. escape(typename, '/\') .. '\m\(\t\|$\)/j '
+ .. fnames
+
+ qflist = getqflist()
+diff --git a/src/testdir/test_plugin_ccomplete.vim b/src/testdir/test_plugin_ccomplete.vim
+index a635bd50bd..c1754d17c1 100644
+--- a/src/testdir/test_plugin_ccomplete.vim
++++ b/src/testdir/test_plugin_ccomplete.vim
+@@ -31,6 +31,32 @@ func Test_ccomplete_no_exec_via_typeref()
+ unlet! g:ccomplete_injected
+ endfunc
+
++" Escaping "/" and "\" is not enough: with no "/" in the payload, an unclosed
++" "[" makes vimgrep's pattern skipping fail, and the command parser then treats
++" the first "|" as a command separator. The typeref must be matched literally.
++func Test_ccomplete_no_exec_via_typeref_bracket()
++ CheckUnix
++ let sentinel = tempname()
++ call delete(sentinel)
++ let tagsfile = s:WriteTags([
++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:struct:[|call system('touch " .. sentinel .. "')|####",
++ \ ])
++
++ let save_tags = &tags
++ let &tags = tagsfile
++
++ new
++ call ccomplete#Complete(1, '')
++ call ccomplete#Complete(0, 'myvar.x')
++
++ call assert_false(filereadable(sentinel),
++ \ 'typeref field was executed as an Ex command during omni-completion')
++
++ bwipe!
++ let &tags = save_tags
++ call delete(sentinel)
++endfunc
++
+ " A legitimate typeref must still drive struct-member completion: escaping the
+ " field value must not break the normal path.
+ func Test_ccomplete_typeref_completion_still_works()
+--
+2.50.1
+
@@ -52,6 +52,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \
file://CVE-2026-59857.patch \
file://CVE-2026-59858.patch \
file://CVE-2026-73072.patch \
+ file://CVE-2026-73073.patch \
"
PV .= ".1683"
Pick the patch from [1], also referenced in the NVD report [2]. [1] https://github.com/vim/vim/commit/2f628d8104958fa7421664f792ca6d4f7a39a10f [2] https://nvd.nist.gov/vuln/detail/CVE-2026-73073 Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com> --- .../vim/files/CVE-2026-73073.patch | 89 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 90 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-73073.patch