new file mode 100644
@@ -0,0 +1,128 @@
+From f09adcf1b1a876e8a9b00a7b3ea15865ff194aad Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Thu, 16 Jul 2026 18:39:24 +0900
+Subject: [PATCH] patch 9.2.0844: [security]: use-after-free on json decode
+ error
+
+Problem: [security]: use-after-free on json decode error
+ (@tdjackey)
+Solution: Report the position from the current reader
+ (Matsumoto Yasuhiro)
+
+json_decode_item() caches "p" into js_buf, but json_decode_string() can
+refill via channel_fill(), which frees the old js_buf. When the string
+parse then fails (e.g. an invalid \u escape), the shared error path passed
+the now-dangling "p" to semsg(), a heap use-after-free read reachable
+pre-auth through the socketserver.
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-69ch-22ch-r887
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/f8126294a526aa80c5123eb3079e325daee9ec75]
+CVE: CVE-2026-73071
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ src/json.c | 4 ++-
+ src/testdir/test_clientserver.vim | 53 +++++++++++++++++++++++++++++++
+ src/version.c | 2 ++
+ 3 files changed, 58 insertions(+), 1 deletion(-)
+
+diff --git a/src/json.c b/src/json.c
+index b0d98a290..340347e42 100644
+--- a/src/json.c
++++ b/src/json.c
+@@ -1420,7 +1420,9 @@ item_end:
+ res->v_type = VAR_SPECIAL;
+ res->vval.v_number = VVAL_NONE;
+ }
+- semsg(_(e_json_decode_error_at_str), p);
++ // "p" may dangle into a buffer freed by a js_fill() refill in
++ // json_decode_string(); report the position from the current reader.
++ semsg(_(e_json_decode_error_at_str), reader->js_buf + reader->js_used);
+
+ theend:
+ for (i = 0; i < stack.ga_len; i++)
+diff --git a/src/testdir/test_clientserver.vim b/src/testdir/test_clientserver.vim
+index 8aa9428f2..148e46910 100644
+--- a/src/testdir/test_clientserver.vim
++++ b/src/testdir/test_clientserver.vim
+@@ -360,6 +360,59 @@ func Test_client_socket_server_custom_path()
+ endfor
+ endfunc
+
++" An invalid JSON message that spans two socketserver read buffers must not
++" crash the server: the parse buffer is refilled (and freed) mid-string, and
++" the error path must not report the position from the stale, freed cursor.
++func Test_client_server_socketserver_json_refill()
++ CheckFeature socketserver
++ CheckNotMSWindows
++
++ let g:test_is_flaky = 1
++ let cmd = GetVimCommand()
++ if cmd == ''
++ throw 'GetVimCommand() failed'
++ endif
++
++ let actual = cmd .. ' --clientserver socket --servername channel:2002'
++ let job = job_start(actual, {'stoponexit': 'kill', 'out_io': 'null'})
++ call WaitForAssert({-> assert_equal("run", job_status(job))})
++ call WaitForAssert({-> assert_match('channel:2002',
++ \ system(actual .. ' --remote-expr "v:servername"'))})
++
++ let ch = test_null_channel()
++ for _ in range(50)
++ let ch = ch_open('127.0.0.1:2002', {'mode': 'raw', 'waittime': 100})
++ if ch_status(ch) == 'open'
++ break
++ endif
++ sleep 100m
++ endfor
++ call assert_equal('open', ch_status(ch))
++
++ " The server reads at most MAXMSGSIZE (4096) bytes per read, so a single
++ " message longer than that is split across two read buffers. Keep the JSON
++ " string open past the split to force a refill (which frees the first
++ " buffer), then end in an invalid \u escape so the parse fails.
++ call ch_sendraw(ch, '{"k":"' .. repeat('A', 4200) .. '\uZZZZ')
++ sleep 500m
++
++ " The server must survive the invalid message and stay responsive.
++ call assert_equal("run", job_status(job))
++ call assert_match('channel:2002',
++ \ system(actual .. ' --remote-expr "v:servername"'))
++
++ call ch_close(ch)
++ call system(actual .. " --remote-expr 'execute(\"qa!\")'")
++ try
++ call WaitForAssert({-> assert_equal("dead", job_status(job))})
++ finally
++ if job_status(job) != 'dead'
++ call assert_report('Server did not exit')
++ call job_stop(job, 'kill')
++ endif
++ endtry
++endfunc
++
+ " Uncomment this line to get a debugging log
+ " call ch_logfile('channellog', 'w')
+
+diff --git a/src/version.c b/src/version.c
+index 92cd53129..43e4bb45b 100644
+--- a/src/version.c
++++ b/src/version.c
+@@ -734,6 +734,8 @@ static char *(features[]) =
+
+ static int included_patches[] =
+ { /* Add new patch number below this line */
++/**/
++ 844,
+ /**/
+ 736,
+ /**/
+--
+2.53.0
+
@@ -39,6 +39,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
file://CVE-2026-59856.patch \
file://CVE-2026-59857.patch \
file://CVE-2026-59858.patch \
+ file://CVE-2026-73071.patch \
"
PV .= ".0340"