From patchwork Wed Jul 22 12:33:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Vijay Anusuri X-Patchwork-Id: 93207 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 043C1C44536 for ; Wed, 22 Jul 2026 12:33:54 +0000 (UTC) Received: from mail-pj1-f54.google.com (mail-pj1-f54.google.com [209.85.216.54]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.47117.1784723630136236652 for ; Wed, 22 Jul 2026 05:33:50 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=Hiny98lh; spf=pass (domain: mvista.com, ip: 209.85.216.54, mailfrom: vanusuri@mvista.com) Received: by mail-pj1-f54.google.com with SMTP id 98e67ed59e1d1-385ea3ce80dso12504147a91.2 for ; Wed, 22 Jul 2026 05:33:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784723629; x=1785328429; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=mYyJQepaT7qKUKFUV0/pg84mP0BfdfU8waC2EXVSmY8=; b=Hiny98lhfER2F08XiBnraTL8jOG5o/Ty7d8rOxcwzBIzmH6JKn40U+QY8MtZyRgYfU E3XWv5gXawYfv9GncNhrPrZyCL7Smt3Vv2qgzi5s0drX3ZgfHwp80B1XaNqQ9HGgvB4N FUXrIbKT/kMMxsgIcRqIpIUV7nUBsrapKplvg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784723629; x=1785328429; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=mYyJQepaT7qKUKFUV0/pg84mP0BfdfU8waC2EXVSmY8=; b=qY7ryY06pc/+J2BpMsbDrNha7XbHaPg7Kvpv6yQpPl0D1LtiIF+ZrVpd/pQOS0GSiP RO0DrCrsMStodPIibv7kwhS04r1jTyokiVkOck00jCqmucRtUmUDWFRJBG7jv083z3TT KfGOUqqGkqnQHJYktj7H+7tJYJzuSX5FJApkkU+QvZ5dBKo+9mOAo37OA8Z6QL4+a89X w/pv6ej39HxNlNt0ok6TMpTo9JTi1hBPyp0sWGynrJxBVMg/Dbf18q0C6y7MG1NEyp+A zIJ1LMFbL4vF+uoIvW+/fJz1bZmSPumEGDlws0o+EeaCAxUZFbrxFvTicJRX+8db3pYN /iNA== X-Gm-Message-State: AOJu0Yys4Io2ceA6bp/f3ipyL0UuuZ//0HP+w+6/X7jAR8aXIdJbOKca Jzc5AJYuG2lHtT+AiSnJ1qldx5Gff6apE6Zhwso/Vu4cl8l6lXjLelHmdiQUUsCZa83GfEPvoC0 EtxNpzKE= X-Gm-Gg: AR+sD11Ipg9dU2uc6rwgTwzKIBp7G69QhoR33Owmbzy14VXrs6Z8KPzXARZJeczGKOc NVaX6ppWAUbgvGf9mQXzFkZaJCWOlcY5NlZW2fB2G/fHISBQNp94fh0mrqCZS39TqXUPkZjS0F7 XYMwyW8BnCCoVB2iMtfzmqbkS8TWkOvyRFi9JEj+bGgyxmcFlL0dQAZxnqvRNbpWFCHdL9HlamM 0kMwurHpmQYkt/Is/VHo7vRFfUyZ74+42rkkiE+qQ9iUPH3j1DkX//OfceI2bOIDPLAQfjK3u2D DKFYDYp+zZSdfiVeQlfiIbl8Ef4LTjzmDsYDJf6YcWOz0iO9Hssb+dY9XhGtjk+AfnKRMf4vNgC h0g8dkFoqT2kflxl/iIUgu2iywIXocVceIwE8vjaQ30AxktOmMlmbubrhP8v+hQG2Td0YP2tQsp VRm0yHJ9+91Bf6ZFMA3gMzXNfA7Ug= X-Received: by 2002:a17:90b:544f:b0:38e:dc4:3fbb with SMTP id 98e67ed59e1d1-38e4b5b7637mr23024537a91.43.1784723629197; Wed, 22 Jul 2026 05:33:49 -0700 (PDT) Received: from MVIN00352.mvista.com ([2401:4900:1f29:92d:e2c5:62da:989e:f39a]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13d130262d2sm5823414c88.7.2026.07.22.05.33.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 05:33:48 -0700 (PDT) From: Vijay Anusuri To: openembedded-core@lists.openembedded.org Cc: Vijay Anusuri Subject: [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Date: Wed, 22 Jul 2026 18:03:27 +0530 Message-ID: <20260722123336.587556-1-vanusuri@mvista.com> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 12:33:54 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241669 Pick patch per [1]. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-55693 [2] https://security-tracker.debian.org/tracker/CVE-2026-55693 Signed-off-by: Vijay Anusuri --- .../vim/files/CVE-2026-55693.patch | 88 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 89 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-55693.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-55693.patch b/meta/recipes-support/vim/files/CVE-2026-55693.patch new file mode 100644 index 0000000000..41f48ebfa5 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-55693.patch @@ -0,0 +1,88 @@ +From a80874d9b84a01040e3d1aef2d4a59e1934dafb7 Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Mon, 15 Jun 2026 19:39:08 +0000 +Subject: [PATCH] patch 9.2.0653: [security]: out-of-bounds write in + tree_count_words() + +Problem: [security]: a crafted spell file can drive tree_count_words() + past the end of its MAXWLEN-sized depth arrays; the descent + loop has no depth bound. +Solution: only descend while depth < MAXWLEN - 1, as the sibling trie + walkers already do; apply the same guard to sug_filltree(). + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-wgh4-64f7-q3jq + +Supported by AI. + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/a80874d9b84a01040e3d1aef2d4a59e1934dafb7] +CVE: CVE-2026-55693 +Signed-off-by: Vijay Anusuri +--- + src/spellfile.c | 4 ++-- + src/testdir/test_spellfile.vim | 26 ++++++++++++++++++++++++++ + 2 files changed, 28 insertions(+), 2 deletions(-) + +diff --git a/src/spellfile.c b/src/spellfile.c +index 5102dad5b6..b3ee9c0d63 100644 +--- a/src/spellfile.c ++++ b/src/spellfile.c +@@ -642,7 +642,7 @@ tree_count_words(char_u *byts, idx_T *idxs) + ++curi[depth]; + } + } +- else ++ else if (depth < MAXWLEN - 1) + { + // Normal char, go one level deeper to count the words. + ++depth; +@@ -5656,7 +5656,7 @@ sug_filltree(spellinfo_T *spin, slang_T *slang) + ++curi[depth]; + } + } +- else ++ else if (depth < MAXWLEN - 1) + { + // Normal char, go one level deeper. + tword[depth++] = c; +diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim +index 8f3ef4907d..4da270acea 100644 +--- a/src/testdir/test_spellfile.vim ++++ b/src/testdir/test_spellfile.vim +@@ -1196,5 +1196,31 @@ func Test_mkspell_no_buffer_overflow() + defer delete('Xbof2.spl') + endfunc + ++func Test_spell_sug_tree_count_words_overflow() ++ " A crafted .spl/.sug pair with a BY_INDEX self-cycle in the fold word tree ++ " parses cleanly (shared refs aren't recursed, so read_tree_node()'s depth ++ " cap never trips), but drove tree_count_words() past its MAXWLEN-sized depth ++ " arrays -> stack out-of-bounds write. The walk only happens when ++ " spellsuggest() loads the matching .sug. Reaching the assert == no OOB. ++ call mkdir('Xrtp/spell', 'pR') ++ " VIMspell + v50, SN_SUGFILE(ts), SN_END, LWORDTREE{node:1,BY_INDEX->0,'A'}, ++ " empty KWORDTREE/PREFIXTREE ++ let spl = eval('0z56494D7370656C6C320B0000000008000000001234' ++ \ .. '5678FF000000020101000000410000000000000000') ++ " VIMsug + v1, matching ts, SUGWORDTREE word "a", empty SUGTABLE ++ let sug = 0z56494D737567010000000012345678000000040161010000000000 ++ call writefile(spl, 'Xrtp/spell/xx.utf-8.spl', 'b') ++ call writefile(sug, 'Xrtp/spell/xx.utf-8.sug', 'b') ++ ++ new ++ set runtimepath+=./Xrtp ++ set spelllang=xx ++ set spell ++ " Unpatched: OOB write here (ASan abort, or crash). Patched: returns a list. ++ call assert_equal(v:t_list, type(spellsuggest('helloo'))) ++ ++ set spell& spelllang& runtimepath& ++ bwipe! ++endfunc + + " vim: shiftwidth=2 sts=2 expandtab +-- +2.43.0 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index e34cc17fe5..c0315dfed6 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -23,6 +23,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-52858.patch \ file://CVE-2026-52859.patch \ file://CVE-2026-52860.patch \ + file://CVE-2026-55693.patch \ " PV .= ".0340" From patchwork Wed Jul 22 12:33:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Vijay Anusuri X-Patchwork-Id: 93208 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0A864C4453C for ; Wed, 22 Jul 2026 12:34:04 +0000 (UTC) Received: from mail-pj1-f49.google.com (mail-pj1-f49.google.com [209.85.216.49]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.46864.1784723636225578277 for ; Wed, 22 Jul 2026 05:33:56 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=Lz5Hh9FG; spf=pass (domain: mvista.com, ip: 209.85.216.49, mailfrom: vanusuri@mvista.com) Received: by mail-pj1-f49.google.com with SMTP id 98e67ed59e1d1-38deea72eebso10561903a91.1 for ; Wed, 22 Jul 2026 05:33:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784723635; x=1785328435; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=BqVUNu9Z1VD1AB/CjsNDfHWoZ7YQTbdmSf0C1uGgyeM=; b=Lz5Hh9FGoZUm+HteIobFFzp8s4n8a/e1pF7dXnkjnOgyYu/1V5vHYtQYTBVdVrXh6y q3dPNV8aP7UcSsYOM9Tlx4ZwtdonkYTXvKv5W3NOMzsLHv4+P7enOlmAxcpIA4Ijblkd ur1SlZcnwHUmAyn9btUwaaF9YItgJYzKSqlcU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784723635; x=1785328435; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=BqVUNu9Z1VD1AB/CjsNDfHWoZ7YQTbdmSf0C1uGgyeM=; b=jzFWU6X4FF+5CIDdvfsgGVGVmc+Hw04D2QJwiOE7fHcqv6zAwmnsJbd4B7/V7Ijehx hjFLJIsIOonyAezXq/Z4g9pivR985yGMcOaBVnw/6DjFwkJjOciGpPvV0LI5EChGJBin wQwlY5mtesL58hWqfzHH18/qTsfpH9izBtyViuGogLGt3S6A19SkuwAvFJYERG0eR7vh XOis2yaYcmwnjY610OpQXVCJC/Tq38+zWkQitGhW8a0/oUQ58ku75eXVWPBHAQePQ7SS 1rY+tlQUFSbNtlaDuYT4joYRchCUAQL4iAx0znOsfkLIg5ZEeye0eVfcL1HOw1/QoigZ GSjA== X-Gm-Message-State: AOJu0YzNtBIQj2RX0eGD96am01O/6GO5xXszgLsf1OMUFyW5ItqDGyD8 UDxRruQzyRT9NRX0UR0axvUH/clfK7FtXMwohUhEEZjhRJ5N8nKw/vdTERmqFq3wGuX1WDwxPbZ vx4fg X-Gm-Gg: AR+sD13jnV56GLMXv1Ixg2TdZ33kfwIGc8ww7KW2pJK+4CiTNvD7mIHDVC1FQnRC3r8 1KDUXqGdEX+X91qP1nD7WCPJ+25Dh14pBXKOadTwy2u1kYt9oDzDJkapVN4+YSYJ0qmWAmKVGvh lKLU1iuVfal+U307fIq/GmRTzQO4F632tqF+uiQUbXmwpD5nPgNAcjxTNoHiWJ368jbQvk/N/j6 Lkl98hOSIqbtq16nHVdnRfPjUNM2JKx9HT/GZsDSJJPU5pIGi5cmy8HUeA3DmBf9M6Mvs2wh9RZ Q5SyxKtDpVchO2ish557ylk0DlTFvEoAlQUfPkReP39nEx4eIgtLSR5li0aABxD/oQbGsAygwRG j3waZQvwKmUuYilBmNy1vlDCYw61Wf85xK8FrU2XR4KSACu3zTStR5zEBQtPK1JoIgWncAkiqyr AgX9/91Mm7XUTt1ZHp X-Received: by 2002:a17:90b:544b:b0:38e:9045:babe with SMTP id 98e67ed59e1d1-38e9045bb96mr8709420a91.7.1784723635477; Wed, 22 Jul 2026 05:33:55 -0700 (PDT) Received: from MVIN00352.mvista.com ([2401:4900:1f29:92d:e2c5:62da:989e:f39a]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13d130262d2sm5823414c88.7.2026.07.22.05.33.51 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 05:33:53 -0700 (PDT) From: Vijay Anusuri To: openembedded-core@lists.openembedded.org Cc: Vijay Anusuri Subject: [OE-core][wrynose][patch 02/10] vim: Fix CVE-2026-55895 Date: Wed, 22 Jul 2026 18:03:28 +0530 Message-ID: <20260722123336.587556-2-vanusuri@mvista.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260722123336.587556-1-vanusuri@mvista.com> References: <20260722123336.587556-1-vanusuri@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 12:34:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241670 Pick patch per [1]. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-55895 [2] https://github.com/vim/vim/security/advisories/GHSA-vhh8-v6wx-hjjh Signed-off-by: Vijay Anusuri --- .../vim/files/CVE-2026-55895.patch | 83 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 84 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-55895.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-55895.patch b/meta/recipes-support/vim/files/CVE-2026-55895.patch new file mode 100644 index 0000000000..cc335ea2a6 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-55895.patch @@ -0,0 +1,83 @@ +From 55bc757a5d436e59d50fe43f7cda94b118f86cb2 Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Tue, 16 Jun 2026 21:00:28 +0000 +Subject: [PATCH] patch 9.2.0663: [security]: runtime(netrw): code injection in + local file deletion + +Problem: [security]: s:NetrwLocalRmFile() escapes only the backslash in + the file name before passing it to :execute, so a name + containing "|" injects arbitrary Ex commands when the file is + deleted (cipher-creator) +Solution: Use fnameescape() to correctly escape the file name + (Yasuhiro Matsumoto). + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-vhh8-v6wx-hjjh + +Supported by AI + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/55bc757a5d436e59d50fe43f7cda94b118f86cb2] +CVE: CVE-2026-55895 +Signed-off-by: Vijay Anusuri +--- + .../pack/dist/opt/netrw/autoload/netrw.vim | 4 ++-- + src/testdir/test_plugin_netrw.vim | 20 +++++++++++++++++++ + 2 files changed, 22 insertions(+), 2 deletions(-) + +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index 8e5fdb5397..ebb856800c 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -3062,7 +3062,7 @@ function s:NetrwBrowse(islocal,dirname) + elseif !a:islocal && dirname !~ '[\/]$' && dirname !~ '^"' + " s:NetrwBrowse : remote regular file handler {{{3 + if bufname(dirname) != "" +- exe "NetrwKeepj b ".bufname(dirname) ++ exe "NetrwKeepj b ".fnameescape(bufname(dirname)) + else + " attempt transfer of remote regular file + +@@ -8772,7 +8772,7 @@ function s:NetrwLocalRmFile(path, fname, all) + call netrw#msg#Notify('ERROR', printf("unable to delete <%s>!", rmfile)) + else + " Remove file only if there are no pending changes +- execute printf('silent! bwipeout %s', rmfile) ++ execute printf('silent! bwipeout %s', fnameescape(rmfile)) + endif + + elseif dir && (all || empty(ok)) +diff --git a/src/testdir/test_plugin_netrw.vim b/src/testdir/test_plugin_netrw.vim +index b234670928..4d5fc9a065 100644 +--- a/src/testdir/test_plugin_netrw.vim ++++ b/src/testdir/test_plugin_netrw.vim +@@ -609,4 +609,24 @@ func Test_netrw_RFC2396() + call assert_equal('a b', netrw#RFC2396(fname)) + endfunc + ++" Deleting a file whose name contains an Ex command separator must not let the ++" name inject commands into the :execute in s:NetrwLocalRmFile(). ++func Test_netrw_local_rm_injection() ++ CheckUnix ++ let dir = getcwd() . '/Xnetrwrm' ++ let fname = "x|let g:injected = 1" ++ call mkdir(dir, 'pR') ++ call writefile([], dir . '/' . fname) ++ try ++ call netrw#Call('NetrwLocalRmFile', dir, fname, 1) ++ call assert_false(exists('g:injected'), 'filename must not inject Ex commands') ++ " The file is removed before the sink, so its absence also confirms the ++ " vulnerable code path was actually exercised (not skipped on an error). ++ call assert_false(filereadable(dir . '/' . fname), 'crafted file must be deleted') ++ finally ++ call delete(dir . '/' . fname) ++ unlet! g:injected ++ endtry ++endfunc ++ + " vim:ts=8 sts=2 sw=2 et +-- +2.43.0 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index c0315dfed6..b9f6ef987c 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -24,6 +24,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-52859.patch \ file://CVE-2026-52860.patch \ file://CVE-2026-55693.patch \ + file://CVE-2026-55895.patch \ " PV .= ".0340" From patchwork Wed Jul 22 12:33:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Vijay Anusuri X-Patchwork-Id: 93209 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 04BE7C44536 for ; Wed, 22 Jul 2026 12:34:04 +0000 (UTC) Received: from mail-pj1-f42.google.com (mail-pj1-f42.google.com [209.85.216.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.47120.1784723641731865481 for ; Wed, 22 Jul 2026 05:34:01 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=SmwM6fM3; spf=pass (domain: mvista.com, ip: 209.85.216.42, mailfrom: vanusuri@mvista.com) Received: by mail-pj1-f42.google.com with SMTP id 98e67ed59e1d1-38e08baf860so10106296a91.2 for ; Wed, 22 Jul 2026 05:34:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784723641; x=1785328441; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=nLAWZbvY1mC4aUxorPU1xb3l4fr2TOUdreuh7/KUsUc=; b=SmwM6fM3ZolVvsippcVyudPzqqDM1qLXEoOjfsQDdLtnEx+6K4avgJFTS8EeL3COhF 3FW5avMowReePT2pk+pgNUiEmLFlvOfTIIdJklOnjCZrUKx/bQ+D0jnTgyOl1QpRAAin sLXApzz539OOROKrIihsLMqeWE1m0uiPrQBf4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784723641; x=1785328441; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=nLAWZbvY1mC4aUxorPU1xb3l4fr2TOUdreuh7/KUsUc=; b=KRqJ7ioK2rbuttJ6VV2rM+MX0I6VxKOSM2slbQUf/JmmHOZ5ZVgRUZYUfPZGALKuwg nol5gjWoMA9X3evlqM65OSQ9hxslTphBd1cgNy31KqY4q36B78c7iz80jQinZlgO4cOk x5nMo2oxRW6L07APHLkKs+JYnmuFc4z7x8XiFktmusxPsGQBrmPtn0dOkqaHP8TvALJJ PA2w5t4wN8TbBKjvwZudGq6N3S+MTyGUcV41d0sLlnb3C+YGTgJ/MOO7+o8EcKwecyde 8P74JDzeoUYr013FOrnz7oWuF0sh+quk4bHuJ/8AlpO4x0KlF+KcQaeJTunnyuLEK6UZ d44g== X-Gm-Message-State: AOJu0YyU+ccDf7Xf43MrDXP9ZDmXzjHVyCbGD5yk6QuRKQq03Mcz30TU KUhnlmZ2HKctoAtmoVWAC3N60c4WNBoiPrnrf8ilEuCh0vm877TAbkJqcxt6tWRkapNTmBi0dRu GBHH2 X-Gm-Gg: AR+sD11YUvS1wJQpQs6SZDrsvkKSkBYxu5LuVs5r26W7dOOzbi7/p2BJDls+8bIBAms o7yD7bBPT7auuk4RRDBvNfvOEJnrm6x54e3TWCz3LVWpMG3aSCfLsw5entK0SdwuH83AZzWdqAY wR9CdgmppnpWTN/PF2Qt6UzNGKLhOcOVZ2LdI/6daBDUxBqRQH7vCLJoNjcvrWTgd7qBgphWFio Q+hsKPH2C8Fay6mcRqT4rkMvSIMWQBwSiXalHM9ZhRtOZNpk63dlmySZvs34+v8R3WV95y5PfLo R91H5bWMMIHutkQn5iZJFZKHubpy9gD2dUugM/vPSKP5eZ9es8kA7q7UPlX2nd7WPTUR4WM4C6g RG0opX3h2tY7h9faSNrtNyu7VXNYlz+yKR5xFtkto5GfwRHTm55B/8832/9Y9/KhYnVHV7wJB1V VR6SxsQTKfUUIBNVYy X-Received: by 2002:a17:90b:4ac8:b0:38e:447c:9a15 with SMTP id 98e67ed59e1d1-38e4b57ddc0mr21912229a91.36.1784723640806; Wed, 22 Jul 2026 05:34:00 -0700 (PDT) Received: from MVIN00352.mvista.com ([2401:4900:1f29:92d:e2c5:62da:989e:f39a]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13d130262d2sm5823414c88.7.2026.07.22.05.33.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 05:33:59 -0700 (PDT) From: Vijay Anusuri To: openembedded-core@lists.openembedded.org Cc: Vijay Anusuri Subject: [OE-core][wrynose][patch 03/10] vim: Fix CVE-2026-57453 Date: Wed, 22 Jul 2026 18:03:29 +0530 Message-ID: <20260722123336.587556-3-vanusuri@mvista.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260722123336.587556-1-vanusuri@mvista.com> References: <20260722123336.587556-1-vanusuri@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 12:34:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241671 Pick patch per [1]. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57453 [2] https://github.com/vim/vim/security/advisories/GHSA-x5fg-h5w9-9frf Signed-off-by: Vijay Anusuri --- .../vim/files/CVE-2026-57453.patch | 248 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 249 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-57453.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-57453.patch b/meta/recipes-support/vim/files/CVE-2026-57453.patch new file mode 100644 index 0000000000..d1ad6d6f54 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-57453.patch @@ -0,0 +1,248 @@ +From b2cc9be119d51212bf0d3f2a994c7e517c73f4a9 Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Sat, 20 Jun 2026 15:35:58 +0000 +Subject: [PATCH] patch 9.2.0678: [security]: potential powershell code + execution in zip.vim + +Problem: [security]: potential powershell code execution in zip.vim + (DDugs) +Solution: Cleanup zip.vim, introduce PSEscape() to escape() potential powershell code, + use consistent s:Escape() in the various PowerShell functions + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-x5fg-h5w9-9frf + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/b2cc9be119d51212bf0d3f2a994c7e517c73f4a9] +CVE: CVE-2026-57453 +Signed-off-by: Vijay Anusuri +--- + runtime/autoload/zip.vim | 78 +++++++++++++++++++--------------------- + runtime/doc/pi_zip.txt | 10 ------ + 2 files changed, 36 insertions(+), 52 deletions(-) + +diff --git a/runtime/autoload/zip.vim b/runtime/autoload/zip.vim +index f4482fd7fc..752503a626 100644 +--- a/runtime/autoload/zip.vim ++++ b/runtime/autoload/zip.vim +@@ -22,6 +22,7 @@ + " 2026 Mar 08 by Vim Project: Make ZipUpdatePS() check for powershell + " 2026 Apr 01 by Vim Project: Detect more path traversal attacks + " 2026 Apr 05 by Vim Project: Detect more path traversal attacks ++" 2026 Jun 20 by Vim Project: Fix wrong escaping for the powershell calls + " License: Vim License (see vim's :help license) + " Copyright: Copyright (C) 2005-2019 Charles E. Campbell {{{1 + " Permission is hereby granted to use and distribute this code, +@@ -49,15 +50,6 @@ let s:NOTE = 0 + + " --------------------------------------------------------------------- + " Global Values: {{{1 +-if !exists("g:zip_shq") +- if &shq != "" +- let g:zip_shq= &shq +- elseif has("unix") +- let g:zip_shq= "'" +- else +- let g:zip_shq= '"' +- endif +-endif + if !exists("g:zip_zipcmd") + let g:zip_zipcmd= "zip" + endif +@@ -133,7 +125,7 @@ function! s:ZipBrowsePS(zipfile) + " Browse the contents of a zip file using PowerShell's + " Equivalent `unzip -Z1 -- zipfile` + let cmds = [ +- \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:Escape(a:zipfile, 1) . ');', ++ \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:PSEscape(a:zipfile) . ');', + \ '$zip.Entries | ForEach-Object { $_.FullName };', + \ '$zip.Dispose()' + \ ] +@@ -147,16 +139,16 @@ function! s:ZipReadPS(zipfile, fname, tempfile) + call s:Mess('WarningMsg', "***warning*** PowerShell can display, but cannot update, files in archive subfolders") + endif + let cmds = [ +- \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:Escape(a:zipfile, 1) . ');', +- \ '$fileEntry = $zip.Entries | Where-Object { $_.FullName -eq ' . s:Escape(a:fname, 1) . ' };', ++ \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:PSEscape(a:zipfile) . ');', ++ \ '$fileEntry = $zip.Entries | Where-Object { $_.FullName -eq ' . s:PSEscape(a:fname) . ' };', + \ '$stream = $fileEntry.Open();', +- \ '$fileStream = [System.IO.File]::Create(' . s:Escape(a:tempfile, 1) . ');', ++ \ '$fileStream = [System.IO.File]::Create(' . s:PSEscape(a:tempfile) . ');', + \ '$stream.CopyTo($fileStream);', + \ '$fileStream.Close();', + \ '$stream.Close();', + \ '$zip.Dispose()' + \ ] +- return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' '), 1) ++ return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' ')) + endfunction + + function! s:ZipUpdatePS(zipfile, fname) +@@ -166,7 +158,7 @@ function! s:ZipUpdatePS(zipfile, fname) + call s:Mess('Error', "***error*** PowerShell cannot update files in archive subfolders") + return ':' + endif +- return 'Compress-Archive -Path ' . a:fname . ' -Update -DestinationPath ' . a:zipfile ++ return 'Compress-Archive -Path ' . s:PSEscape(a:fname) . ' -Update -DestinationPath ' . s:PSEscape(a:zipfile) + endfunction + + function! s:ZipExtractFilePS(zipfile, fname) +@@ -177,16 +169,16 @@ function! s:ZipExtractFilePS(zipfile, fname) + return ':' + endif + let cmds = [ +- \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:Escape(a:zipfile, 1) . ');', +- \ '$fileEntry = $zip.Entries | Where-Object { $_.FullName -eq ' . a:fname . ' };', ++ \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:PSEscape(a:zipfile) . ');', ++ \ '$fileEntry = $zip.Entries | Where-Object { $_.FullName -eq ' . s:PSEscape(a:fname) . ' };', + \ '$stream = $fileEntry.Open();', +- \ '$fileStream = [System.IO.File]::Create(' . a:fname . ');', ++ \ '$fileStream = [System.IO.File]::Create(' . s:PSEscape(a:fname) . ');', + \ '$stream.CopyTo($fileStream);', + \ '$fileStream.Close();', + \ '$stream.Close();', + \ '$zip.Dispose()' + \ ] +- return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' '), 1) ++ return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' ')) + endfunction + + function! s:ZipDeleteFilePS(zipfile, fname) +@@ -194,12 +186,12 @@ function! s:ZipDeleteFilePS(zipfile, fname) + " Equivalent to `zip -d zipfile fname` + let cmds = [ + \ 'Add-Type -AssemblyName System.IO.Compression.FileSystem;', +- \ '$zip = [System.IO.Compression.ZipFile]::Open(' . s:Escape(a:zipfile, 1) . ', ''Update'');', +- \ '$entry = $zip.Entries | Where-Object { $_.Name -eq ' . s:Escape(a:fname, 1) . ' };', ++ \ '$zip = [System.IO.Compression.ZipFile]::Open(' . s:PSEscape(a:zipfile) . ', ''Update'');', ++ \ '$entry = $zip.Entries | Where-Object { $_.Name -eq ' . s:PSEscape(a:fname) . ' };', + \ 'if ($entry) { $entry.Delete(); $zip.Dispose() }', + \ 'else { $zip.Dispose() }' + \ ] +- return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' '), 1) ++ return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' ')) + endfunction + + " ---------------- +@@ -339,9 +331,9 @@ fun! zip#Read(fname,mode) + let temp = tempname() + let fn = expand('%:p') + +- let gnu_cmd = g:zip_unzipcmd . ' -p -- ' . s:Escape(zipfile, 0) . ' ' . s:Escape(fname, 0) . ' > ' . s:Escape(temp, 0) +- let gnu_cmd = 'call system(''' . substitute(gnu_cmd, "'", "''", 'g') . ''')' +- let ps_cmd = 'sil !' . s:ZipReadPS(zipfile, fname, temp) ++ let gnu_cmd = g:zip_unzipcmd . ' -p -- ' . s:Escape(zipfile) . ' ' . s:Escape(fname) . ' > ' . s:Escape(temp) ++ let gnu_cmd = 'call system(' . string(gnu_cmd) . ')' ++ let ps_cmd = $"call system({string(s:ZipDeleteFilePS(zipfile, fname))})" + call s:TryExecGnuFallBackToPs(g:zip_unzipcmd, gnu_cmd, ps_cmd) + + sil exe 'keepalt file '.temp +@@ -408,9 +400,9 @@ fun! zip#Write(fname) + " TODO: what to check on MS-Windows to avoid writing absolute paths? + endif + if fname =~ '^[.]\{1,2}/' +- let gnu_cmd = g:zip_zipcmd . ' -d ' . s:Escape(fnamemodify(zipfile,":p"),0) . ' ' . s:Escape(fname,0) +- let gnu_cmd = 'call system(''' . substitute(gnu_cmd, "'", "''", 'g') . ''')' +- let ps_cmd = $"call system({s:Escape(s:ZipDeleteFilePS(zipfile, fname), 1)})" ++ let gnu_cmd = g:zip_zipcmd . ' -d ' . s:Escape(fnamemodify(zipfile,":p")) . ' ' . s:Escape(fname) ++ let gnu_cmd = 'call system(' . string(gnu_cmd) . ')' ++ let ps_cmd = $"call system({string(s:ZipDeleteFilePS(zipfile, fname))})" + call s:TryExecGnuFallBackToPs(g:zip_zipcmd, gnu_cmd, ps_cmd) + let fname = fname->substitute('^\([.]\{1,2}/\)\+', '', 'g') + let need_rename = 1 +@@ -419,7 +411,7 @@ fun! zip#Write(fname) + if fname =~ '/' + let dirpath = substitute(fname,'/[^/]\+$','','e') + if has("win32unix") && executable("cygpath") +- let dirpath = substitute(system("cygpath ".s:Escape(dirpath,0)),'\n','','e') ++ let dirpath = substitute(system("cygpath ".s:Escape(dirpath)),'\n','','e') + endif + call mkdir(dirpath,"p") + endif +@@ -430,16 +422,17 @@ fun! zip#Write(fname) + " don't overwrite files forcefully + exe "w ".fnameescape(fname) + if has("win32unix") && executable("cygpath") +- let zipfile = substitute(system("cygpath ".s:Escape(zipfile,0)),'\n','','e') ++ let zipfile = substitute(system("cygpath ".s:Escape(zipfile)),'\n','','e') + endif + + if (has("win32") || has("win95") || has("win64") || has("win16")) && &shell !~? 'sh$' + let fname = substitute(fname, '[', '[[]', 'g') + endif + +- let gnu_cmd = g:zip_zipcmd . ' -u '. s:Escape(fnamemodify(zipfile,":p"),0) . ' ' . s:Escape(fname,0) ++ let gnu_cmd = g:zip_zipcmd . ' -u '. s:Escape(fnamemodify(zipfile,":p")) . ' ' . s:Escape(fname) + let gnu_cmd = 'call system(''' . substitute(gnu_cmd, "'", "''", 'g') . ''')' +- let ps_cmd = s:ZipUpdatePS(s:Escape(fnamemodify(zipfile, ':p'), 0), s:Escape(fname, 0)) ++ let zip = fnamemodify(zipfile, ':p') ++ let ps_cmd = s:ZipUpdatePS(zip, fname) + let ps_cmd = 'call system(''' . substitute(ps_cmd, "'", "''", 'g') . ''')' + call s:TryExecGnuFallBackToPs(g:zip_zipcmd, gnu_cmd, ps_cmd) + if &shell =~ 'pwsh' +@@ -522,8 +515,8 @@ fun! zip#Extract() + + " extract the file mentioned under the cursor + let gnu_cmd = g:zip_extractcmd . ' -o '. shellescape(b:zipfile) . ' ' . target +- let gnu_cmd = 'call system(''' . substitute(gnu_cmd, "'", "''", 'g') . ''')' +- let ps_cmd = $"call system({s:Escape(s:ZipExtractFilePS(b:zipfile, target), 1)})" ++ let gnu_cmd = 'call system(' . string(gnu_cmd) . ')' ++ let ps_cmd = 'call system(' . string(s:ZipExtractFilePS(b:zipfile, fname)) . ')' + call s:TryExecGnuFallBackToPs(g:zip_extractcmd, gnu_cmd, ps_cmd) + + if v:shell_error != 0 +@@ -537,19 +530,20 @@ endfun + + " --------------------------------------------------------------------- + " s:Escape: {{{2 +-fun! s:Escape(fname,isfilt) +- if exists("*shellescape") +- if a:isfilt +- let qnameq= shellescape(a:fname,1) +- else +- let qnameq= shellescape(a:fname) +- endif ++fun! s:Escape(fname, isfilt = 0) ++ if a:isfilt ++ let qnameq = shellescape(a:fname, 1) + else +- let qnameq= g:zip_shq.escape(a:fname,g:zip_shq).g:zip_shq ++ let qnameq = shellescape(a:fname) + endif + return qnameq + endfun + ++" s:PSEscape: Escape a string for Powershell, shellescape() does not work here {{{2 ++fun! s:PSEscape(str) ++ return "'" .. substitute(a:str, "'", "''", 'g') .. "'" ++endfun ++ + " --------------------------------------------------------------------- + " s:ChgDir: {{{2 + fun! s:ChgDir(newdir,errlvl,errmsg) +diff --git a/runtime/doc/pi_zip.txt b/runtime/doc/pi_zip.txt +index e9294b4059..b1800dfcc5 100644 +--- a/runtime/doc/pi_zip.txt ++++ b/runtime/doc/pi_zip.txt +@@ -48,16 +48,6 @@ Copyright: Copyright (C) 2005-2015 Charles E Campbell *zip-copyright* + If this variable exists and is true, the file window will not be + automatically maximized when opened. + +- *g:zip_shq* +- Different operating systems may use one or more shells to execute +- commands. Zip will try to guess the correct quoting mechanism to +- allow spaces and whatnot in filenames; however, if it is incorrectly +- guessing the quote to use for your setup, you may use > +- g:zip_shq +-< which by default is a single quote under Unix (') and a double quote +- under Windows ("). If you'd rather have no quotes, simply set +- g:zip_shq to the empty string (let g:zip_shq= "") in your <.vimrc>. +- + *g:zip_unzipcmd* + Use this option to specify the program which does the duty of "unzip". + It's used during browsing. By default: > +-- +2.43.0 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index b9f6ef987c..ecdf7cb5b9 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -25,6 +25,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-52860.patch \ file://CVE-2026-55693.patch \ file://CVE-2026-55895.patch \ + file://CVE-2026-57453.patch \ " PV .= ".0340" From patchwork Wed Jul 22 12:33:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Vijay Anusuri X-Patchwork-Id: 93211 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 13DC7C44536 for ; Wed, 22 Jul 2026 12:34:14 +0000 (UTC) Received: from mail-pj1-f46.google.com (mail-pj1-f46.google.com [209.85.216.46]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.46867.1784723647363264026 for ; Wed, 22 Jul 2026 05:34:07 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=eXj0DD6E; spf=pass (domain: mvista.com, ip: 209.85.216.46, mailfrom: vanusuri@mvista.com) Received: by mail-pj1-f46.google.com with SMTP id 98e67ed59e1d1-381216921aaso11712805a91.1 for ; Wed, 22 Jul 2026 05:34:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784723647; x=1785328447; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=1Veno6ShKG5PMVdxdCu21m7iEmq4QTTViKU1RCtzXME=; b=eXj0DD6Ec3vxsPWGMeDCKbNj1JRGCbxxhZtfvK4NlRj9tENe9InY6hsu0WT1yRkgsW hz+dZb8fTAaZn2DcYmd5uVvH+kwpX0S6A518YI9lIKPIEOHOTnS01z1G3yVru4vBlcSn 3+geUGe2y4nOZeWmqUQaj5/T3t5zFV7Ip39UY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784723647; x=1785328447; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=1Veno6ShKG5PMVdxdCu21m7iEmq4QTTViKU1RCtzXME=; b=N9VzaBfv+ho5egDBOHGwHQJJpd4ViZAnT8UMQcZageNpd/p8BI/bvKbo6PQqE+3QAy CwIw8bGBL4XX1VVMaFbiLtnj+0RKOL3fyDfvpCPJI72pkUMIsmKPMTf3Of5rNHlolb2y 8i98kmPlWxH+eDygHuNPT21R3ISNRrW6coP2Qh1Yy+hLlZ2qoEJGVyFAuB3haq56dhEC F4W9xt7lVOwfxLoXqzvH7feZvblUSXUtnP3JqGOdnR/Na+2vxSWNJyBhh7gXNLcH/2v1 IDnCOjkObaU5VO1bm74+GI+EhjwTksqhfYp/Pa2vd4HkMWvz/1YW3yPewcEj9LltJh/E Ac7w== X-Gm-Message-State: AOJu0Yw+oHbi9x9mRP2bT7k18vV7UF2RjA+p0b4Ktvfvjp/9Fq5RSikV Md4gf0A6Fx6sUTqp8t2kJKwxr11rPcDAyiIp6u1Wj/qO+8o5Wp30YdabcvXCtlrAGM6HfVQdrx5 FtF0k7EA= X-Gm-Gg: AR+sD11ql9SYj6WjPSo03YqhcaC0MH7RtAwEF7llMyP/o8AYXv0qCCKovnABkdJ56Fo m03Oy9FF9zO4qMKBj4nv2bhMu9I7w6K2Pww+8njK8DYMmgCo6+N33uiNVGEuMfN+LCzuoq6wWOZ A/AxYFLezqal5bSMYX61ccbn1pqiTb1942dWM8H5u0NE2kN8RODapdzDZeDk0ZbE8V858fROIWA wvWGP4cqdFRxxhJ4M7OWN13mJ6EGZObXYoKQ1OhzDzmy5TsDaZnXcVGt001XzCX0suxTNcgyuro fpIZ9kuawud9LdzbHDXLKlL5Oc7xByMovEu0L19KXskW3oKQKZlGryRJfYZ68TWIZxNSafyO0yO fkGNAaJQkx0spL/1wYkJYvHzuMprfWLM2GDGCi3Qa9w76CJCco40BCKulPFAX2zFTtoNVgOfNsp DrGEItyToChW6bsKtS X-Received: by 2002:a17:90b:2407:b0:38e:57a3:f218 with SMTP id 98e67ed59e1d1-38e57a3f788mr14681178a91.13.1784723646619; Wed, 22 Jul 2026 05:34:06 -0700 (PDT) Received: from MVIN00352.mvista.com ([2401:4900:1f29:92d:e2c5:62da:989e:f39a]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13d130262d2sm5823414c88.7.2026.07.22.05.34.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 05:34:04 -0700 (PDT) From: Vijay Anusuri To: openembedded-core@lists.openembedded.org Cc: Vijay Anusuri Subject: [OE-core][wrynose][patch 04/10] vim: Fix CVE-2026-57451 Date: Wed, 22 Jul 2026 18:03:30 +0530 Message-ID: <20260722123336.587556-4-vanusuri@mvista.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260722123336.587556-1-vanusuri@mvista.com> References: <20260722123336.587556-1-vanusuri@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 12:34:14 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241672 Pick patch per [1]. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57451 [2] https://github.com/vim/vim/security/advisories/GHSA-f36c-2qcp-7gpw Signed-off-by: Vijay Anusuri --- .../vim/files/CVE-2026-57451.patch | 177 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 178 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-57451.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-57451.patch b/meta/recipes-support/vim/files/CVE-2026-57451.patch new file mode 100644 index 0000000000..22a0cfc03e --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-57451.patch @@ -0,0 +1,177 @@ +From b2338ca90643e2f01ecb6547c1172716aaec4f79 Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Wed, 17 Jun 2026 21:06:59 +0000 +Subject: [PATCH] patch 9.2.0670: [security]: Out-of-bounds read with text + properties + +Problem: [security]: Out-of-bounds read with text properties + (cipher-creator) +Solution: Add out-of-bound checks (Yasuhiro Matsumoto) + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-f36c-2qcp-7gpw + +Supported by AI + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/b2338ca90643e2f01ecb6547c1172716aaec4f79] +CVE: CVE-2026-57451 +Signed-off-by: Vijay Anusuri +--- + src/memline.c | 7 ++++ + src/proto/textprop.pro | 1 + + src/testdir/test_textprop2.vim | 59 ++++++++++++++++++++++++++++++++++ + src/textprop.c | 20 ++++++++++++ + 4 files changed, 87 insertions(+) + +diff --git a/src/memline.c b/src/memline.c +index c15946a6eb..07c7a07d38 100644 +--- a/src/memline.c ++++ b/src/memline.c +@@ -3796,6 +3796,11 @@ adjust_text_props_for_delete( + uint16_t pc; + + mch_memmove(&pc, text + textlen, PROP_COUNT_SIZE); ++ if (!text_prop_count_valid(pc, (size_t)(line_size - (long)textlen))) ++ { ++ internal_error("text property count too large"); ++ return; ++ } + this_props_len = pc * (int)sizeof(textprop_T); + } + +@@ -4034,6 +4039,8 @@ theend: + mch_memmove(&pc, textprop_save, PROP_COUNT_SIZE); + props_data = textprop_save + PROP_COUNT_SIZE; + props_bytes = pc * (int)sizeof(textprop_T); ++ if (!text_prop_count_valid(pc, (size_t)textprop_len)) ++ props_bytes = 0; + + // Adjust text properties in the line above and below. + if (lnum > 1) +diff --git a/src/proto/textprop.pro b/src/proto/textprop.pro +index d3ecf6d14c..a01c2f3b2d 100644 +--- a/src/proto/textprop.pro ++++ b/src/proto/textprop.pro +@@ -35,4 +35,5 @@ void clear_buf_prop_types(buf_T *buf); + int adjust_prop_columns(linenr_T lnum, colnr_T col, int bytes_added, int flags); + void adjust_props_for_split(linenr_T lnum_props, linenr_T lnum_top, int kept, int deleted, int at_eol); + void prepend_joined_props(unpacked_memline_T *um, linenr_T lnum, int last_line, long col, int removed); ++bool text_prop_count_valid(int prop_count, size_t propdata_len); + /* vim: set ft=c : */ +diff --git a/src/testdir/test_textprop2.vim b/src/testdir/test_textprop2.vim +index 193a808415..48387d1c04 100644 +--- a/src/testdir/test_textprop2.vim ++++ b/src/testdir/test_textprop2.vim +@@ -428,4 +428,63 @@ func Test_multiline_prop_delete_penultimate_line() + call s:CleanupPropTypes(['1', '2', '3']) + endfunc + ++func s:ManipulateUndoBlob(name) ++ " Patch the saved old line in the undo file: ++ " 00 00 00 08 'QQQQQQQQ' -> 00 00 00 27 'AAAA' NUL count=0xFFFF <32x00> ++ " i.e. textlen 8 text-only -> 39-byte blob: text "AAAA", NUL, prop_count ++ " 0xFFFF, one zeroed textprop_T(32). propdata_len becomes 34, count 65535. ++ let blob = readfile(a:name, 'B') ++ let marker = 0z000000085151515151515151 ++ let repl = 0z000000274141414100FFFF + repeat(0z00, 32) ++ let mlen = len(marker) ++ let idx = -1 ++ let i = 0 ++ while i <= len(blob) - mlen ++ if blob[i : i + mlen - 1] ==# marker ++ let idx = i ++ break ++ endif ++ let i += 1 ++ endwhile ++ call assert_true(idx >= 0, 'saved-line marker not found in undo file') ++ ++ let head = idx > 0 ? blob[0 : idx - 1] : 0z ++ call writefile(head + repl + blob[idx + mlen :], a:name) ++ ++ exe "rundo" a:name ++endfunc ++ ++" A crafted undo file can restore a line whose declared text-property count is ++" far larger than the data, making get_text_props() / consumers read past the ++" line buffer. Restore such a line and force a consumer; reaching the asserts ++" (no ASan abort / crash) means the count is bounded. ++func Test_textprop_undo_bad_prop_count() ++ CheckFeature persistent_undo ++ ++ new ++ call setline(1, ['QQQQQQQQ', 'DECOYLINE']) ++ let &ul = &ul ++ call setline(1, 'BBBB') " undo step saves old line 1 = "QQQQQQQQ" ++ wundo Xtpundo ++ call s:ManipulateUndoBlob('Xtpundo') ++ ++ undo ++ ++ " Safety: prove the malicious line was actually restored before the consumer ++ " runs, so the test can't pass vacuously if the patch missed. ++ call assert_equal('AAAA', getline(1)) ++ ++ " Adding a property anywhere sets b_has_textprop, so get_text_props() will ++ " actually inspect line 1 instead of returning early. ++ call prop_type_add('Xtp', {}) ++ call prop_add(2, 1, {'type': 'Xtp', 'length': 1}) ++ ++ " this caused OOB read, now it triggers internal error ++ call assert_fails('call prop_list(1)', ['E340:', 'corrupted']) ++ ++ call prop_type_delete('Xtp') ++ bwipe! ++ call delete('Xtpundo') ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +diff --git a/src/textprop.c b/src/textprop.c +index 33165a8e43..931fb78d25 100644 +--- a/src/textprop.c ++++ b/src/textprop.c +@@ -109,6 +109,12 @@ um_goto_line(unpacked_memline_T *um, linenr_T lnum, int extra_props) + char_u *props_start; + + mch_memmove(&prop_count, count_ptr, PROP_COUNT_SIZE); ++ if (!text_prop_count_valid(prop_count, propdata_len)) ++ { ++ iemsg(e_text_property_info_corrupted); ++ um->buf = NULL; ++ return false; ++ } + proplen = (int)prop_count; + props_start = count_ptr + PROP_COUNT_SIZE; + +@@ -1235,6 +1241,11 @@ get_text_props(buf_T *buf, linenr_T lnum, char_u **props, int will_change) + return 0; + } + mch_memmove(&prop_count, text + textlen, PROP_COUNT_SIZE); ++ if (!text_prop_count_valid(prop_count, propdata_len)) ++ { ++ iemsg(e_text_property_info_corrupted); ++ return 0; ++ } + *props = text + textlen + PROP_COUNT_SIZE; + return (int)prop_count; + } +@@ -3219,4 +3230,13 @@ prepend_joined_props( + um_abort(&r_um); + } + ++ bool ++text_prop_count_valid(int prop_count, size_t propdata_len) ++{ ++ if (propdata_len < PROP_COUNT_SIZE) ++ return false; ++ return (size_t)prop_count * sizeof(textprop_T) ++ <= propdata_len - PROP_COUNT_SIZE; ++} ++ + #endif // FEAT_PROP_POPUP +-- +2.43.0 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index ecdf7cb5b9..b9acb4665a 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -26,6 +26,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-55693.patch \ file://CVE-2026-55895.patch \ file://CVE-2026-57453.patch \ + file://CVE-2026-57451.patch \ " PV .= ".0340" From patchwork Wed Jul 22 12:33:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Vijay Anusuri X-Patchwork-Id: 93210 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 05098C44539 for ; Wed, 22 Jul 2026 12:34:14 +0000 (UTC) Received: from mail-pj1-f54.google.com (mail-pj1-f54.google.com [209.85.216.54]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.46870.1784723651552148401 for ; Wed, 22 Jul 2026 05:34:11 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=L0jcsax9; spf=pass (domain: mvista.com, ip: 209.85.216.54, mailfrom: vanusuri@mvista.com) Received: by mail-pj1-f54.google.com with SMTP id 98e67ed59e1d1-38e69bdb0fcso2995417a91.1 for ; Wed, 22 Jul 2026 05:34:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784723651; x=1785328451; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Jl5kDnmptWSvW3cGszFh1bofuhs3I6n528+31ILh8cE=; b=L0jcsax9Op2A5AfYanwAXnEFZKeDqhUHxdJUS4Mq2fpKoRAFxJHkJd7fVLNj7VBmFe eB2/o0yPi37rDSUvvze4kpX+hgYDcYoVoQYncXcdwVmcuiiZN9pR2wsIGiUqNzP1rjHf 1dHjxNB94mwSY9Sf+bQ5nIU0gy4LgZlgsmuSA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784723651; x=1785328451; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Jl5kDnmptWSvW3cGszFh1bofuhs3I6n528+31ILh8cE=; b=hBDgMHJcFeItcbnB5zGEPFQYYN1Vdi1nSNV4JBs803T13ll5gegqbXApzM4ULq0hct 0hIvWrALjM9SJJM76sWf/JqQh7G+ymtb+TDrhDVqN53w9eh+5nwynY/OfwWn57WF/1rC OHF8/5w7NhOLclIQsqzajZZ0fqjLrNn6c7OIxvchDk7ImLxNmZNDDjVsgkGjrmr5i2Rd WZH2H3udrsIVvtIbbeJEYxd2DSQRGkW9wbrlw5siBzc9QddOI+fv5k/XQRpmwnvGllG9 Q35Pa+SD/q9fMditVSkmxYU2JODPpN5yb8G1X+02G3iwRVs/qH0vYFhzJtwJ8W9Bs1gH 8HlQ== X-Gm-Message-State: AOJu0YyLXX6u8+T2arHMKGopq2nl11pn+USalO65XHuKLQcveTyPgr9q QzBT06CBN7+1ktarvJYBtrlMN8i0BtsBX/9BmTdkZSkjpQXvvnAnUN7a+S2om5pnY34HS6pwT/D FVAGdsZM= X-Gm-Gg: AR+sD11w+WsPaFDnPiLZAuPSnXR7NiOB3BfrGVLJ7wjypCdmEQNadi+6I9MLZPbtcua VqqPhgqctBfY1dTS3yivIWERiKs8vn5QEjf7FCBflgQtIn/4atCD2Mr0rS4JddUlkSdr5YIpVr5 84ffgfyrXhFujBlGJ9Ehsg/lJIwNeqy+aOsYQePdRNcJNEGrIf7bKlOazaYl7Jx50FvGGZhxCrM u/FY8TMa1OXy+9Iv6kAPNamR0ouPxNVkNW+bdZHtU6UDrGqTJ4C3Req0qCUQNXaxwKqDLLWb0B7 s9Gzu3O/5yvtTWZEyI+tnUv359fIRMu1+MI0hXVBiF32ByB7Ak2ofFR47xkQy4krj3K3TZq2anA /UyuDoCpETnvuRNF4tTGdFtWonuG4EmvbObWwlJ2JWp5L8w38bJVqw7Ozi67hFirEXeOKpnAXPP r6UGK40NR3qS89XSv406bBA4DZ5vA= X-Received: by 2002:a17:90b:3b48:b0:38e:a555:8fc3 with SMTP id 98e67ed59e1d1-38ea5558fffmr3165660a91.41.1784723650730; Wed, 22 Jul 2026 05:34:10 -0700 (PDT) Received: from MVIN00352.mvista.com ([2401:4900:1f29:92d:e2c5:62da:989e:f39a]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13d130262d2sm5823414c88.7.2026.07.22.05.34.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 05:34:09 -0700 (PDT) From: Vijay Anusuri To: openembedded-core@lists.openembedded.org Cc: Vijay Anusuri Subject: [OE-core][wrynose][patch 05/10] vim: Fix CVE-2026-57454 Date: Wed, 22 Jul 2026 18:03:31 +0530 Message-ID: <20260722123336.587556-5-vanusuri@mvista.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260722123336.587556-1-vanusuri@mvista.com> References: <20260722123336.587556-1-vanusuri@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 12:34:14 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241673 Pick patch per [1]. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57454 [2] https://security-tracker.debian.org/tracker/CVE-2026-57454 Signed-off-by: Vijay Anusuri --- .../vim/files/CVE-2026-57454.patch | 188 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 189 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-57454.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-57454.patch b/meta/recipes-support/vim/files/CVE-2026-57454.patch new file mode 100644 index 0000000000..579ffbf11b --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-57454.patch @@ -0,0 +1,188 @@ +From b3faeecc976d3031d7c0675623516ec60c30f949 Mon Sep 17 00:00:00 2001 +From: Hirohito Higashi +Date: Sat, 20 Jun 2026 16:06:58 +0000 +Subject: [PATCH] patch 9.2.0679: [security]: Out-of-bounds read with text + property virtual text + +Problem: [security]: Out-of-bounds read with text property virtual text. + A crafted undo file can declare a virtual-text property whose + offset points outside the line's property data, so reading the + virtual text reads out of bounds. This completes the count-only + check added in 9.2.0670. +Solution: Validate the virtual-text offset and length of each property + against the available property data before turning the offset + into a pointer. + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-ww8h-47xp-hp4w + +Co-Authored-By: Claude Opus 4.8 (1M context) +Signed-off-by: Hirohito Higashi +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/b3faeecc976d3031d7c0675623516ec60c30f949] +CVE: CVE-2026-57454 +Signed-off-by: Vijay Anusuri +--- + src/proto/textprop.pro | 1 + + src/testdir/test_textprop2.vim | 60 ++++++++++++++++++++++++++++++---- + src/textprop.c | 36 ++++++++++++++++++++ + 3 files changed, 90 insertions(+), 7 deletions(-) + +diff --git a/src/proto/textprop.pro b/src/proto/textprop.pro +index a01c2f3b2d..4e6fcc89a4 100644 +--- a/src/proto/textprop.pro ++++ b/src/proto/textprop.pro +@@ -36,4 +36,5 @@ int adjust_prop_columns(linenr_T lnum, colnr_T col, int bytes_added, int flags); + void adjust_props_for_split(linenr_T lnum_props, linenr_T lnum_top, int kept, int deleted, int at_eol); + void prepend_joined_props(unpacked_memline_T *um, linenr_T lnum, int last_line, long col, int removed); + bool text_prop_count_valid(int prop_count, size_t propdata_len); ++bool text_prop_vtext_valid(char_u *props, int prop_count, size_t propdata_len); + /* vim: set ft=c : */ +diff --git a/src/testdir/test_textprop2.vim b/src/testdir/test_textprop2.vim +index 48387d1c04..689096209c 100644 +--- a/src/testdir/test_textprop2.vim ++++ b/src/testdir/test_textprop2.vim +@@ -428,14 +428,12 @@ func Test_multiline_prop_delete_penultimate_line() + call s:CleanupPropTypes(['1', '2', '3']) + endfunc + +-func s:ManipulateUndoBlob(name) +- " Patch the saved old line in the undo file: +- " 00 00 00 08 'QQQQQQQQ' -> 00 00 00 27 'AAAA' NUL count=0xFFFF <32x00> +- " i.e. textlen 8 text-only -> 39-byte blob: text "AAAA", NUL, prop_count +- " 0xFFFF, one zeroed textprop_T(32). propdata_len becomes 34, count 65535. ++func s:ManipulateUndoBlob(name, repl) ++ " Replace the saved old line (00 00 00 08 'QQQQQQQQ') in the undo file with ++ " the crafted "repl" blob, then read it back in. + let blob = readfile(a:name, 'B') + let marker = 0z000000085151515151515151 +- let repl = 0z000000274141414100FFFF + repeat(0z00, 32) ++ let repl = a:repl + let mlen = len(marker) + let idx = -1 + let i = 0 +@@ -466,7 +464,10 @@ func Test_textprop_undo_bad_prop_count() + let &ul = &ul + call setline(1, 'BBBB') " undo step saves old line 1 = "QQQQQQQQ" + wundo Xtpundo +- call s:ManipulateUndoBlob('Xtpundo') ++ " 39-byte blob: "AAAA" NUL count=0xFFFF, one zeroed textprop_T(32). ++ " propdata_len becomes 34 while the count claims 65535 properties. ++ call s:ManipulateUndoBlob('Xtpundo', 0z000000274141414100FFFF ++ \ + repeat(0z00, 32)) + + undo + +@@ -487,4 +488,49 @@ func Test_textprop_undo_bad_prop_count() + call delete('Xtpundo') + endfunc + ++" A crafted undo file can restore a line whose virtual-text property declares an ++" out-of-range tp_text_offset. Turning that offset into a pointer and reading ++" the virtual text would read past the line buffer. Restore such a line and ++" force a consumer; reaching the asserts (no ASan abort / crash) means the ++" offset is bounded. ++func Test_textprop_undo_bad_vtext_offset() ++ CheckFeature persistent_undo ++ ++ new ++ call setline(1, ['QQQQQQQQ', 'DECOYLINE']) ++ let &ul = &ul ++ call setline(1, 'BBBB') " undo step saves old line 1 = "QQQQQQQQ" ++ wundo Xtpundo ++ ++ " One textprop_T for a virtual text prop (tp_id < 0) whose tp_text_offset ++ " (0x00100000) points far past the 34-byte property data. The count (1) is ++ " valid, so only the offset/length check can reject this. ++ let prop = 0z01000000 " tp_col = 1 ++ let prop += 0z04000000 " tp_len = 4 ++ let prop += 0zFFFFFFFF " tp_id = -1 (virtual text) ++ let prop += 0z00000000 " tp_type = 0 ++ let prop += 0z00000000 " tp_flags = 0 ++ let prop += 0z00000000 " tp_padleft = 0 ++ let prop += 0z00001000 " u.tp_text_offset = 0x00100000 ++ let prop += 0z00000000 " union upper bytes ++ call s:ManipulateUndoBlob('Xtpundo', 0z000000274141414100 + 0z0100 + prop) ++ ++ undo ++ ++ " Safety: prove the malicious line was actually restored before the consumer ++ " runs, so the test can't pass vacuously if the patch missed. ++ call assert_equal('AAAA', getline(1)) ++ ++ call prop_type_add('Xtp', {}) ++ call prop_add(2, 1, {'type': 'Xtp', 'length': 1}) ++ ++ " this caused OOB read, now it is rejected as a corrupted (untrusted) undo ++ " file with a catchable error ++ call assert_fails('call prop_list(1)', 'E967:') ++ ++ call prop_type_delete('Xtp') ++ bwipe! ++ call delete('Xtpundo') ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +diff --git a/src/textprop.c b/src/textprop.c +index 931fb78d25..463a477e4d 100644 +--- a/src/textprop.c ++++ b/src/textprop.c +@@ -118,6 +118,13 @@ um_goto_line(unpacked_memline_T *um, linenr_T lnum, int extra_props) + proplen = (int)prop_count; + props_start = count_ptr + PROP_COUNT_SIZE; + ++ if (!text_prop_vtext_valid(props_start, proplen, propdata_len)) ++ { ++ emsg(e_text_property_info_corrupted); ++ um->buf = NULL; ++ return false; ++ } ++ + um->props = ALLOC_MULT(textprop_T, proplen + extra_props); + if (um->props == NULL) + { +@@ -1246,6 +1253,12 @@ get_text_props(buf_T *buf, linenr_T lnum, char_u **props, int will_change) + iemsg(e_text_property_info_corrupted); + return 0; + } ++ if (!text_prop_vtext_valid(text + textlen + PROP_COUNT_SIZE, ++ (int)prop_count, propdata_len)) ++ { ++ emsg(e_text_property_info_corrupted); ++ return 0; ++ } + *props = text + textlen + PROP_COUNT_SIZE; + return (int)prop_count; + } +@@ -3239,4 +3252,27 @@ text_prop_count_valid(int prop_count, size_t propdata_len) + <= propdata_len - PROP_COUNT_SIZE; + } + ++/* ++ * Return true when every virtual text property's offset and length stay within ++ * "propdata_len", so tp_text_offset can be safely turned into a pointer. ++ * "props" may be unaligned. ++ */ ++ bool ++text_prop_vtext_valid(char_u *props, int prop_count, size_t propdata_len) ++{ ++ for (int i = 0; i < prop_count; ++i) ++ { ++ textprop_T prop; ++ ++ mch_memmove(&prop, props + (size_t)i * sizeof(textprop_T), ++ sizeof(textprop_T)); ++ if (prop.tp_id >= 0 || prop.u.tp_text_offset <= 0) ++ continue; ++ if (prop.tp_len < 0 || (size_t)prop.u.tp_text_offset ++ + (size_t)prop.tp_len + 1 > propdata_len) ++ return false; ++ } ++ return true; ++} ++ + #endif // FEAT_PROP_POPUP +-- +2.43.0 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index b9acb4665a..82f63f6067 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -27,6 +27,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-55895.patch \ file://CVE-2026-57453.patch \ file://CVE-2026-57451.patch \ + file://CVE-2026-57454.patch \ " PV .= ".0340" From patchwork Wed Jul 22 12:33:32 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Vijay Anusuri X-Patchwork-Id: 93212 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0EADFC4453C for ; Wed, 22 Jul 2026 12:34:24 +0000 (UTC) Received: from mail-pj1-f50.google.com (mail-pj1-f50.google.com [209.85.216.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.46871.1784723655361029236 for ; Wed, 22 Jul 2026 05:34:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=L28X0mYU; spf=pass (domain: mvista.com, ip: 209.85.216.50, mailfrom: vanusuri@mvista.com) Received: by mail-pj1-f50.google.com with SMTP id 98e67ed59e1d1-38dcbade417so10738804a91.1 for ; Wed, 22 Jul 2026 05:34:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784723655; x=1785328455; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=dP+I5WFwGkJ7NvOLxOXBkTLQIBteIU7BYPG5ytKdAdc=; b=L28X0mYULPHq5dl/071841AlQzUS4uDM7zyZvBYRTHC/Mjjvxe65/RRMxruAS+H7xm y4tZSw1MjHQ5pqGpg9AJhA8yfSQxXH6npVy4jtBsGpAmgEBgG/BcreYw/LfWCieMOAMu OMt59b2T5FtjPWX8uNz3jyuKg7wHsjyu5cooQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784723655; x=1785328455; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=dP+I5WFwGkJ7NvOLxOXBkTLQIBteIU7BYPG5ytKdAdc=; b=rehAvAHBIu+PsMLTTOvGIiXgqkhm0QEzKfXDXUmf1+mnTSO59fUOMlknP69Bl2S0UN b9XzuwaYhnOpm9TZVjIKBklUSGT1mDn+hMUzysP4+gLWmk3XTnX9GY06AOzziQ57D8wB OYpHLxZrYk7xDzgNDA8w56ZZEp03u+WRn2Dlm9M6RI/Sdz2EqOHgZxJNZgE4AwgLP6bC QvbzTAxO/MFqw+4v+AJt8LiUPqPybMZ16vaAjNdGBkCA9gx7RYpyWLxS4YEr/gRWB/zW 3wGsYegVcoHq4oeWaZxxEkMfLrkgdsbPbC11dRXUe8NXjNq+9jUSM2eC9e+WpSgE9hlM GbMQ== X-Gm-Message-State: AOJu0YyKPyA3xP0lP6W25hpxn1Y3hIodHnjbAU4Cch0NbxeRFY9rN5Oh +sFhyPSoYdC1nVn2BeMDRd1UMnPX3hKwHhlzWTamj0h7RRCNQlxO06fF9O5Nkn1aYRrxHLzNWWA gbT9b2gQ= X-Gm-Gg: AR+sD12NjGr5qlBRHBE5NxVpu2j09aVe+akLBAIE/ZDU6R3nG6qH9Bt3jkECXzrGIU/ uE+evsV8KUPjQeL+rOhvyzJr8Q1bu3H4CQOuWKAKH/xbsCvzwX044k93bHuyQwe0fnP+cJ+7vuc Umiy87SAPraexyBRFWZgsVaN0Tcl25CFe64IV32eSBilraA78PNgbnMxf7G+TyHCT83B0rShcNG za+YoDlcCmHvg9bx8aUBEqUfpvOiJUXYwJqDYou9tG9Avnv05T7W//ignr6AsSVYIEPK5rZl+9G zGUlp9nQZn6uxtKH1c/yPmobH1jcouwwN+Qhbr7PKmDDX72LgbJDlj3fFHu5XKi4+9yqgi29vDk 9QTBVCHkaurRyT9E4S3YQ7UGRMs2/D8pumN477opiqpQXBYDKjg59Ss5J0WhiYmFzjhbS1dX43/ DyFwRsx0Dd6hFuNmvr X-Received: by 2002:a17:90b:544f:b0:38e:dc4:3fbb with SMTP id 98e67ed59e1d1-38e4b5b7637mr23026303a91.43.1784723654625; Wed, 22 Jul 2026 05:34:14 -0700 (PDT) Received: from MVIN00352.mvista.com ([2401:4900:1f29:92d:e2c5:62da:989e:f39a]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13d130262d2sm5823414c88.7.2026.07.22.05.34.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 05:34:13 -0700 (PDT) From: Vijay Anusuri To: openembedded-core@lists.openembedded.org Cc: Vijay Anusuri Subject: [OE-core][wrynose][patch 06/10] vim: Fix CVE-2026-57455 Date: Wed, 22 Jul 2026 18:03:32 +0530 Message-ID: <20260722123336.587556-6-vanusuri@mvista.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260722123336.587556-1-vanusuri@mvista.com> References: <20260722123336.587556-1-vanusuri@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 12:34:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241674 Pick patch per [1]. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57455 [2] https://security-tracker.debian.org/tracker/CVE-2026-57455 Signed-off-by: Vijay Anusuri --- .../vim/files/CVE-2026-57455.patch | 72 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 73 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-57455.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-57455.patch b/meta/recipes-support/vim/files/CVE-2026-57455.patch new file mode 100644 index 0000000000..51f0eb7fe0 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-57455.patch @@ -0,0 +1,72 @@ +From 497f931f85339d175d7f69588dd249e8ccfed41b Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Sun, 21 Jun 2026 19:20:03 +0000 +Subject: [PATCH] patch 9.2.0698: [security]: Out-of-bounds write with + soundfold() + +Problem: [security]: Out-of-bounds write with soundfold() + (cipher-creator) +Solution: Add an abort condition to the for loop to validate the buffer + size. + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-q8mh-6qm3-25g4 + +Supported by AI + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/497f931f85339d175d7f69588dd249e8ccfed41b] +CVE: CVE-2026-57455 +Signed-off-by: Vijay Anusuri +--- + src/spell.c | 2 +- + src/testdir/test_spellfile.vim | 21 +++++++++++++++++++++ + 2 files changed, 22 insertions(+), 1 deletion(-) + +diff --git a/src/spell.c b/src/spell.c +index 01eb57e3a9..060a2251a4 100644 +--- a/src/spell.c ++++ b/src/spell.c +@@ -3270,7 +3270,7 @@ spell_soundfold_sofo(slang_T *slang, char_u *inword, char_u *res) + else + { + // The sl_sal_first[] table contains the translation. +- for (s = inword; (c = *s) != NUL; ++s) ++ for (s = inword; (c = *s) != NUL && ri < MAXWLEN - 1; ++s) + { + if (VIM_ISWHITE(c)) + c = ' '; +diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim +index 4da270acea..c0c46a32d2 100644 +--- a/src/testdir/test_spellfile.vim ++++ b/src/testdir/test_spellfile.vim +@@ -1223,4 +1223,25 @@ func Test_spell_sug_tree_count_words_overflow() + bwipe! + endfunc + ++" A word longer than MAXWLEN must not overflow the soundfold result buffer in ++" the single-byte SOFO branch of spell_soundfold_sofo(). ++func Test_soundfold_overflow() ++ let _enc=&enc ++ set enc=latin1 ++ call writefile(['SOFOFROM ab', 'SOFOTO xy'], 'Xtest.aff', 'D') ++ call writefile(['1', 'foo'], 'Xtest.dic', 'D') ++ mkspell! Xtest Xtest ++ defer delete('Xtest.latin1.spl') ++ defer delete('Xtest.latin1.sug') ++ setl spelllang=Xtest.latin1.spl spell ++ ++ " Before the fix the copy loop wrote one byte per input byte into a ++ " MAXWLEN (254) stack buffer with no upper bound, smashing the stack. ++ let sound = soundfold(repeat('ab', 300)) ++ call assert_true(strlen(sound) < 254, 'soundfold result exceeds MAXWLEN') ++ ++ set spell& spelllang& ++ let &enc = _enc ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +-- +2.43.0 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 82f63f6067..dec5b68324 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -28,6 +28,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-57453.patch \ file://CVE-2026-57451.patch \ file://CVE-2026-57454.patch \ + file://CVE-2026-57455.patch \ " PV .= ".0340" From patchwork Wed Jul 22 12:33:33 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Vijay Anusuri X-Patchwork-Id: 93213 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 02578C44536 for ; Wed, 22 Jul 2026 12:34:24 +0000 (UTC) Received: from mail-pj1-f45.google.com (mail-pj1-f45.google.com [209.85.216.45]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.46872.1784723660712759588 for ; Wed, 22 Jul 2026 05:34:20 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=JGEGey/d; spf=pass (domain: mvista.com, ip: 209.85.216.45, mailfrom: vanusuri@mvista.com) Received: by mail-pj1-f45.google.com with SMTP id 98e67ed59e1d1-38a0c7e841fso10481343a91.2 for ; Wed, 22 Jul 2026 05:34:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784723660; x=1785328460; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=+r5PIA7wCrycVEPu00S4/NgGGLuCbdUWeaApKVSJCno=; b=JGEGey/dwb/DarXIGym2ju1qHtdc5g1Nu1VP54H6tMF6x5gUgzobErPqQWU4buu9J9 8xMw23cQih/duvBPlvjuQRcXh3W6RJKWEGUJ9yQbETnBLsc3WNGU1mQ8qujgIvLaqsV/ gSQncii69aevicDO0HyQr2qrbZizpQ4AUkR5c= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784723660; x=1785328460; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=+r5PIA7wCrycVEPu00S4/NgGGLuCbdUWeaApKVSJCno=; b=Fch3iTVMhEzi+8hY1B1aLfFbkTJAFuCIcYjtOfXFY9sAe/W/JBIdHrvma5S+Sk9Eg2 WkA8m/lDDpXJ6kJmIK5Y80e8fyzg1uZmLTyv2kXE25rWxloYPyNZ17jP7SSoTB0BLamL 2sSKOClByj21TEOIifYA91CX84aj2lNoserBr8SaL466f0/4qJH1lWNHIL6XxOD+/h5u fZo3wWk+abuPMjbF3PX7fYXUWCn6Ie35L5CjtjgyeSCHeLfzD1b3ynFNPbnwl6gzGSTM 4z937ZWgXop7q6QDW6yr5XnjoV8vf9pNePBKXg1mON4HP2l9OA6TLWVAwAi2VJWOOW8/ nLGg== X-Gm-Message-State: AOJu0YyDc/tvwZMEAIcOo7gtQfnO9rc/Rvg5zC4Mo9wX5oB4brHqA2Hw b5GL1KbjxheXBt4l0L3VdSpsLLf5u4aiKu0Ks+BrbxhUz4ZlgHesvuLbQC4XnuQ3oM9OMA6GkGw pfZMubwg= X-Gm-Gg: AR+sD11EUPe8nnm23lanuvs67z6dGRuQf/eiJzqG32nHKXmnzNfysg6XH9uka0uM5H0 X3UmanltU27zX8bNVLFIM6p2U8ZntMH+2qZlgONYxiPv3JnNafIqYkDaeer+27TcoPU04uNWHeE iND1OLNggTfmrKFZie4m0KdFnwISDc2FMT3TdGgPxpvaLRXunrP6fisLdPtFAe2Wli13F7I0xBZ M3Xif+msQaxyCSFKIUErhBG1WOfA513wG6i+8bU2LUx+RmNTk8lH0fctzHQz0j+DRFs+TBExGVb /mRDdIe5cKzpwH1glFSNfj5N7Swf1GmNcUgB0rqSxhWU1bJckX5D/+x24dbLsR/LRokxA4EfPit JpYBxDwh89/PmYzMYZy76wLYC/t1RADf4BASLVOboO+Cnme54lCR7wm8wwbaUQJeplJ2xsTktKX 7AhHpW2brFLhqHT1b64rod+Amb1dY= X-Received: by 2002:a17:90b:4d09:b0:38e:2fa0:491b with SMTP id 98e67ed59e1d1-38e4b594eb3mr23140973a91.31.1784723659850; Wed, 22 Jul 2026 05:34:19 -0700 (PDT) Received: from MVIN00352.mvista.com ([2401:4900:1f29:92d:e2c5:62da:989e:f39a]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13d130262d2sm5823414c88.7.2026.07.22.05.34.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 05:34:18 -0700 (PDT) From: Vijay Anusuri To: openembedded-core@lists.openembedded.org Cc: Vijay Anusuri Subject: [OE-core][wrynose][patch 07/10] vim: Fix CVE-2026-57456 Date: Wed, 22 Jul 2026 18:03:33 +0530 Message-ID: <20260722123336.587556-7-vanusuri@mvista.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260722123336.587556-1-vanusuri@mvista.com> References: <20260722123336.587556-1-vanusuri@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 12:34:24 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241675 Pick patch per [1]. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57456 [2] https://security-tracker.debian.org/tracker/CVE-2026-57456 Signed-off-by: Vijay Anusuri --- .../vim/files/CVE-2026-57456.patch | 149 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 150 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-57456.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-57456.patch b/meta/recipes-support/vim/files/CVE-2026-57456.patch new file mode 100644 index 0000000000..9a4155ef04 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-57456.patch @@ -0,0 +1,149 @@ +From cce141c42740f122dd8486ae04e21c2a81016ba8 Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Sun, 21 Jun 2026 19:50:56 +0000 +Subject: [PATCH] patch 9.2.0699: [security]: possible code execution with + python complete + +Problem: [security]: possible code execution with python complete + (morningbread) +Solution: Use repr() to quote the doc strings correctly + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-ppj8-wqjf-6fp3 + +Supported by AI + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/cce141c42740f122dd8486ae04e21c2a81016ba8] +CVE: CVE-2026-57456 +Signed-off-by: Vijay Anusuri +--- + runtime/autoload/python3complete.vim | 9 +++++---- + runtime/autoload/pythoncomplete.vim | 9 +++++---- + src/testdir/test_plugin_python3complete.vim | 15 +++++++++++++++ + 3 files changed, 25 insertions(+), 8 deletions(-) + +diff --git a/runtime/autoload/python3complete.vim b/runtime/autoload/python3complete.vim +index c4ef19d82f..f90cca74b3 100644 +--- a/runtime/autoload/python3complete.vim ++++ b/runtime/autoload/python3complete.vim +@@ -2,7 +2,7 @@ + " Maintainer: + " Previous Maintainer: Aaron Griffin + " Version: 0.10 +-" Last Updated: 2026 Jun 04 ++" Last Updated: 2026 Jun 21 + " + " Roland Puntaier: this file contains adaptations for python3 and is parallel to pythoncomplete.vim + " +@@ -22,6 +22,7 @@ + " previous code passed buffer-supplied expressions to exec() which + " Python evaluates at definition time, allowing arbitrary code + " execution via crafted def/class headers ++" * use repr() on doc strings to prevent code execution + " + " v 0.9 + " * Fixed docstring parsing for classes and functions +@@ -335,7 +336,7 @@ class Scope(object): + + def get_code(self): + str = "" +- if len(self.docstr) > 0: str += '"""'+self.docstr+'"""\n' ++ if len(self.docstr) > 0: str += repr(self.docstr)+'\n' + str += 'class _PyCmplNoType:\n def __getattr__(self,name):\n return None\n' + for sub in self.subscopes: + str += sub.get_code() +@@ -378,7 +379,7 @@ class Class(Scope): + if _DOTTED_NAME_RE.match(s.strip())] + if len(safe_supers) > 0: str += '(%s)' % ','.join(safe_supers) + str += ':\n' +- if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n' ++ if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n' + if len(self.subscopes) > 0: + for s in self.subscopes: str += s.get_code() + else: +@@ -401,7 +402,7 @@ class Function(Scope): + safe_params = [p for p in safe_params if p] + str = "%sdef %s(%s):\n" % \ + (self.currentindent(),self.name,','.join(safe_params)) +- if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n' ++ if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n' + str += "%spass\n" % self.childindent() + return str + +diff --git a/runtime/autoload/pythoncomplete.vim b/runtime/autoload/pythoncomplete.vim +index 39b1efd299..d2f5d57b0c 100644 +--- a/runtime/autoload/pythoncomplete.vim ++++ b/runtime/autoload/pythoncomplete.vim +@@ -2,7 +2,7 @@ + " Maintainer: + " Previous Maintainer: Aaron Griffin + " Version: 0.10 +-" Last Updated: 2026 Jun 04 ++" Last Updated: 2026 Jun 21 + " + " Changes + " TODO: +@@ -20,6 +20,7 @@ + " previous code passed buffer-supplied expressions to exec() which + " Python evaluates at definition time, allowing arbitrary code + " execution via crafted def/class headers ++" * use repr() on doc strings to prevent code execution + " + " v 0.9 + " * Fixed docstring parsing for classes and functions +@@ -350,7 +351,7 @@ class Scope(object): + + def get_code(self): + str = "" +- if len(self.docstr) > 0: str += '"""'+self.docstr+'"""\n' ++ if len(self.docstr) > 0: str += repr(self.docstr)+'\n' + str += 'class _PyCmplNoType:\n def __getattr__(self,name):\n return None\n' + for sub in self.subscopes: + str += sub.get_code() +@@ -393,7 +394,7 @@ class Class(Scope): + if _DOTTED_NAME_RE.match(s.strip())] + if len(safe_supers) > 0: str += '(%s)' % ','.join(safe_supers) + str += ':\n' +- if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n' ++ if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n' + if len(self.subscopes) > 0: + for s in self.subscopes: str += s.get_code() + else: +@@ -416,7 +417,7 @@ class Function(Scope): + safe_params = [p for p in safe_params if p] + str = "%sdef %s(%s):\n" % \ + (self.currentindent(),self.name,','.join(safe_params)) +- if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n' ++ if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n' + str += "%spass\n" % self.childindent() + return str + +diff --git a/src/testdir/test_plugin_python3complete.vim b/src/testdir/test_plugin_python3complete.vim +index e2b0c6616d..590348ee4a 100644 +--- a/src/testdir/test_plugin_python3complete.vim ++++ b/src/testdir/test_plugin_python3complete.vim +@@ -221,4 +221,19 @@ func Test_python3complete_allow_import_on_runs_imports() + \ 'g:pythoncomplete_allow_import=1 did not run the buffer import') + endfunc + ++func Test_python3complete_no_exec_via_class_docstring() ++ " A class-body docstring is emitted verbatim between triple quotes by ++ " get_code() and runs at class-definition time during exec(). A single- ++ " quoted source docstring lets an embedded """ survive doc()'s leading/ ++ " trailing quote strip and break out of the generated literal. ++ let marker = tempname() ++ call s:CompleteAndExpectNoMarker([ ++ \ 'class Foo:', ++ \ ' ''x"""+open("' . marker . '", "w").close()+"""y''', ++ \ ' pass', ++ \ 'Foo.', ++ \ ], marker, ++ \ 'class docstring expression was evaluated during omni-completion') ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +-- +2.43.0 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index dec5b68324..008dbdb8df 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -29,6 +29,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-57451.patch \ file://CVE-2026-57454.patch \ file://CVE-2026-57455.patch \ + file://CVE-2026-57456.patch \ " PV .= ".0340" From patchwork Wed Jul 22 12:33:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Vijay Anusuri X-Patchwork-Id: 93214 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0A23FC44536 for ; Wed, 22 Jul 2026 12:34:34 +0000 (UTC) Received: from mail-pj1-f48.google.com (mail-pj1-f48.google.com [209.85.216.48]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.47126.1784723666116259652 for ; Wed, 22 Jul 2026 05:34:26 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=cMiry6tm; spf=pass (domain: mvista.com, ip: 209.85.216.48, mailfrom: vanusuri@mvista.com) Received: by mail-pj1-f48.google.com with SMTP id 98e67ed59e1d1-38e347638adso7556000a91.0 for ; Wed, 22 Jul 2026 05:34:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784723665; x=1785328465; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=OhtQIebtHCUf5i1JGKj3dT/7bvnIDHWmD/WeMpaY2Yw=; b=cMiry6tms9MMwrfPV6i6lNIXIOHeXIORb6yHyNWtZVUVleeFEAczMjmWt5+jSKyYZe yH21Oce+wk+zm3MTkYSKbtalSTOsOb+BJ2nq6Vo4AuNhrPpyYz19as88npxr6UHeOkUK MZLMzk1vO43iEMkbSG4l8avJwtPP2YyDeVMHA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784723665; x=1785328465; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=OhtQIebtHCUf5i1JGKj3dT/7bvnIDHWmD/WeMpaY2Yw=; b=EbzHGjNsTJvQelIKrCA3lbTD5afUiGpbUIJqoNJJBRG6wMxv26cZl+GchfqN1ynOlU E+FWswJWW7odInGNGzuRJ+W5OQEk7I8LowWO/LhaUFQzMMX6jcNSioo6u/dndFDSrHft eVbBmpRKm3fG7Tl9QMDdH0VjdpfDUmbSnGbGrN2a4gBFSLkprcw28NkbUTQt2rlo1GVB jMnLrV7yk6c2N3meSDsbz4sf9TLGl4MSy1nAPnPrcUr8fblkON9YH2f/9MtWkCb78tfA VfDs//GYC6AtgLVQ5P+5GiYSbNrHfXqIsF6ALAlQ+Py91Mt1sHPnbStBpGphVuZTbvCs zw4g== X-Gm-Message-State: AOJu0Yx11b0SwQwO7/YT7zhgRw0oEd3g79vhmOyM2/gE0Kk9EKGmZyzo PRoKPdRrKfQrEou1CTGDzibZXvYW7S0zQjFNXv5Lfhbe1UQ8O91LgxplbHp6xdzqlakn7Q3bBs8 ukIRC5Fg= X-Gm-Gg: AR+sD12qV2s2dDbl+MAsj9gF+CAOk1D+ZiloEYOotstEKZnAovM/zpzP83weGRVNT6o bEKSeQrlENZLv/1SE2X+7LDKcpXHEUnUDwrokMSLZEnvS3ukLYsIYw2Pfcic04ceiSxdg2qAebe x1X4GLl+F5ys45P/E7Q5OBPM18+3hMBEZfcpuUbdqMvvtCfWZNCiJ15URroR05LSG0+lpAb1UzU wCth88ssFf7ykE9PdVWvYczhvn4n4eA30OgMCsjlQZ4AUz8c3UROh9Th5zdVQ8zkxgsy1Ni8v0V hRFRH+PmRZwd0pXvTb9KgSNI9hCTu8iXVfQqIJaMFweBgvgZol7RM432pb34jP69ukpXRZCAtCb BhmrtPX6vaLf7UGbG09TDU9w5iAjVzZpi1HBFuaBIjVK8UflaKlUh4/7FJuA2/0ZeLX6hJo+E+Y iNcsGIl9g0+MuE1w0O X-Received: by 2002:a17:90b:4d8f:b0:38e:b400:a860 with SMTP id 98e67ed59e1d1-38eb400a9camr839788a91.13.1784723665391; Wed, 22 Jul 2026 05:34:25 -0700 (PDT) Received: from MVIN00352.mvista.com ([2401:4900:1f29:92d:e2c5:62da:989e:f39a]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13d130262d2sm5823414c88.7.2026.07.22.05.34.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 05:34:24 -0700 (PDT) From: Vijay Anusuri To: openembedded-core@lists.openembedded.org Cc: Vijay Anusuri Subject: [OE-core][wrynose][patch 08/10] vim: Fix CVE-2026-59856 Date: Wed, 22 Jul 2026 18:03:34 +0530 Message-ID: <20260722123336.587556-8-vanusuri@mvista.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260722123336.587556-1-vanusuri@mvista.com> References: <20260722123336.587556-1-vanusuri@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 12:34:34 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241676 Pick patch per [1]. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-59856 [2] https://security-tracker.debian.org/tracker/CVE-2026-59856 Signed-off-by: Vijay Anusuri --- .../vim/files/CVE-2026-59856.patch | 103 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 104 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-59856.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-59856.patch b/meta/recipes-support/vim/files/CVE-2026-59856.patch new file mode 100644 index 0000000000..42636161d0 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-59856.patch @@ -0,0 +1,103 @@ +From 43afc581a37a35762dd0ef292f038b9dc5680a24 Mon Sep 17 00:00:00 2001 +From: Hirohito Higashi +Date: Fri, 26 Jun 2026 20:07:01 +0900 +Subject: [PATCH] patch 9.2.0736: potential command execution in PHP + omni-completion + +Problem: With PHP omni-completion, a crafted file can potentially + execute arbitrary commands when completing a class member. +Solution: Quote the class name before inserting it into the search() + pattern run via win_execute(). + +Co-Authored-By: Claude Opus 4.8 (1M context) +Signed-off-by: Hirohito Higashi +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/43afc581a37a35762dd0ef292f038b9dc5680a24] +CVE: CVE-2026-59856 +Signed-off-by: Vijay Anusuri +--- + runtime/autoload/phpcomplete.vim | 3 ++- + src/testdir/Make_all.mak | 2 ++ + src/testdir/test_plugin_phpcomplete.vim | 35 +++++++++++++++++++++++++ + 3 files changed, 39 insertions(+), 1 deletion(-) + create mode 100644 src/testdir/test_plugin_phpcomplete.vim + +diff --git a/runtime/autoload/phpcomplete.vim b/runtime/autoload/phpcomplete.vim +index 5b4263ae45..ec54352586 100644 +--- a/runtime/autoload/phpcomplete.vim ++++ b/runtime/autoload/phpcomplete.vim +@@ -2082,7 +2082,8 @@ function! phpcomplete#GetClassContentsStructure(file_path, file_lines, class_nam + let result = [] + let popup_id = popup_create(a:file_lines, {'hidden': v:true}) + +- call win_execute(popup_id, 'call search(''\c\(class\|interface\|trait\)\_s\+'.a:class_name.'\(\>\|$\)'')') ++ call win_execute(popup_id, 'call search(' ++ \ . string('\c\(class\|interface\|trait\)\_s\+' . a:class_name . '\(\>\|$\)') . ')') + call win_execute(popup_id, "let cfline = line('.')") + call win_execute(popup_id, "call search('{')") + call win_execute(popup_id, "let endline = line('.')") +diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak +index b06d1af431..b5735b6c3c 100644 +--- a/src/testdir/Make_all.mak ++++ b/src/testdir/Make_all.mak +@@ -250,6 +250,7 @@ NEW_TESTS = \ + test_plugin_man \ + test_plugin_matchparen \ + test_plugin_netrw \ ++ test_plugin_phpcomplete \ + test_plugin_python3complete \ + test_plugin_osc52 \ + test_plugin_tar \ +@@ -529,6 +530,7 @@ NEW_TESTS_RES = \ + test_plugin_man.res \ + test_plugin_matchparen.res \ + test_plugin_netrw.res \ ++ test_plugin_phpcomplete.res \ + test_plugin_python3complete.res \ + test_plugin_osc52.res \ + test_plugin_tar.res \ +diff --git a/src/testdir/test_plugin_phpcomplete.vim b/src/testdir/test_plugin_phpcomplete.vim +new file mode 100644 +index 0000000000..7f66be47b7 +--- /dev/null ++++ b/src/testdir/test_plugin_phpcomplete.vim +@@ -0,0 +1,35 @@ ++" Tests for the PHP omni-completion plugin (runtime/autoload/phpcomplete.vim). ++ ++" A buffer class name is interpolated into a search() pattern run via ++" win_execute(). Without escaping, "'" closes the string and "|" starts a new ++" Ex command, so the name runs as an Ex command during completion. ++func Test_phpcomplete_no_exec_via_class_name() ++ unlet! g:phpcomplete_injected ++ let lines = [' 0, 'no class structure returned') ++ call assert_match('class Foo', result[0].content, ++ \ 'class body missing from returned content') ++ call assert_match('bar', result[0].content, ++ \ 'class member missing from returned content') ++endfunc ++ ++" vim: shiftwidth=2 sts=2 expandtab +-- +2.43.0 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 008dbdb8df..b9f8e40a28 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -30,6 +30,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-57454.patch \ file://CVE-2026-57455.patch \ file://CVE-2026-57456.patch \ + file://CVE-2026-59856.patch \ " PV .= ".0340" From patchwork Wed Jul 22 12:33:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Vijay Anusuri X-Patchwork-Id: 93215 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 03515C44539 for ; Wed, 22 Jul 2026 12:34:34 +0000 (UTC) Received: from mail-pg1-f176.google.com (mail-pg1-f176.google.com [209.85.215.176]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.47128.1784723670676357573 for ; Wed, 22 Jul 2026 05:34:30 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=Twe3NHWH; spf=pass (domain: mvista.com, ip: 209.85.215.176, mailfrom: vanusuri@mvista.com) Received: by mail-pg1-f176.google.com with SMTP id 41be03b00d2f7-cb5b8572b70so4050446a12.2 for ; Wed, 22 Jul 2026 05:34:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784723670; x=1785328470; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=+fH7whDIH9xzshCdb2nc6nk+OkEZt/O3UGVkrfTTRZs=; b=Twe3NHWHpSE3i4ptygAsJ8/+/ubk5658MSqSwsK9Y7DRBn0dl+x0rqcMvBCKGyn3Jx sOBlLJGl5Ho6ZKGKqMR2sjdX8ENyDExd5B5yXknA2q90zKU4Fufgye3TeniCGjT3BAXF Q0GbHvswvV7F5/ky9OhUXN3Ah5Q0PpA4ZjK90= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784723670; x=1785328470; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=+fH7whDIH9xzshCdb2nc6nk+OkEZt/O3UGVkrfTTRZs=; b=jGV7IYx9o9rz9IRBKzgKlyEqXRp0uic40cot5VjdW7amSxwSWCR8QUvpjfr9Iu2vNd L1qMLClXypAtwcgx0IkhJT+ckkY/DmkyW74oxVEhYP+S6hEkty9kFTe7BSIY0oRgcDJv kKNWrUGvPMlYwAa9LT3GHc68aOYFtBi24+ACY0LFm+Dx+YjllG/GZU3xdVKICLizlmJ4 7D+5z4M0NZSPcKcqHnkNLB4EnSUW8XZV9zH1RZDQd+oj8sv+4I2NchasN8+sgq8RpQy/ K4NXJbLY1GTeyL8JTSc+ducWXjuXN944mq790De+FONUrEBA1hUCTSWBmMdTw3ZECqsu 9d8w== X-Gm-Message-State: AOJu0Yx/xsWn/t0VXn2aybTXup/UPnNDMgHReZWUd4T43LMLO6+KzVhu FpF9vYTeknYhT05zWLwvuoRts5AXdlNppmH6fhae+droU/vjrOPaIs1BPpZ9tvdOQt3jUUSpD1+ kd5oM6qo= X-Gm-Gg: AR+sD13b1kWeKA7Zjqs7nSMwrt1q+FANqs2azGiQqlnMybHHhNzvEb4MbW6BCxgCytG ru4QrQgYxWCZ90m7kWQ++JXxPG/3xJxC+SxvZoTEKSZHYE+O0fVyoKtL2ycseQMYM+Y1xdk01uh 6aR1V/Nb99ZtCp5coZLl0nuQGyRPNTwpmGi4ztPupCY+pGTMD2OBmiNq21R/LjzU2MehEPJn3LY 8WdTPuTAqW7ydGWGiFIxTv/v+3axHkQ5xgWmczC7YHGUkL5gAJMBRbpaKDtgasmaxvE0jO+6sHX kXvxvoyNT1ZSPTeniGZgriH0VeZUx++AGchBKIWKTVpy5LVk1jmsSfdJ8uVmDX7YaE8jwK2r4zw k1UFGmA3dS0c2k7p7K428ZvNVm1rS73hUXEKe+fojWKea4B+hwEHVWgS3hylyO+4Jums/Mk7gT0 ttehViDbl7MIdjw/7x2f0FNCyKxaY= X-Received: by 2002:a17:90b:2f85:b0:38e:1497:af5b with SMTP id 98e67ed59e1d1-38e4b3e1015mr22028526a91.1.1784723670025; Wed, 22 Jul 2026 05:34:30 -0700 (PDT) Received: from MVIN00352.mvista.com ([2401:4900:1f29:92d:e2c5:62da:989e:f39a]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13d130262d2sm5823414c88.7.2026.07.22.05.34.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 05:34:29 -0700 (PDT) From: Vijay Anusuri To: openembedded-core@lists.openembedded.org Cc: Vijay Anusuri Subject: [OE-core][wrynose][patch 09/10] vim: Fix CVE-2026-59857 Date: Wed, 22 Jul 2026 18:03:35 +0530 Message-ID: <20260722123336.587556-9-vanusuri@mvista.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260722123336.587556-1-vanusuri@mvista.com> References: <20260722123336.587556-1-vanusuri@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 12:34:34 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241677 Pick patch per [1]. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-59857 [2] https://security-tracker.debian.org/tracker/CVE-2026-59857 Signed-off-by: Vijay Anusuri --- .../vim/files/CVE-2026-59857.patch | 110 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 111 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-59857.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-59857.patch b/meta/recipes-support/vim/files/CVE-2026-59857.patch new file mode 100644 index 0000000000..aa1f0725b5 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-59857.patch @@ -0,0 +1,110 @@ +From d22ff1c955ff87e8273210eae125aab0e85b6c30 Mon Sep 17 00:00:00 2001 +From: Hirohito Higashi +Date: Mon, 22 Jun 2026 13:00:36 +0900 +Subject: [PATCH] patch 9.2.0725: [security]: Stack out-of-bounds write in + spell_soundfold_sal() + +Problem: [security]: A crafted spell file with non-collapsing SAL rules + can make soundfold() write one byte past the end of the + MAXWLEN result buffer. This is the same class of + out-of-bounds write as GHSA-q8mh-6qm3-25g4 (fixed in 9.2.0698 + for the SOFO branch), found while auditing the surrounding + code. +Solution: Bound the single-byte SAL result writes and the terminating + NUL to MAXWLEN - 1, matching the SOFO branch. + +The single-byte branch of spell_soundfold_sal() guarded its writes with +"reslen < MAXWLEN", allowing reslen to reach MAXWLEN (254). The trailing +"res[reslen] = NUL" then wrote at index 254 of the 254-byte stack buffer +res[MAXWLEN], an off-by-one out-of-bounds write. Input is case-folded to +about 253 characters, so a 253-character argument together with a SAL map +that does not collapse (collapse_result false) reaches the boundary. + +Related to previous issue +[GHSA-q8mh-6qm3-25g4](https://github.com/vim/vim/security/advisories/GHSA-q8mh-6qm3-25g4) +(9.2.0698) + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-m3hf-xcm3-xhm2 + +Co-Authored-By: Claude Opus 4.8 (1M context) +Signed-off-by: Hirohito Higashi +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/d22ff1c955ff87e8273210eae125aab0e85b6c30] +CVE: CVE-2026-59857 +Signed-off-by: Vijay Anusuri +--- + src/spell.c | 6 +++--- + src/testdir/test_spellfile.vim | 24 ++++++++++++++++++++++++ + 2 files changed, 27 insertions(+), 3 deletions(-) + +diff --git a/src/spell.c b/src/spell.c +index 060a2251a4..43a83ce7dc 100644 +--- a/src/spell.c ++++ b/src/spell.c +@@ -3513,7 +3513,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res) + // no '<' rule used + i += k - 1; + z = 0; +- while (*s != NUL && s[1] != NUL && reslen < MAXWLEN) ++ while (*s != NUL && s[1] != NUL && reslen < MAXWLEN - 1) + { + if (reslen == 0 || res[reslen - 1] != *s) + res[reslen++] = *s; +@@ -3523,7 +3523,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res) + c = *s; + if (strstr((char *)pf, "^^") != NULL) + { +- if (c != NUL) ++ if (c != NUL && reslen < MAXWLEN - 1) + res[reslen++] = c; + STRMOVE(word, word + i + 1); + i = 0; +@@ -3542,7 +3542,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res) + + if (z0 == 0) + { +- if (k && !p0 && reslen < MAXWLEN && c != NUL ++ if (k && !p0 && reslen < MAXWLEN - 1 && c != NUL + && (!slang->sl_collapse || reslen == 0 + || res[reslen - 1] != c)) + // condense only double letters +diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim +index c0c46a32d2..a9bccc6491 100644 +--- a/src/testdir/test_spellfile.vim ++++ b/src/testdir/test_spellfile.vim +@@ -387,6 +387,30 @@ func Test_spellfile_format_error() + let &rtp = save_rtp + endfunc + ++" An over-length soundfold() argument must not overflow the MAXWLEN result ++" buffer in the single-byte branch of spell_soundfold_sal(). ++func Test_spellfile_soundfold_sal_overflow() ++ let save_enc = &encoding ++ set encoding=latin1 ++ " A SAL map that appends without collapsing, so the result is not shorter ++ " than the input. ++ call writefile(['SET ISO8859-1', 'SAL collapse_result false', ++ \ 'SAL a aaaa', 'SAL b bbbb'], 'Xsal.aff') ++ call writefile(['2', 'hello', 'world'], 'Xsal.dic') ++ mkspell! Xsal Xsal ++ set spl=Xsal.latin1.spl spell ++ ++ " 253 input characters hit the buffer boundary; the result must not exceed ++ " MAXWLEN - 1. ++ call assert_true(strlen(soundfold(repeat('a', 253))) <= 253) ++ ++ set nospell spl& spelllang& ++ call delete('Xsal.aff') ++ call delete('Xsal.dic') ++ call delete('Xsal.latin1.spl') ++ let &encoding = save_enc ++endfunc ++ + " Test for format errors in suggest file + func Test_sugfile_format_error() + let save_rtp = &rtp +-- +2.43.0 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index b9f8e40a28..ab7564c3b6 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -31,6 +31,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-57455.patch \ file://CVE-2026-57456.patch \ file://CVE-2026-59856.patch \ + file://CVE-2026-59857.patch \ " PV .= ".0340" From patchwork Wed Jul 22 12:33:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Vijay Anusuri X-Patchwork-Id: 93216 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0365DC44539 for ; Wed, 22 Jul 2026 12:34:44 +0000 (UTC) Received: from mail-pj1-f52.google.com (mail-pj1-f52.google.com [209.85.216.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.46875.1784723675786730945 for ; Wed, 22 Jul 2026 05:34:35 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=ETn31k77; spf=pass (domain: mvista.com, ip: 209.85.216.52, mailfrom: vanusuri@mvista.com) Received: by mail-pj1-f52.google.com with SMTP id 98e67ed59e1d1-38e07ebd263so5774220a91.1 for ; Wed, 22 Jul 2026 05:34:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784723675; x=1785328475; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=LgXcNkp400B1FLrHzfzkUdYmHRFUiMPnNZenfYoB4cU=; b=ETn31k77ghZQqjCdwjP6BXJSr762rweKfBVeQs74qUxEuhEij5mXGm0tf5R0CDeE+j RAODf0GeOg/4ZaGG/2eOV9kgDYXAyR7MnCe17Y/57phdbxgiiAJQ1h9J5xpViP+bpMA3 BKev3/y+0IjnTpGqbhG74F24MOCEeOASoFJpo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784723675; x=1785328475; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=LgXcNkp400B1FLrHzfzkUdYmHRFUiMPnNZenfYoB4cU=; b=B36fIFVaQwplSC7N4WaAzk3Mr36nTcoCNJ68pQmQmqV9kHxnlDLnKsLgJ6xzk8i2I7 5/7R0GvxAixhXTXBL3x+Da57Qbw8xYmrafy5fMwcluYE3ehXY1OZbeOG45rlcH+yX+ph 8Fac9WPiX4T7QZ9QkQfmNV2dS5dOboMZNrbDZ7HVTIEUT/tHY7fhko06BKPIoNrOb/2f +100R58t6jujVc0GSIdaKZB3AYNIkcKMFhR3qWatYXV2oJ56bUzeT0LZgg3My4qOuH12 fsK2bUJt3rRr3++P+psoiSaLPJr8z6uY/nmqWe5IwMdgD9zKoyF09u9vxjxLZchuUf7p WbOg== X-Gm-Message-State: AOJu0Yz11thM1A9b88NEKLNwErLbPGAsXi62eFyZzb5OP/Zk/104VsZZ muqDL7w8sd8QdFNP/8Q8hdrIqiAMDcoCUSH9+g6Kw4E0RNJbxmfuHlzuL4YSIUtsbDHFyZs65cx 5+6KysrQ= X-Gm-Gg: AR+sD10pcGncAE0zFhJjyRT0571ubBl1+6SRoK1kJXcnj+KHLTI3tDMJsH0xBInglYt +ReR5SQERyy0RS3ioJ4IqB+n3mPTxWCP7xLgMeP7o7AwTQCOXClt7jvozNsOlPIqhb0jfktovw3 JInS0wNt1UTK6D7XTzUab2yvcvnftisZVfqD+UqWw0PvuIVB8femc6e9gfOm7JyqW/OXgm322Jb T50ko78hTCkBlOq6p+IDGuoUBDseyJknnwP9JdbfFhIfDWMwgnq1H8vLzigNUGhY42Z37WmB/G7 jkqVEv/t4e95hUZWbknzJvoAKrpV3/VRBOXUtH8UA+AXRtZzgeQM28LRCFvjkbO4247HI4Rso4u aJxYHrnNNH6MB9mR3n3WSJkbO+QgHzeDCt1oZZxI33KKBmQj2cbVfk9RTON5u9THh3D5eq2F7u6 LiSum6w7DWelOu4uKU X-Received: by 2002:a17:90b:4a0e:b0:387:e0db:bc25 with SMTP id 98e67ed59e1d1-38e4b55c8cemr24305439a91.37.1784723675007; Wed, 22 Jul 2026 05:34:35 -0700 (PDT) Received: from MVIN00352.mvista.com ([2401:4900:1f29:92d:e2c5:62da:989e:f39a]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13d130262d2sm5823414c88.7.2026.07.22.05.34.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 05:34:34 -0700 (PDT) From: Vijay Anusuri To: openembedded-core@lists.openembedded.org Cc: Vijay Anusuri Subject: [OE-core][wrynose][patch 10/10] vim: Fix CVE-2026-59858 Date: Wed, 22 Jul 2026 18:03:36 +0530 Message-ID: <20260722123336.587556-10-vanusuri@mvista.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260722123336.587556-1-vanusuri@mvista.com> References: <20260722123336.587556-1-vanusuri@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 12:34:44 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241678 Pick patch per [1]. [1] https://nvd.nist.gov/vuln/detail/CVE-2026-59858 [2] https://security-tracker.debian.org/tracker/CVE-2026-59858 Signed-off-by: Vijay Anusuri --- .../vim/files/CVE-2026-59858.patch | 134 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 135 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-59858.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-59858.patch b/meta/recipes-support/vim/files/CVE-2026-59858.patch new file mode 100644 index 0000000000..a2b903be04 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-59858.patch @@ -0,0 +1,134 @@ +From 6b611b0d15603c52ebdad17172b0232b4f65704e Mon Sep 17 00:00:00 2001 +From: Hirohito Higashi +Date: Fri, 26 Jun 2026 15:41:24 +0900 +Subject: [PATCH] patch 9.2.0735: [security]: arbitrary Ex command execution + during C omni-completion + +Problem: [security]: With C omni-completion, a crafted tags file can execute + arbitrary Ex commands when completing a struct/union member + (cipher-creator) +Solution: Escape the type field before inserting it into the :vimgrep + pattern so it cannot close the pattern and start a new command + (Hirohito Higashi). + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-mf92-v4xw-j45x + +Co-Authored-By: Claude Opus 4.8 (1M context) " +Signed-off-by: Hirohito Higashi +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/6b611b0d15603c52ebdad17172b0232b4f65704e] +CVE: CVE-2026-59858 +Signed-off-by: Vijay Anusuri +--- + runtime/autoload/ccomplete.vim | 2 +- + src/testdir/Make_all.mak | 2 + + src/testdir/test_plugin_ccomplete.vim | 62 +++++++++++++++++++++++++++ + 3 files changed, 65 insertions(+), 1 deletion(-) + create mode 100644 src/testdir/test_plugin_ccomplete.vim + +diff --git a/runtime/autoload/ccomplete.vim b/runtime/autoload/ccomplete.vim +index 51237be98b..dc3388b524 100644 +--- a/runtime/autoload/ccomplete.vim ++++ b/runtime/autoload/ccomplete.vim +@@ -600,7 +600,7 @@ def StructMembers( # {{{1 + return [] + endif + execute 'silent! keepjumps noautocmd ' +- .. n .. 'vimgrep ' .. '/\t' .. typename .. '\(\t\|$\)/j ' ++ .. n .. 'vimgrep ' .. '/\t' .. escape(typename, '/\') .. '\(\t\|$\)/j ' + .. fnames + + qflist = getqflist() +diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak +index b5735b6c3c..0cf2c41102 100644 +--- a/src/testdir/Make_all.mak ++++ b/src/testdir/Make_all.mak +@@ -243,6 +243,7 @@ NEW_TESTS = \ + test_partial \ + test_paste \ + test_perl \ ++ test_plugin_ccomplete \ + test_plugin_comment \ + test_plugin_glvs \ + test_plugin_helpcurwin \ +@@ -523,6 +524,7 @@ NEW_TESTS_RES = \ + test_partial.res \ + test_paste.res \ + test_perl.res \ ++ test_plugin_ccomplete.res \ + test_plugin_comment.res \ + test_plugin_glvs.res \ + test_plugin_helpcurwin.res \ +diff --git a/src/testdir/test_plugin_ccomplete.vim b/src/testdir/test_plugin_ccomplete.vim +new file mode 100644 +index 0000000000..a635bd50bd +--- /dev/null ++++ b/src/testdir/test_plugin_ccomplete.vim +@@ -0,0 +1,62 @@ ++" Tests for the C omni-completion plugin (runtime/autoload/ccomplete.vim). ++ ++func s:WriteTags(lines) ++ " Mark unsorted so lookup is a linear scan regardless of entry order. ++ let tagsfile = tempname() ++ call writefile(["!_TAG_FILE_SORTED\t0\t/0/"] + a:lines, tagsfile) ++ return tagsfile ++endfunc ++ ++" A crafted typeref field is interpolated into the :vimgrep pattern in ++" StructMembers(). Without escaping, "/" closes the pattern and "|" starts a ++" new Ex command, so the field runs as an Ex command during completion. ++func Test_ccomplete_no_exec_via_typeref() ++ unlet! g:ccomplete_injected ++ let tagsfile = s:WriteTags([ ++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:x/|let g:ccomplete_injected = 1|\"", ++ \ ]) ++ ++ let save_tags = &tags ++ let &tags = tagsfile ++ ++ new ++ call ccomplete#Complete(1, '') ++ call ccomplete#Complete(0, 'myvar.x') ++ ++ call assert_false(exists('g:ccomplete_injected'), ++ \ 'typeref field was executed as an Ex command during omni-completion') ++ ++ bwipe! ++ let &tags = save_tags ++ unlet! g:ccomplete_injected ++endfunc ++ ++" A legitimate typeref must still drive struct-member completion: escaping the ++" field value must not break the normal path. ++func Test_ccomplete_typeref_completion_still_works() ++ let tagsfile = s:WriteTags([ ++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:struct:mystruct", ++ \ "alpha\tmain.c\t/^x$/;\"\tm\tstruct:mystruct", ++ \ "beta\tmain.c\t/^x$/;\"\tm\tstruct:mystruct", ++ \ ]) ++ ++ let save_tags = &tags ++ let &tags = tagsfile ++ ++ new ++ call ccomplete#Complete(1, '') ++ let items = ccomplete#Complete(0, 'myvar.') ++ ++ call assert_equal(type([]), type(items), ++ \ 'ccomplete#Complete did not return a list') ++ let names = map(copy(items), 'v:val.word') ++ call assert_true(index(names, 'alpha') >= 0, ++ \ 'struct member "alpha" missing from completion: ' . string(names)) ++ call assert_true(index(names, 'beta') >= 0, ++ \ 'struct member "beta" missing from completion: ' . string(names)) ++ ++ bwipe! ++ let &tags = save_tags ++endfunc ++ ++" vim: shiftwidth=2 sts=2 expandtab +-- +2.43.0 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index ab7564c3b6..0642393db3 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -32,6 +32,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-57456.patch \ file://CVE-2026-59856.patch \ file://CVE-2026-59857.patch \ + file://CVE-2026-59858.patch \ " PV .= ".0340"