From patchwork Wed Jul 22 20:18:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93276 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 90421C4453A for ; Wed, 22 Jul 2026 20:21:53 +0000 (UTC) Received: from mail-pl1-f178.google.com (mail-pl1-f178.google.com [209.85.214.178]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.9340.1784751709481774513 for ; Wed, 22 Jul 2026 13:21:49 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=dki46wsR; spf=pass (domain: mvista.com, ip: 209.85.214.178, mailfrom: sdoshi@mvista.com) Received: by mail-pl1-f178.google.com with SMTP id d9443c01a7336-2cc97653887so142290145ad.1 for ; Wed, 22 Jul 2026 13:21:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784751709; x=1785356509; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=GXIjjXqI3cbzQV0/tVsAPHqGpmPpZylgmBRha3OZrxU=; b=dki46wsR+heO/mJUPMSeYUqe/DF4zDfKEERo0ovLhkH95wfjjEO07okGxuEZY4gw3U JjydD9zVTRqOQJDkYfp+xkfDeKZwVamPHvJjY6UxL52cvkdh4+O6gE58QwJhOQZm5RKZ 2/60Hs2UiVaPh+dMOtPjWVb0Nr/XYNt+ooOyA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784751709; x=1785356509; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=GXIjjXqI3cbzQV0/tVsAPHqGpmPpZylgmBRha3OZrxU=; b=pbX/inVFbFEtqkC8bnaf5ztX1fBKk1KMo789CHEhsljKXigyOQGDV2j3nLSk1yGUFs nk8U08bq5JEB9xUQvlKncu8pwvdf9ysyp+ZjsOJL8JmcabwvnU/TE8ZFwsL9BlcRbnBo 74ZerFXL0hnNthVE6Yu59Bky2hfPP84+tBtVffdjsIyJWczS/VA1PqpNAQGZwEqyglK1 lgFdxUVepJmchN9CIP3D4rURR2x/bpDUobhKN3Biw644lckUDEy4Iysz3XJgSL/zutvS p0OJAukM/Ime2TwSuzIbuWIkv3jyXTvays2JuQDq1CgYXIOtPALc9AZt+/833ne8qHBa tYfw== X-Gm-Message-State: AOJu0YzieZUCns5JFpXbjIebF9r/MyRUZZqWMygtRTRoI1tgy17WXYT3 rZzktpYA+iXUox4qBJrW0EI/4iynOgkDkuRpUD4YgHCfYsqbFkyyNhoxenKZJ/nNuSpbiKhqeIZ euUNEqa0= X-Gm-Gg: AR+sD102ukWk/KWmL4WY2pboEInzkci/3K59ZLNan8clnBREO3oDfIxDP5YyYY4BFEC Nxu41CSrjVmkOuI9uhmgyYrjogK2bpfw3lTCPllfKH5kl5l/eGG5H8qsJmFFD2MhYrU27LFg0zD 1J59/aWbPkb+VXrB//890svVdVPXPjjgRwR5ehOGWrwJrlR/3LWtNEK85JNA4a7N6qzVgBi1XQl gCfoBkg9SkMBuPez6Tk14M9Y5cX8DRHrkhTWMAF8QVilGZOPNO7aDjl68AeZvjdX03kl/oMEQ2S lK08w18N+VPyxsyFXyOIAXrt2+GfxGBALMHUsPcMvY8jsFRfS53RC8QjO9xhB5+DPywE85gjfmz 0lHEMLYqEvncxKU8pR6RZ2EjcmktansOTE3PtVurNWUSoqXzO5sMGdq4MGSYOwxpoqtsLMJEOiz CH3cy+redGHybJ X-Received: by 2002:a17:903:1c3:b0:2ca:e5c:7fba with SMTP id d9443c01a7336-2cfa74b2e2fmr3542445ad.39.1784751708798; Wed, 22 Jul 2026 13:21:48 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.199]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3147d47960dsm11699468eec.0.2026.07.22.13.21.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 13:21:48 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 01/13] vim: Security Fix for CVE-2026-28422 Date: Thu, 23 Jul 2026 01:48:53 +0530 Message-Id: <20260722201905.491897-1-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 20:21:53 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241745 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-28422 [2] https://security-tracker.debian.org/tracker/CVE-2026-28422 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-28422.patch | 44 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 45 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-28422.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-28422.patch b/meta/recipes-support/vim/files/CVE-2026-28422.patch new file mode 100644 index 0000000000..89f219ccf6 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-28422.patch @@ -0,0 +1,44 @@ +From fcf19885004325f5a52db6bd6893cb5b387799d3 Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Tue, 24 Feb 2026 20:29:20 +0000 +Subject: [PATCH 01/17] patch 9.2.0078: [security]: stack-buffer-overflow in + build_stl_str_hl() + +Problem: A stack-buffer-overflow occurs when rendering a statusline + with a multi-byte fill character on a very wide terminal. + The size check in build_stl_str_hl() uses the cell width + rather than the byte length, allowing the subsequent fill + loop to write beyond the 4096-byte MAXPATHL buffer + (ehdgks0627, un3xploitable). +Solution: Update the size check to account for the byte length of + the fill character (using MB_CHAR2LEN). + +Github Advisory: +https://github.com/vim/vim/security/advisories/GHSA-gmqx-prf2-8mwf + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/4e5b9e31cb7484ad156fba995fdce3c9b075b5fd] +CVE: CVE-2026-28422 +Signed-off-by: Siddharth Doshi +--- + src/buffer.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/src/buffer.c b/src/buffer.c +index 0feafc590d..363dd0e04a 100644 +--- a/src/buffer.c ++++ b/src/buffer.c +@@ -5293,7 +5293,8 @@ build_stl_str_hl( + } + width = maxwidth; + } +- else if (width < maxwidth && outputlen + maxwidth - width + 1 < outlen) ++ else if (width < maxwidth && ++ outputlen + (maxwidth - width) * MB_CHAR2LEN(fillchar) + 1 < outlen) + { + // Find how many separators there are, which we will use when + // figuring out how many groups there are. +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 9a4b21f530..16edebf1e9 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -33,6 +33,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-45130.patch \ file://CVE-2026-46483.patch \ file://CVE-2026-28420.patch \ + file://CVE-2026-28422.patch \ " PV .= ".1683" From patchwork Wed Jul 22 20:18:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93277 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9144BC4453C for ; Wed, 22 Jul 2026 20:21:53 +0000 (UTC) Received: from mail-pg1-f174.google.com (mail-pg1-f174.google.com [209.85.215.174]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.9338.1784751712530185336 for ; Wed, 22 Jul 2026 13:21:52 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=SLO3aiA9; spf=pass (domain: mvista.com, ip: 209.85.215.174, mailfrom: sdoshi@mvista.com) Received: by mail-pg1-f174.google.com with SMTP id 41be03b00d2f7-c9ef3e1337fso8823276a12.2 for ; Wed, 22 Jul 2026 13:21:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784751712; x=1785356512; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=W++JjZFssDc7KzYG9kdBgmElO+in4MEx1XlIKdpd7rw=; b=SLO3aiA9P4JWZgGAdGM8vRFUM6/jX+R+71KLpMe5YiwM9w7hYmEF1pttEoI3Mx6Slv VmNBayDS90EGTSYAWOZVm5OWrubEaEztV2eVW/3kjlIyTUUGZ6jyrQwlsT8vJOxFfUev kZVbcbm8gbxmhNoIVl3TMr9BclJG3bGi2dO9U= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784751712; x=1785356512; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=W++JjZFssDc7KzYG9kdBgmElO+in4MEx1XlIKdpd7rw=; b=JDhHgBFrqIt4WesDfRriKGattyjOQ+s39st2xW5j7iqb60Qm6GBFcTRGSo+64YWqCw l9Nwy7X2/sa9qhAMmgoWMxKDr6GUFePnG3UZP3YldDsjmFobSHakyrsi1rsgcRnj/NCo 6hmVXZs0hL2r/h6nL1FvzMnCKXYET/QJ/05yy8HadSWqfgQmwVeUXyl9JHcK8R7m4QO5 J8zBCNPs7e1ljcXQMF3W0ITp4enY4su6HdkCDft51NpDqogpUtgWw7Alhy8gY1MdmgFP q8ubHKHc1ZG650W7IjvwhSQw3It5frJUZIq3bfC3xdxSai76WXyWqreP1oWWYblQwihd AI+Q== X-Gm-Message-State: AOJu0Yx+iYNjaz+hG9068Xp/KSFbGPamL2m9uoS7W8zMN2McvH8PFIsi +K8dp8jbtrfZF+7dXFPdq+91LYjKtidLz66GoL8ysO0XL5nywnrjxtIcrdaikWnjV7aElfHJY4g QTHzfjrc= X-Gm-Gg: AR+sD10AEc/1KxYb2PwHLIzCm5O9mkjiJEkD6iwqqZQhs7c+5UYp2zcET7Jto2PNcKf 8/qEo00ltYTg9Vf3rtUSQECtF3SRfuZziT/VpxyfbdpPQFxnGgPrg1FTvdVe4X2xBbwIRSdUObJ yi5kaWPQ6f1F5eKmyhJSW0frJLtbfzQGOGVgUID+/pY2SFPXI6wCp6vHg/3pvS/UW3wdfHY8LNc C3b78bY7phFmDH2t7AOh2b0WvSFc017diSsEzwAfexHm1zsEj2Vs5lQbMGzI/myOcxDdMCqOl4e k9XTRPa0Q965idgfq7RBT8InLtbNzQAY6ik5RnxnIWNGTbMTVXWaOksjqQd1ZitLID10ipwSsOS 46sThB8QNXc2CqUkpDWZBrvn11vBxSGV80RciJebT4R3D+QYO/dnIAoVTEWfprstlSLHmaWxxCf yZ9qu0sNCOIZ0X X-Received: by 2002:a05:6a21:1788:b0:3c3:8d86:9855 with SMTP id adf61e73a8af0-3c44afa2435mr45025637.7.1784751711676; Wed, 22 Jul 2026 13:21:51 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.199]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3147d47960dsm11699468eec.0.2026.07.22.13.21.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 13:21:51 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 02/13] vim: Security Fix for CVE-2026-42307 Date: Thu, 23 Jul 2026 01:48:54 +0530 Message-Id: <20260722201905.491897-2-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260722201905.491897-1-sdoshi@mvista.com> References: <20260722201905.491897-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 20:21:53 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241746 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-42307 [2] https://security-tracker.debian.org/tracker/CVE-2026-42307 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-42307.patch | 121 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 122 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-42307.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-42307.patch b/meta/recipes-support/vim/files/CVE-2026-42307.patch new file mode 100644 index 0000000000..03acd436a0 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-42307.patch @@ -0,0 +1,121 @@ +From 936634660e3836e1a495965b48a0dc913e9d0deb Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Tue, 21 Apr 2026 19:03:02 +0000 +Subject: [PATCH 02/17] patch 9.2.0383: [security]: runtime(netrw): + shell-injection via sftp: and file: URLs + +Problem: runtime(netrw): shell-injection via sftp: and file: URLs + (Joshua Rogers) +Solution: Escape temporary file names, harden filename suffix regex, + drop unused g:netrw_tmpfile_escape variable + +Supported by AI + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/405e2fb6d54d5653523809e2853d99d1c000a5fc] +CVE: CVE-2026-42307 +Signed-off-by: Siddharth Doshi +--- + runtime/doc/pi_netrw.txt | 4 ---- + runtime/doc/tags | 1 - + runtime/pack/dist/opt/netrw/autoload/netrw.vim | 16 +++++++++------- + runtime/pack/dist/opt/netrw/doc/netrw.txt | 4 ---- + 4 files changed, 9 insertions(+), 16 deletions(-) + +diff --git a/runtime/doc/pi_netrw.txt b/runtime/doc/pi_netrw.txt +index a86cac36ba..2d98a8407b 100644 +--- a/runtime/doc/pi_netrw.txt ++++ b/runtime/doc/pi_netrw.txt +@@ -2854,10 +2854,6 @@ your browsing preferences. (see also: |netrw-settings|) + such as listing, file removal, etc. + default: ssh + +- *g:netrw_tmpfile_escape* =' &;' +- escape() is applied to all temporary files +- to escape these characters. +- + *g:netrw_timefmt* specify format string to vim's strftime(). + The default, "%c", is "the preferred date + and time representation for the current +diff --git a/runtime/doc/tags b/runtime/doc/tags +index 300dfd18a6..7ce3b63075 100644 +--- a/runtime/doc/tags ++++ b/runtime/doc/tags +@@ -7863,7 +7863,6 @@ g:netrw_ssh_browse_reject pi_netrw.txt /*g:netrw_ssh_browse_reject* + g:netrw_ssh_cmd pi_netrw.txt /*g:netrw_ssh_cmd* + g:netrw_sshport pi_netrw.txt /*g:netrw_sshport* + g:netrw_timefmt pi_netrw.txt /*g:netrw_timefmt* +-g:netrw_tmpfile_escape pi_netrw.txt /*g:netrw_tmpfile_escape* + g:netrw_uid pi_netrw.txt /*g:netrw_uid* + g:netrw_use_noswf pi_netrw.txt /*g:netrw_use_noswf* + g:netrw_use_nt_rcp pi_netrw.txt /*g:netrw_use_nt_rcp* +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index 1c98104d00..805474616d 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -378,7 +378,6 @@ else + call s:NetrwInit("g:netrw_glob_escape",'*[]?`{~$\') + endif + call s:NetrwInit("g:netrw_menu_escape",'.&? \') +-call s:NetrwInit("g:netrw_tmpfile_escape",' &;') + call s:NetrwInit("s:netrw_map_escape","<|\n\r\\\\"") + if has("gui_running") && (&enc == 'utf-8' || &enc == 'utf-16' || &enc == 'ucs-4') + let s:treedepthstring= "│ " +@@ -1799,14 +1798,14 @@ function netrw#NetRead(mode,...) + "......................................... + " NetRead: (sftp) NetRead Method #9 {{{3 + elseif b:netrw_method == 9 +- call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_sftp_cmd." ".netrw#os#Escape(g:netrw_machine.":".b:netrw_fname,1)." ".tmpfile) ++ call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_sftp_cmd." ".netrw#os#Escape(g:netrw_machine.":".b:netrw_fname,1)." ".netrw#os#Escape(tmpfile,1)) + let result = s:NetrwGetFile(readcmd, tmpfile, b:netrw_method) + let b:netrw_lastfile = choice + + "......................................... + " NetRead: (file) NetRead Method #10 {{{3 + elseif b:netrw_method == 10 && exists("g:netrw_file_cmd") +- call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_file_cmd." ".netrw#os#Escape(b:netrw_fname,1)." ".tmpfile) ++ call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_file_cmd." ".netrw#os#Escape(b:netrw_fname,1)." ".netrw#os#Escape(tmpfile,1)) + let result = s:NetrwGetFile(readcmd, tmpfile, b:netrw_method) + let b:netrw_lastfile = choice + +@@ -8927,14 +8926,17 @@ function s:GetTempfile(fname) + endif + + " use fname's suffix for the temporary file ++ " Restrict the suffix to word characters so shell metacharacters in a ++ " remote filename (e.g. sftp://host/foo.txt;id) cannot ride along into ++ " the tempfile name and out into a downstream shell command. + if a:fname != "" +- if a:fname =~ '\.[^./]\+$' ++ if a:fname =~ '\.\w\+$' + if a:fname =~ '\.tar\.gz$' || a:fname =~ '\.tar\.bz2$' || a:fname =~ '\.tar\.xz$' +- let suffix = ".tar".substitute(a:fname,'^.*\(\.[^./]\+\)$','\1','e') ++ let suffix = ".tar".substitute(a:fname,'^.*\(\.\w\+\)$','\1','e') + elseif a:fname =~ '.txz$' +- let suffix = ".txz".substitute(a:fname,'^.*\(\.[^./]\+\)$','\1','e') ++ let suffix = ".txz".substitute(a:fname,'^.*\(\.\w\+\)$','\1','e') + else +- let suffix = substitute(a:fname,'^.*\(\.[^./]\+\)$','\1','e') ++ let suffix = substitute(a:fname,'^.*\(\.\w\+\)$','\1','e') + endif + let tmpfile= substitute(tmpfile,'\.tmp$','','e') + let tmpfile .= suffix +diff --git a/runtime/pack/dist/opt/netrw/doc/netrw.txt b/runtime/pack/dist/opt/netrw/doc/netrw.txt +index 01a5bda597..144bab5fb3 100644 +--- a/runtime/pack/dist/opt/netrw/doc/netrw.txt ++++ b/runtime/pack/dist/opt/netrw/doc/netrw.txt +@@ -2854,10 +2854,6 @@ your browsing preferences. (see also: |netrw-settings|) + such as listing, file removal, etc. + default: ssh + +- *g:netrw_tmpfile_escape* =' &;' +- escape() is applied to all temporary files +- to escape these characters. +- + *g:netrw_timefmt* specify format string to vim's strftime(). + The default, "%c", is "the preferred date + and time representation for the current +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 16edebf1e9..902115bbd6 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -34,6 +34,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-46483.patch \ file://CVE-2026-28420.patch \ file://CVE-2026-28422.patch \ + file://CVE-2026-42307.patch \ " PV .= ".1683" From patchwork Wed Jul 22 20:18:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93280 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8DBACC4453F for ; Wed, 22 Jul 2026 20:22:03 +0000 (UTC) Received: from mail-pf1-f170.google.com (mail-pf1-f170.google.com [209.85.210.170]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.9339.1784751715671614068 for ; Wed, 22 Jul 2026 13:21:55 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=HY8g6kar; spf=pass (domain: mvista.com, ip: 209.85.210.170, mailfrom: sdoshi@mvista.com) Received: by mail-pf1-f170.google.com with SMTP id d2e1a72fcca58-8486ac3f347so5558496b3a.1 for ; Wed, 22 Jul 2026 13:21:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784751715; x=1785356515; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=a0mzEY+lbFwh/gt03vTXdj/qJFufO8jGgsVmAQb6c/g=; b=HY8g6kargnJUo/Q3/jLFg6XXDXp0oYXphrNfVvvDxa9uN5XCePjvk8kg2Bcej6ias4 J2j5tlj4Rd5TiQgSsxdRR97Gpwl3up40YMi0JJeBTfFIImaxGOZwsnHemHKtPC4etOoe LcSQOSxR06za53E2OIQFOrmJWECFjGYN09Iy0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784751715; x=1785356515; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=a0mzEY+lbFwh/gt03vTXdj/qJFufO8jGgsVmAQb6c/g=; b=OrpP26HeDSoNGPqYD4ly2/s+UEo2jxyA0OOy/CDl96PjqUlJ2uNrNjvLjVznjEq1q4 7XeDISmMlVylRtevQbCKIQsCn0Yw7Wq1e88kpg4Ped3myDzmPnpB4+JnJuY9EwXXxhRA re+oK5SFcrWzj9enx0YMAea/tAyXiF2kkDpE2haFnDbKVjT9xBTmIMCf8Mu3ZuHUdbs6 VGEkWG4HRfDJkERd2RvCmV23lHdg52MTXR1ffIEM32uFFfRuB68bGfVY+NuwANn+nikr 7dcBWQmxz7fif2l/l0SYAX1LYowmFJhxPLS7c/mcG5kjJt2J8iyGPfUPazWycjBNqNTL +Hyg== X-Gm-Message-State: AOJu0Yw19rB9DolaXVofdTrLvdyq7mSVM6vvxZzV9N7YgRHSJUuyn3kS AsOU49ESUSWr2JU55EemCgDmW6dKWSzasFK+XnUylaKOTbVdR+uB6/49UpKlEXh1u6sqyk0WDKc NroMldbQ= X-Gm-Gg: AR+sD10CsgFfgpfc3UoZStV+KBxEzQ54J6awKM7PNNBw4uKYmdswmvi6BTeVBUKUjZW CRMYHt2rY1XQB17GYpl3bMj6JwvneT3g6FzkwFSvfP5k6U4Fks2nxu3TnVbH2Q8iR9O2MOwK71f 31+eklRoL8dBAR9ue5wzNzf6PwVjBvC07mu1O3HdnWYuxdz3PFMYVevsnDw9vMsJpeYDfB1voWu +SoU5BKOSc2nS77xC3u7mqUTqtNa+k69yjCTBzxIcghjlrBTLQzpp2dgdWmvWnfJeWn90p1Yha9 y/bjefTatSkWeqFhnpG53tgG8hw3lzBuVQADpu8MZviX/TimIJPvYfL+mDhaG4wCi2ugXyKGy7u BH62WmD+I1t0UwW5Aye39ulaRW56EGfDgog0iR24QYj2ZFUka2i/ZSSFu1Jz73yOqJamS5OBzvr eahK6xKbAgZmuL X-Received: by 2002:a05:6a21:46c4:b0:3c3:6e84:ace8 with SMTP id adf61e73a8af0-3c429455f22mr6090314637.23.1784751715025; Wed, 22 Jul 2026 13:21:55 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.199]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3147d47960dsm11699468eec.0.2026.07.22.13.21.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 13:21:54 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 03/13] vim: Security Fix for CVE-2026-43961 Date: Thu, 23 Jul 2026 01:48:55 +0530 Message-Id: <20260722201905.491897-3-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260722201905.491897-1-sdoshi@mvista.com> References: <20260722201905.491897-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 20:22:03 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241747 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://github.com/vim/vim/commit/8af0f098c3a42a28661d0295364e [2] https://security-tracker.debian.org/tracker/CVE-2026-43961 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-43961.patch | 65 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 66 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-43961.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-43961.patch b/meta/recipes-support/vim/files/CVE-2026-43961.patch new file mode 100644 index 0000000000..f9e0fc0df4 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-43961.patch @@ -0,0 +1,65 @@ +From f38c7cb2fcc9d5839386ea4722463ea921f0bbce Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Thu, 14 May 2026 16:43:15 +0000 +Subject: [PATCH 03/17] patch 9.2.0480: [security]: runtime(netrw): code + injection via mf command + +Problem: [security]: runtime(netrw): code injection via mf command + (Christopher Lusk, Zdenek Dohnal) +Solution: Do not use string concatenation inside the filter() commands + (Zdenek Dohnal) + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-66hr-7p6x-x5j3 + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/8af0f098c3a42a28661d0295364e] +CVE: CVE-2026-43961 +Signed-off-by: Siddharth Doshi +--- + runtime/pack/dist/opt/netrw/autoload/netrw.vim | 7 +++---- + 1 file changed, 3 insertions(+), 4 deletions(-) + +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index 805474616d..e484de5c93 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -5155,7 +5155,7 @@ function s:NetrwMarkFile(islocal,fname) + + else + " remove filename from buffer's markfilelist +- call filter(s:netrwmarkfilelist_{curbufnr},'v:val != a:fname') ++ call filter(s:netrwmarkfilelist_{curbufnr}, {_, v -> v !=# a:fname}) + if s:netrwmarkfilelist_{curbufnr} == [] + " local markfilelist is empty; remove it entirely + call s:NetrwUnmarkList(curbufnr,curdir) +@@ -5176,7 +5176,6 @@ function s:NetrwMarkFile(islocal,fname) + + else + " initialize new markfilelist +- + let s:netrwmarkfilelist_{curbufnr}= [] + call add(s:netrwmarkfilelist_{curbufnr},substitute(a:fname,'[|@]$','','')) + +@@ -5196,7 +5195,7 @@ function s:NetrwMarkFile(islocal,fname) + call add(s:netrwmarkfilelist,netrw#fs#ComposePath(b:netrw_curdir,a:fname)) + else + " remove new filename from global markfilelist +- call filter(s:netrwmarkfilelist,'v:val != "'.dname.'"') ++ call filter(s:netrwmarkfilelist, {_, v -> v !=# dname}) + if s:netrwmarkfilelist == [] + unlet s:netrwmarkfilelist + endif +@@ -7202,7 +7201,7 @@ function s:NetrwTreeDisplay(dir,depth) + " hide given patterns + let listhide= split(g:netrw_list_hide,',') + for pat in listhide +- call filter(w:netrw_treedict[dir],'v:val !~ "'.escape(pat,'\\').'"') ++ call filter(w:netrw_treedict[dir], {_, v -> v !~# pat}) + endfor + + elseif g:netrw_hide == 2 +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 902115bbd6..006ae9473f 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -35,6 +35,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-28420.patch \ file://CVE-2026-28422.patch \ file://CVE-2026-42307.patch \ + file://CVE-2026-43961.patch \ " PV .= ".1683" From patchwork Wed Jul 22 20:18:56 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93279 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 75586C4453A for ; Wed, 22 Jul 2026 20:22:03 +0000 (UTC) Received: from mail-pl1-f177.google.com (mail-pl1-f177.google.com [209.85.214.177]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.9342.1784751718358861205 for ; Wed, 22 Jul 2026 13:21:58 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=cmDjBIEH; spf=pass (domain: mvista.com, ip: 209.85.214.177, mailfrom: sdoshi@mvista.com) Received: by mail-pl1-f177.google.com with SMTP id d9443c01a7336-2cacf197759so156056995ad.2 for ; Wed, 22 Jul 2026 13:21:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784751718; x=1785356518; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Dbw0uGTNUuSNzwvng4oGurvFgdjKg2rGCI30S/KNZEk=; b=cmDjBIEHCZu710GmLN9nhuT1XlU8P975DkwCaY6XlpGrsOpP0h2XoOdItBLrkyGjll /3d61KqpHcGudKjrZUNpjQwjg7goUjWCFMfzK33S5q6++PyhVjyf7aRfBSqbBSAXRRQj +sJEFd71w8o6RQUV6PD217Rku1jHiRvY+9FWM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784751718; x=1785356518; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Dbw0uGTNUuSNzwvng4oGurvFgdjKg2rGCI30S/KNZEk=; b=lv/ZkmKm+UZ/JLpsHrwUtfDrrCgeWxNpE6v7pY4/2fmZJI4NFQgdd73m/qeG0ciuNj 7XVGlgCVwbeqWVakCcf5Ojf9EmQpA62yZrXmdHJ2fyabG4kG2dOVIapipNP1CXWlOy2c CX2tvQ1CU800cqKF+KXI1fYs24hxAhXcNFVLZJUHgvFDEyh3rWIMkVOdYwlDxa6Q10ch 81zGLpByIU6tBQMS/BJfj+ydHgMIo1mI4kKToOkG9T2NDz1nHUXczxajJYiEXF20zhpP MpwC9/t4bC43HcrCD610qRH+5KReDnMxXQprwQQZyRunrsbA26LczKJJ0Nx6WpXhsGVq a5DA== X-Gm-Message-State: AOJu0YxLk4EtT5GMu+EYY4tPBo43QeyBaHBgroV9Oe7lsHpWMz/Qv9eD CBaxH1tcc55LEEVY8Pu06r9lKiEo1l2ukwod/EGb5FT+WhdJCNPNgei0lwokzQiE8mYmQJRdMUT 8dwztzvU= X-Gm-Gg: AR+sD10kZKAs7POHP4bVpictl0kyAm/nm66QdcZnpsYyqz2nhlOvScV0L8DiGgDLviw JDvkXU5itMm3c9CF6p0CECDBRpnc+wO7w2kLOxiOQHc8/7OHXjirwfS0nBEEAZpDRdjp4baUpt5 Nb0KV9cebpK8YaVDEcZEQG/G3s94B/BOUXbC9kjXpqUysUn2t87YuQNsv7HYcJwXfw5wjrt14Py cq/0gNQIldI1X9xyV1ALWldfZQL7eS27dc2PbNCi4VSG0BZ9r8FiAR8w6REkp67WbeaEeUVej9d dSEDHQx2sxOJQx8ChrFkHojop0XtnRHdQj/1sOk57uAMQzvkXNZvOEzinH2eqFPPSl1/OMHkO01 Z80hnZs0xzyV810Wdyckk4tVs2BjO6f77ZTXDVxMMznmp6UghmctJVtdQNdSKoIsG6UGRn3xBF+ gIuZfDqSnNCvQZKUsEZA2HA3U= X-Received: by 2002:a17:902:eccb:b0:2c9:c46b:1286 with SMTP id d9443c01a7336-2cfa74ada2dmr3628315ad.34.1784751717673; Wed, 22 Jul 2026 13:21:57 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.199]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3147d47960dsm11699468eec.0.2026.07.22.13.21.55 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 13:21:57 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 04/13] vim: Security Fix for CVE-2026-47162 Date: Thu, 23 Jul 2026 01:48:56 +0530 Message-Id: <20260722201905.491897-4-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260722201905.491897-1-sdoshi@mvista.com> References: <20260722201905.491897-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 20:22:03 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241748 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-47162 [2] https://security-tracker.debian.org/tracker/CVE-2026-47162 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-47162.patch | 39 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 40 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-47162.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-47162.patch b/meta/recipes-support/vim/files/CVE-2026-47162.patch new file mode 100644 index 0000000000..33f1ebbfd1 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-47162.patch @@ -0,0 +1,39 @@ +From d254c3b584e19555f2aecc4886ae7c92c0acc199 Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Sun, 17 May 2026 18:53:48 +0000 +Subject: [PATCH 04/17] patch 9.2.0495: [security]: runtime(netrw): code + injection via NetrwBookHistSave() + +Problem: [security]: runtime(netrw): code injection via + NetrwBookHistSave() +Solution: Properly quote the directory name using string() function + (Srinivas Piskala Ganesh Babu) + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-crm5-rh6j-2c7c + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/f08ab2f4d7d2947c8dd6c179ae08ee6146a2694b] +CVE: CVE-2026-47162 +Signed-off-by: Siddharth Doshi +--- + runtime/pack/dist/opt/netrw/autoload/netrw.vim | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index e484de5c93..9014ca339b 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -2921,7 +2921,7 @@ function s:NetrwBookHistSave() + while ( first || cnt != g:netrw_dirhistcnt ) + let lastline= lastline + 1 + if exists("g:netrw_dirhist_{cnt}") +- call setline(lastline,'let g:netrw_dirhist_'.cnt."='".g:netrw_dirhist_{cnt}."'") ++ call setline(lastline,'let g:netrw_dirhist_'.cnt.'='.string(g:netrw_dirhist_{cnt})) + endif + let first = 0 + let cnt = ( cnt - 1 ) % g:netrw_dirhistmax +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 006ae9473f..7b0b140bf8 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -36,6 +36,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-28422.patch \ file://CVE-2026-42307.patch \ file://CVE-2026-43961.patch \ + file://CVE-2026-47162.patch \ " PV .= ".1683" From patchwork Wed Jul 22 20:18:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93278 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 81271C44536 for ; Wed, 22 Jul 2026 20:22:03 +0000 (UTC) Received: from mail-pg1-f171.google.com (mail-pg1-f171.google.com [209.85.215.171]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.9346.1784751721007595874 for ; Wed, 22 Jul 2026 13:22:01 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=RbGDz39C; spf=pass (domain: mvista.com, ip: 209.85.215.171, mailfrom: sdoshi@mvista.com) Received: by mail-pg1-f171.google.com with SMTP id 41be03b00d2f7-c998fd549a8so8645368a12.2 for ; Wed, 22 Jul 2026 13:22:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784751720; x=1785356520; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=8TG39gHoxpQoiKdmxRy9lvILoXdedsRJ0AmJvYkKuJc=; b=RbGDz39C+aWpync61GLDeq3zydP+hSiBFDk7K4b/rMH8JuH7S3IfcNKET0evGwsAzr SF7JNVEplFy1NH1DuUenl0+XTdqUfipyUCzI9QsPio0E91evaXRrVBnzfdIQV7FrNCMs 2539Hu8UCsPs/Y0EkSD0HR5vFU1GqmDxSZs48= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784751720; x=1785356520; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=8TG39gHoxpQoiKdmxRy9lvILoXdedsRJ0AmJvYkKuJc=; b=eidiJ/nRH2mhNSaSU7EbrURnEa+aEOzSDvqGuAJ3mhTXzRD3oqL+TtdbxffD67sytu cI54p8BA1/ZDm8S9JZQDceJJ/uX5AVP7qJJZP6THATIqn7TPzK3LoxlSb1Iq7U+dhh3v nn1SEeT8FTOWUAHbR+Quf1R6Kk/Oqt+LSBlG/LJ8APLRX/shHth5F37uLhDhRMBRBTHy kRv8Wwsh+mWa4BtSqb35XM1Mc68Stg44xTTFR/iOR+WbJX+D4R1SXpcNFUVXfX9hEJza nfFk4BR8HmcHiGrpRY7+m9fZA2CemrHrSVjfkmPpu0hY0yoqasOlRUnYZ0Jk2S5mJ1ag U7gA== X-Gm-Message-State: AOJu0YywtsZCGXatB3WUAkFIK3qgp1/5F3Lt1v6ZgIXJypHzbWufUzok 5yZpQJiD2Cdet35dpacYvrbvru2lKCwy9yiv7LquQTDAebSAkB0K3VsYitX94HXqNNCr4zdz49w GndzWNpw= X-Gm-Gg: AR+sD12oXFnkuOE+UvrlsZCwDVG7Fc5dF3teeSrOGtOYLfZPlKQvvRlhGDPDWGK3ZIB 59i+TiAY7KhRob8wx9d7NJuazwQBxOU6kzxS+nnqfwt/e+1pHhY+9uoHZrn/sT/gMn028thKEKa 9RnRSMSnEVYei2buJ4egun76+sZ06uD3hhWBo2f26ziMEqn6FLQowyALxQZvHDUFpOpGFdr5gpI dodr3GPSFnwsTqIg1YII7HAf4Ddp5Hzh4EtjIi3eonhfhSdpyXXeDPwE9LBKPmLy1IoNp2KYFnZ nJUvd50wHLIg2WJv2/uyv8v8lAzukmM3idofRp0Oe+DpyLSPTh7NYbqv3g8TYmqaYmG2NZJXBV7 ai/D2hW8aiLGoAOGopzOIjFMW50DcXA86hCE1V/Dy1o1/+JXxnAIOarecTaWleb6My6nsb0tL0O igOVLLqi+YJgqe X-Received: by 2002:a05:6a20:7344:b0:3c4:1c9f:d81 with SMTP id adf61e73a8af0-3c44afaabf8mr46722637.7.1784751720412; Wed, 22 Jul 2026 13:22:00 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.199]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3147d47960dsm11699468eec.0.2026.07.22.13.21.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 13:21:59 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 05/13] vim: Security Fix for CVE-2026-47167 Date: Thu, 23 Jul 2026 01:48:57 +0530 Message-Id: <20260722201905.491897-5-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260722201905.491897-1-sdoshi@mvista.com> References: <20260722201905.491897-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 20:22:03 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241749 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-47167 [2] https://security-tracker.debian.org/tracker/CVE-2026-47167 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-47167.patch | 39 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 40 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-47167.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-47167.patch b/meta/recipes-support/vim/files/CVE-2026-47167.patch new file mode 100644 index 0000000000..f0e493290c --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-47167.patch @@ -0,0 +1,39 @@ +From e117fcc6f1c1973602c8e2c6529fba9ee1ce59b4 Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Sun, 17 May 2026 19:39:24 +0000 +Subject: [PATCH 05/17] patch 9.2.0496: [security]: Code Injection in cucumber + filetype plugin + +Problem: [security]: Code Injection in cucumber filetype plugin + (Christopher Lusk) +Solution: Use rubys Regexp.new() with the untrusted pattern + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-4473-94jm-w5x9 + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/a65a52d684bc58535ad28a4ae824d22e76399934] +CVE: CVE-2026-47167 +Signed-off-by: Siddharth Doshi +--- + runtime/ftplugin/cucumber.vim | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/runtime/ftplugin/cucumber.vim b/runtime/ftplugin/cucumber.vim +index f4848d1c60..3361f1db4a 100644 +--- a/runtime/ftplugin/cucumber.vim ++++ b/runtime/ftplugin/cucumber.vim +@@ -96,7 +96,8 @@ function! s:stepmatch(receiver,target) + catch + endtry + if has("ruby") && pattern !~ '\\\@ X-Patchwork-Id: 93282 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id AF8AEC4453C for ; Wed, 22 Jul 2026 20:22:13 +0000 (UTC) Received: from mail-pl1-f174.google.com (mail-pl1-f174.google.com [209.85.214.174]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.9347.1784751723862836669 for ; Wed, 22 Jul 2026 13:22:03 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=RiPDrngx; spf=pass (domain: mvista.com, ip: 209.85.214.174, mailfrom: sdoshi@mvista.com) Received: by mail-pl1-f174.google.com with SMTP id d9443c01a7336-2caced6038eso88757105ad.0 for ; Wed, 22 Jul 2026 13:22:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784751723; x=1785356523; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=6AmZZWKiYr4F0BLJf0RxqTC5ZK5VaVGyD/OVRkqZCTo=; b=RiPDrngxKpz+ugUq/yTe51js+AU0G9dB8PuKYmUMCL18fJCajmHncAjP63xiF/r4K9 Yl0ddkKaPsMlbIuRm+4NNbSBzkGUnZWmZvInZvnLuF5B9OyPLUheGnQi1ECroJyc2Hk9 Bftn9uwurc0pmJS/Jvmrw3egfN70A5Cmnjl6Y= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784751723; x=1785356523; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=6AmZZWKiYr4F0BLJf0RxqTC5ZK5VaVGyD/OVRkqZCTo=; b=q4X/eVgMNY/g/vXFiVrQhkTOmXKBmvb0EILoQoV7HK2/jt3SpvZEN/48wnJqBAiYhy 1EQlld8GzT9Wh3LXYLPQ54G2YUWyECabikEg5SDQgdkeVtS7VpTOw7QcW998agqrH/yS sUtmSBdU9y4toCxbD3FfDUHRKMoXhZpBCn+56SwOe2WCXPXogVlMhTxYqif4AH5ukB3K r3gpPMxY9uuTXjcx4h/NhGnJayYejJJH312BhpCJ23BvB84tZNqGr1qzSpewYXZCSdf0 bcF3slkYw5twWovwp7lV3dAdjX4zwL70najBqNmF5JSPdR/4HucGNTHHP4C7Fk+EvLV/ 2mEw== X-Gm-Message-State: AOJu0YwklY0iD8kjQqUtDknkFcIur/oRQFFNW1+SieDYznAEVVmXnNzS 5OGfyvDOBxXjVkRtoLOXRakKUw0ftHwd5I4baYt4CKbNVunv+OrAGUCCVAqFWGqqEEQ6n4Mjnix sLN5cMK8= X-Gm-Gg: AR+sD11fUG2PIBzd/siujYQLhZ3YN0EeDqwlsIbdn6NhJZYOP/tmTitQag7AhE2acHi +UGLazJQtAyNQRtQKyxbphBFZRTSTiNxpHM4tPGux3yhZx4HdpdxH1StSK5WEBeJfRkhmIcOOL7 kLO6nLNZzRWx3HYeBp2opUVtO5ehzVz/QKFCtr6X8g2bOngDO2yD6w/JMcR+mxx3HVP71+9Q2Qx GlAlunncfUL4ySpiywkQvRy+x8mVAnkwhJYk0iZrKSDmQ8Sd6jEI7uVFeZk65P19Rzv6yQhm3Y1 VzOVhcoqpqNoY/MG07++j3wbJSV3ZVwot1JYlpGu3d/XtQ/XFg78RKRHKjel7z2BuaGbST33LPN OuakoiJ8fVTL6k5aPgvUlLREzSA0uMZO2oLeMNsCtB9GX4xrXEasfSh0qGxTGW7MhbeleRpwyhI Gnz+UJYH8ox6Od/8vnCHSfQwc= X-Received: by 2002:a17:902:fdaf:b0:2cf:70d2:da7c with SMTP id d9443c01a7336-2cf8dc98e9fmr57990485ad.12.1784751723183; Wed, 22 Jul 2026 13:22:03 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.199]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3147d47960dsm11699468eec.0.2026.07.22.13.22.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 13:22:02 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 06/13] vim: Security Fix for CVE-2026-55693 Date: Thu, 23 Jul 2026 01:48:58 +0530 Message-Id: <20260722201905.491897-6-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260722201905.491897-1-sdoshi@mvista.com> References: <20260722201905.491897-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 20:22:13 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241750 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-55693 [2] https://security-tracker.debian.org/tracker/CVE-2026-55693 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-55693.patch | 88 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 89 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-55693.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-55693.patch b/meta/recipes-support/vim/files/CVE-2026-55693.patch new file mode 100644 index 0000000000..d35b6f5fe5 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-55693.patch @@ -0,0 +1,88 @@ +From 315b35adb406138c962bcc653db95acc3c87c8ab Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Mon, 15 Jun 2026 19:39:08 +0000 +Subject: [PATCH 09/17] patch 9.2.0653: [security]: out-of-bounds write in + tree_count_words() + +Problem: [security]: a crafted spell file can drive tree_count_words() + past the end of its MAXWLEN-sized depth arrays; the descent + loop has no depth bound. +Solution: only descend while depth < MAXWLEN - 1, as the sibling trie + walkers already do; apply the same guard to sug_filltree(). + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-wgh4-64f7-q3jq + +Supported by AI. + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/a80874d9b84a01040e3d1aef2d4a59e1934dafb7] +CVE: CVE-2026-55693 +Signed-off-by: Siddharth Doshi +--- + src/spellfile.c | 4 ++-- + src/testdir/test_spellfile.vim | 27 +++++++++++++++++++++++++++ + 2 files changed, 29 insertions(+), 2 deletions(-) + +diff --git a/src/spellfile.c b/src/spellfile.c +index 0b9536dc16..0010d9aa27 100644 +--- a/src/spellfile.c ++++ b/src/spellfile.c +@@ -645,7 +645,7 @@ tree_count_words(char_u *byts, idx_T *idxs) + ++curi[depth]; + } + } +- else ++ else if (depth < MAXWLEN - 1) + { + // Normal char, go one level deeper to count the words. + ++depth; +@@ -5648,7 +5648,7 @@ sug_filltree(spellinfo_T *spin, slang_T *slang) + ++curi[depth]; + } + } +- else ++ else if (depth < MAXWLEN - 1) + { + // Normal char, go one level deeper. + tword[depth++] = c; +diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim +index b72974ed07..e5f8c5778f 100644 +--- a/src/testdir/test_spellfile.vim ++++ b/src/testdir/test_spellfile.vim +@@ -1166,4 +1166,31 @@ func Test_mkspell_empty_dic() + endfunc + + ++func Test_spell_sug_tree_count_words_overflow() ++ " A crafted .spl/.sug pair with a BY_INDEX self-cycle in the fold word tree ++ " parses cleanly (shared refs aren't recursed, so read_tree_node()'s depth ++ " cap never trips), but drove tree_count_words() past its MAXWLEN-sized depth ++ " arrays -> stack out-of-bounds write. The walk only happens when ++ " spellsuggest() loads the matching .sug. Reaching the assert == no OOB. ++ call mkdir('Xrtp/spell', 'pR') ++ " VIMspell + v50, SN_SUGFILE(ts), SN_END, LWORDTREE{node:1,BY_INDEX->0,'A'}, ++ " empty KWORDTREE/PREFIXTREE ++ let spl = eval('0z56494D7370656C6C320B0000000008000000001234' ++ \ .. '5678FF000000020101000000410000000000000000') ++ " VIMsug + v1, matching ts, SUGWORDTREE word "a", empty SUGTABLE ++ let sug = 0z56494D737567010000000012345678000000040161010000000000 ++ call writefile(spl, 'Xrtp/spell/xx.utf-8.spl', 'b') ++ call writefile(sug, 'Xrtp/spell/xx.utf-8.sug', 'b') ++ ++ new ++ set runtimepath+=./Xrtp ++ set spelllang=xx ++ set spell ++ " Unpatched: OOB write here (ASan abort, or crash). Patched: returns a list. ++ call assert_equal(v:t_list, type(spellsuggest('helloo'))) ++ ++ set spell& spelllang& runtimepath& ++ bwipe! ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 038751ed74..e867d4c1cd 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -38,6 +38,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-43961.patch \ file://CVE-2026-47162.patch \ file://CVE-2026-47167.patch \ + file://CVE-2026-55693.patch \ " PV .= ".1683" From patchwork Wed Jul 22 20:18:59 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93281 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 90822C4453A for ; Wed, 22 Jul 2026 20:22:13 +0000 (UTC) Received: from mail-pf1-f176.google.com (mail-pf1-f176.google.com [209.85.210.176]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.9349.1784751726504473610 for ; Wed, 22 Jul 2026 13:22:06 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=Uerec/Pg; spf=pass (domain: mvista.com, ip: 209.85.210.176, mailfrom: sdoshi@mvista.com) Received: by mail-pf1-f176.google.com with SMTP id d2e1a72fcca58-84830c774a0so7479681b3a.1 for ; Wed, 22 Jul 2026 13:22:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784751726; x=1785356526; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=yrh2nLHz6Y6WC6ygeGf1dbL/mHfXtM35WVz7jcJwofU=; b=Uerec/PghT7IlEquE7/VRkP6HToahaXCf04KTfaolXZdaTFY+d6NqLPUKgd47KiaWR 9O+9lSCFznNYR8FAFDc8UR0pxdemLn3DHF+WfmRdPXxA+zZWYWIPyGdk26ecX8QfN1QW /rsvYrNOCYa0aoojSbPSIpa3Woj65fF15keLQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784751726; x=1785356526; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=yrh2nLHz6Y6WC6ygeGf1dbL/mHfXtM35WVz7jcJwofU=; b=hBIX+cBOX23f1VXPlmQTWB5nmxDIaEi7FV33jfZrjKvtHmh2/gwKkxBn0d86PTa4iN bBMVm5fs3ET2tDzUvRl3BozFPwHYmZIfkXfdR7aoHxvHNBn7DCzhDRC/mrvx6jrGjvL5 jVkGyZlUwkdUJVyWrFszvoQJfBpWpUrNuQ0vfUYBWOeu/hLQeu9xLWBhm9DUnQl7v4C1 46E1U4eKXxHl7rZSp75h1c7SLNLVjc1y7bR9VNSq7ruWyX/mrAcgib1BBMbwWsjTZ9p6 Xil9EAbyAjfLKoOxQUemid5LDJqVDz2bY9dAtUldbS3Y7jj8cNl3d5UWd9kfw2t9OCfT 5Tlw== X-Gm-Message-State: AOJu0YzFftDwcvh+VvM+E7t0HNpwev5NiuvBYC8CZl7W+sLcRlmo9bA4 VmQ35pSExj0cfZxwJlJCTBYm80jo9L23R9JnowVKbbPtfG2nStYWyESjadmcD5j0tomCOuOm4Yp LeDZZeuM= X-Gm-Gg: AR+sD10rxd+C93qVEfybVrp3OP0wAl07dCGch2r6lbOBqxhONLKtI/PY+OzINyJrvUm lticjjw7fs8M0NSIZYn9ZOMqw8eT0dlV4z9Qvyjv1l8kRT9bHGYJLb4ZPCZ/yiK0rdIhw3KuGZ2 Eg4LMkUqGpkI7C/mPlmVU1dz6SdOz0zIjet9vEuj/tZWnhCf57J9dROHUDSHZcDRSzKckxFyt2v yVvO/N1sPwlxKyW8YGJUg8nAQicZVNsYsVlY0JKdWWCMsok0GlADui/apakbkRH2IHr1T124/Wi S8+lyxWiSsyV7GezEgFS95ibwRvhB+f++aYFwpt57tsGgFwTbq1y0nonZbZNz/I42splNRyMAc3 tp3646zxCPCDCUoX8xoHvAD6VxGhZ850TBsMnrWKnxqLzHL9FnL6FYr99iPbXQLuKWvGxK8xDT+ OX2wsf55GNqMRu70HhA5yyKKY= X-Received: by 2002:a05:6a20:3d82:b0:3bf:a0e5:999f with SMTP id adf61e73a8af0-3c44afd5fcdmr35532637.22.1784751725855; Wed, 22 Jul 2026 13:22:05 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.199]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3147d47960dsm11699468eec.0.2026.07.22.13.22.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 13:22:05 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 07/13] vim: Security Fix for CVE-2026-55892 Date: Thu, 23 Jul 2026 01:48:59 +0530 Message-Id: <20260722201905.491897-7-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260722201905.491897-1-sdoshi@mvista.com> References: <20260722201905.491897-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 20:22:13 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241751 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-55892 [2] https://security-tracker.debian.org/tracker/CVE-2026-55892 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-55892.patch | 81 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 82 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-55892.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-55892.patch b/meta/recipes-support/vim/files/CVE-2026-55892.patch new file mode 100644 index 0000000000..5f46c97cfa --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-55892.patch @@ -0,0 +1,81 @@ +From f0df4a48a426bd67c0c2f5ad536000a4368cd4c0 Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Tue, 16 Jun 2026 20:32:21 +0000 +Subject: [PATCH 10/17] patch 9.2.0662: [security] Stack out-of-bounds write in + dump_prefixes() + +Problem: [security]: a crafted spell file with a self-referential + BY_INDEX node in the prefix tree can drive dump_prefixes() + past the end of its MAXWLEN-sized depth arrays on :spelldump + (cipher-creator) +Solution: only descend while depth < MAXWLEN - 1, as the sibling trie + walkers already do (Yasuhiro Matsumoto) + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-qm9w-fmpj-879h + +Supported by AI + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/8325b193bba5f01e7a7d8241fc8633d93dff996b] +CVE: CVE-2026-55892 +Signed-off-by: Siddharth Doshi +--- + src/spell.c | 2 +- + src/testdir/test_spell.vim | 27 +++++++++++++++++++++++++++ + 2 files changed, 28 insertions(+), 1 deletion(-) + +diff --git a/src/spell.c b/src/spell.c +index 2281986435..6ef3fa899b 100644 +--- a/src/spell.c ++++ b/src/spell.c +@@ -4328,7 +4328,7 @@ dump_prefixes( + } + } + } +- else ++ else if (depth < MAXWLEN - 1) + { + // Normal char, go one level deeper. + prefix[depth++] = c; +diff --git a/src/testdir/test_spell.vim b/src/testdir/test_spell.vim +index 170ea57926..2a3f0e3696 100644 +--- a/src/testdir/test_spell.vim ++++ b/src/testdir/test_spell.vim +@@ -1567,4 +1567,31 @@ let g:test_data_aff_sal = [ + \"SAL Z S", + \ ] + ++" A crafted .spl with a self-referential BY_INDEX node in the PREFIXTREE drove ++" dump_prefixes() past its MAXWLEN-sized depth arrays (stack out-of-bounds ++" write). The tree parses cleanly (shared refs aren't recursed); the walk ++" happens on :spelldump. Reaching the assert means no OOB. Same class as the ++" tree_count_words() fix (9.2.0653). ++func Test_spelldump_prefixtree_overflow() ++ CheckUnix ++ call mkdir('Xrtp/spell', 'pR') ++ " VIMspell + v50, SN_PREFCOND(prefixcnt=1), SN_END, ++ " LWORDTREE word "a" with affixID=1 (so dump_prefixes runs), ++ " empty KWORDTREE, PREFIXTREE child BY_INDEX -> nodeidx 0 (self-cycle), 'A' ++ let spl = eval('0z56494D7370656C6C32030000000003000100FF00000004' ++ \ .. '0161010220010000000000000002010100000041') ++ call writefile(spl, 'Xrtp/spell/xx.utf-8.spl', 'b') ++ ++ new ++ set runtimepath+=./Xrtp ++ set spelllang=xx ++ set spell ++ spelldump ++ call assert_true(line('$') > 1) ++ ++ set spell& spelllang& runtimepath& ++ bwipe! ++ bwipe! ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index e867d4c1cd..64e3eab106 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -39,6 +39,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-47162.patch \ file://CVE-2026-47167.patch \ file://CVE-2026-55693.patch \ + file://CVE-2026-55892.patch \ " PV .= ".1683" From patchwork Wed Jul 22 20:19:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93284 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9D19AC4453F for ; Wed, 22 Jul 2026 20:22:13 +0000 (UTC) Received: from mail-pl1-f177.google.com (mail-pl1-f177.google.com [209.85.214.177]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.9348.1784751730346467435 for ; Wed, 22 Jul 2026 13:22:10 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=Ga3X2dE2; spf=pass (domain: mvista.com, ip: 209.85.214.177, mailfrom: sdoshi@mvista.com) Received: by mail-pl1-f177.google.com with SMTP id d9443c01a7336-2cae1a3a744so97546405ad.3 for ; Wed, 22 Jul 2026 13:22:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784751730; x=1785356530; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=w2ylDJHfN6eboNGhjTfK6F0Comaey72ufFrog9E/4N0=; b=Ga3X2dE2tZEJ+XiasD0J4OcfHrtfVaSFqFi2QQVCYCi3ZXlE4blG48k8Q8qdkMBKrE 7zLyG23h02CBATbNUOdNwx4Q349G740YTv0i6BVAFEqopSCgrgySNVhgWqKtsRpRYSk8 BsMgwo8g0QIlaL3ZGAzS3RbwVldMypQ3jmqvY= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784751730; x=1785356530; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=w2ylDJHfN6eboNGhjTfK6F0Comaey72ufFrog9E/4N0=; b=l2AIVBcbphhcJn+/bmYxbD6/4pIDHw3bBZxRXKS2jGBzWJZm/5VWyAy0bE7AnHGNc3 ZCwhEKguhDIC91X52Xnrl2U0u6Iun92AVJdaznMjfbKY6b6D72Gu3dF7JoGG4P7TlGWD fZ6ow5R00GSDGyBhIKxRGILKeiCF/ShZb+1h0/xJRKgoIbBSC6Kl7NK7Jgh1f+ur2MpE 3MGggYsFudvMP5eS7Fvl+eWcpXPxWWvaAuxvN8wsC5h7fPzJxMWZh85wLAJHbXtf3BLA qvEyZPbjYu01Q7nzWHQHTM5uAv/X1ZI1csn05PhGihTbrTeZrLlWciUiuVvxcqBpFU/a lbaw== X-Gm-Message-State: AOJu0Yz6RCqTOJPD4Y2Guqnag5fRNQ1zHrSgXw7MnYIiehmp7R2Wzbjl 5kthmpCj3E5JPwSBs/q4AnTZIRME0s52P+mn9iYnI8CiSH2/se/Y6VIL63DXemz958f83tQYgOX zWRkmbsg= X-Gm-Gg: AR+sD12XXSygq78T3WSO1TQSBo/8bYlNEv5yTzITq7QkwwoOMvdPI2Mc1qNqUMBnFNK z+9IG56B+rZMrruYv6z69qafcrNHxXlaSOzsccaRv9EE/YpAh5nleSmPPc/hYBUNhOsdR0vrRFv zKec91B06U1rp1mCFpR8jV98Y6mn0WcdBTQseq+vK48SS7LsDGyk6r75N/0sZ6K1hVz2lgydUg2 gwlxzGzPt1EiP1Ccitu24GwLvteMaYKpembi+wUMdmfFWWUov4ny+EtyQz04JG6qJimagtHhM9W irM8GLFLeIPUSQT4y+YuYSRAN4yRvsshs4IA48CFRYmxGgXzRPpuAE7dU+AOFDcBTwTN6dSl8jL xKw4tx6QVS2aN8UkSNiJJVSmc47uyheDP2TLXx6TnTdenYQJ/GBXLJcUgxDOJe+qeW3tmrXqA7C IGn3PfhQpA8/6C X-Received: by 2002:a17:902:f693:b0:2cc:d192:50b5 with SMTP id d9443c01a7336-2cfa75078dbmr3611065ad.34.1784751729723; Wed, 22 Jul 2026 13:22:09 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.199]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3147d47960dsm11699468eec.0.2026.07.22.13.22.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 13:22:09 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 08/13] vim: Security Fix for CVE-2026-55895 Date: Thu, 23 Jul 2026 01:49:00 +0530 Message-Id: <20260722201905.491897-8-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260722201905.491897-1-sdoshi@mvista.com> References: <20260722201905.491897-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 20:22:13 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241752 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-55895 [2] https://security-tracker.debian.org/tracker/CVE-2026-55895 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-55895.patch | 53 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 54 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-55895.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-55895.patch b/meta/recipes-support/vim/files/CVE-2026-55895.patch new file mode 100644 index 0000000000..0084006b72 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-55895.patch @@ -0,0 +1,53 @@ +From 0d286458d71ff7b4d759621dd9a567aa9354819a Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Tue, 16 Jun 2026 21:00:28 +0000 +Subject: [PATCH 11/17] patch 9.2.0663: [security]: runtime(netrw): code + injection in local file deletion + +Problem: [security]: s:NetrwLocalRmFile() escapes only the backslash in + the file name before passing it to :execute, so a name + containing "|" injects arbitrary Ex commands when the file is + deleted (cipher-creator) +Solution: Use fnameescape() to correctly escape the file name + (Yasuhiro Matsumoto). + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-vhh8-v6wx-hjjh + +Supported by AI + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/55bc757a5d436e59d50fe43f7cda94b118f86cb2] +CVE: CVE-2026-55895 +Signed-off-by: Siddharth Doshi +--- + runtime/pack/dist/opt/netrw/autoload/netrw.vim | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index 9014ca339b..af43f469d1 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -3025,7 +3025,7 @@ function s:NetrwBrowse(islocal,dirname) + elseif !a:islocal && dirname !~ '[\/]$' && dirname !~ '^"' + " s:NetrwBrowse : remote regular file handler {{{3 + if bufname(dirname) != "" +- exe "NetrwKeepj b ".bufname(dirname) ++ exe "NetrwKeepj b ".fnameescape(bufname(dirname)) + else + " attempt transfer of remote regular file + +@@ -8737,7 +8737,7 @@ function s:NetrwLocalRmFile(path, fname, all) + call netrw#msg#Notify('ERROR', printf("unable to delete <%s>!", rmfile)) + else + " Remove file only if there are no pending changes +- execute printf('silent! bwipeout %s', rmfile) ++ execute printf('silent! bwipeout %s', fnameescape(rmfile)) + endif + + elseif dir && (all || empty(ok)) +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 64e3eab106..5a4778fe7c 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -40,6 +40,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-47167.patch \ file://CVE-2026-55693.patch \ file://CVE-2026-55892.patch \ + file://CVE-2026-55895.patch \ " PV .= ".1683" From patchwork Wed Jul 22 20:19:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93283 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D5F73C531BC for ; Wed, 22 Jul 2026 20:22:13 +0000 (UTC) Received: from mail-pl1-f178.google.com (mail-pl1-f178.google.com [209.85.214.178]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.9353.1784751733496095336 for ; Wed, 22 Jul 2026 13:22:13 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=kDEnxu5g; spf=pass (domain: mvista.com, ip: 209.85.214.178, mailfrom: sdoshi@mvista.com) Received: by mail-pl1-f178.google.com with SMTP id d9443c01a7336-2cc891373e0so163161615ad.2 for ; Wed, 22 Jul 2026 13:22:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784751733; x=1785356533; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=N17u9LLjVTN1fYJfvrFsxJerOrXS+NF+DEduOPOQdiw=; b=kDEnxu5g2P/3ROC5FPfqsOI+X+Q5S3y8Df8+MIOKRVz5o6PJ5kpEYShESgW5Qf7Qpt u7HVD10f4VbJoUDc5CxzPRYr1FubnJ0lB6hd4D9pVJ5YtlmEB/nFcAh4/iaEtbkQ/wq/ Gq6TOvj50+pQkD2iw5ZDcfGPQbynMGvFDsFhk= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784751733; x=1785356533; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=N17u9LLjVTN1fYJfvrFsxJerOrXS+NF+DEduOPOQdiw=; b=ojoPgfD5KXqn7t7BBw9HGygJEzYY+f/XirGzJ4GKpqrdAn+NkVjni13IclqvB/vOzY aObjuNHr06suCdLUPrfMAQu/hYAf+8oavGPFsROg+gvVmh6gNN372jzk2AuTgHSSSx07 +DwaYE//pY9i4UmPLU2AbDZFyWywZvgWJMY1ws4UCMYhRx4bdxQAAH2cqtJJDqx/Bevj Y9lIpbvAdcZQSkS/tagdQwMzwGa5FOyvMW5uBar4f8lkriNoWZW0ZipgDSToGhAd4QFY 1X4Y9/Ao5Va3V0d0pMywMplwhRiEsE9Op3RLXzcGw75T9xMflU+OY6ux7hpS4kLpfk9S VDtQ== X-Gm-Message-State: AOJu0YzeforQenMQ3EHDW8AxJfiTFG9Nvr8dHEtQRegclX5UmjkhCCWF 6jzh9SPpjHUnKBDGAVyJHc3cMTT85EEZAvqJQzuYxdSD10qM78x9dSuV8kQ/aroiZ2ACbhpYfmT VIliwNWc= X-Gm-Gg: AR+sD13SDWgeZd6o1eLV5FaUU/MtDSJkR3kvYYDStcR5zt76GKMxx6o/TFKqGWFVZFH XI1GsXYrkwwUyVTZbV+jB4CtfFBt8Mf74ANNGt1oLlM4e9gWK80x8/GGi+vL5O0pDQZw55jODw6 m6CoJEsh0q7jCX8zxfsovUty2rQjgwKLQ+9CN044643+cPm47XaC95oAgXxlxbC30hFi56fO2KQ og5FNguZ+6a2qE0TJElxCfZzq1Sn+PNUPWqzbk441ndvhHnl5Gx4D5DfSHie+WF5bxgq5ydr4ze De07Fly2yVlX16iwgQaFE0X6bjnaE+MH//NarMwQmDj2bcfnyT3G9if2bgh9bIwPtFAhYfBBZAN 2iP8SwvuyBkSZ21acdiO6HUInPHmyqcLPCdZ2aXB3j+YiQ1mdx76nl0Tna+6wvO6OasP5w1R5Ey YK4EVGLnyaz6QI X-Received: by 2002:a17:903:2390:b0:2cf:7e56:22c4 with SMTP id d9443c01a7336-2cfa6c667a3mr3855545ad.30.1784751732859; Wed, 22 Jul 2026 13:22:12 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.199]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3147d47960dsm11699468eec.0.2026.07.22.13.22.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 13:22:12 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 09/13] vim: Security Fix for CVE-2026-57452 Date: Thu, 23 Jul 2026 01:49:01 +0530 Message-Id: <20260722201905.491897-9-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260722201905.491897-1-sdoshi@mvista.com> References: <20260722201905.491897-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 20:22:13 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241753 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57452 [2] https://security-tracker.debian.org/tracker/CVE-2026-57452 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-57452.patch | 76 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 77 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-57452.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-57452.patch b/meta/recipes-support/vim/files/CVE-2026-57452.patch new file mode 100644 index 0000000000..aaefbe80eb --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-57452.patch @@ -0,0 +1,76 @@ +From c8777cec25dcfae89c42e9aff51af61f71c5745f Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Thu, 18 Jun 2026 18:41:16 +0000 +Subject: [PATCH] patch 9.2.0671: [security]: possible out-of-bounds read with + sodium encrypted files + +Problem: [security]: possible out-of-bounds read with sodium encrypted + files (cipher-creator) +Solution: Verify that there is enough space before calling + crypto_secretstream_xchacha20poly1305_init_pull() + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-c4j9-wr9j-4486 + +Supported by AI + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/c8777cec25dcfae89c42e9aff51af61f71c5745f] +CVE: CVE-2026-57452 +Signed-off-by: Siddharth Doshi +--- + src/crypt.c | 3 ++- + src/testdir/test_crypt.vim | 24 ++++++++++++++++++++++++ + 2 files changed, 26 insertions(+), 1 deletion(-) + +diff --git a/src/crypt.c b/src/crypt.c +index 55edd6c6de..a11d204e5e 100644 +--- a/src/crypt.c ++++ b/src/crypt.c +@@ -1257,7 +1257,8 @@ crypt_sodium_buffer_decode( + + if (sod_st->count == 0) + { +- if (crypto_secretstream_xchacha20poly1305_init_pull(&sod_st->state, ++ if (len < crypto_secretstream_xchacha20poly1305_HEADERBYTES || ++ crypto_secretstream_xchacha20poly1305_init_pull(&sod_st->state, + from, sod_st->key) != 0) + { + emsg(_(e_libsodium_decryption_failed_header_incomplete)); +diff --git a/src/testdir/test_crypt.vim b/src/testdir/test_crypt.vim +index 4a96c30702..151a4dea17 100644 +--- a/src/testdir/test_crypt.vim ++++ b/src/testdir/test_crypt.vim +@@ -459,4 +459,28 @@ func Test_crypt_set_key_disallow_append_subtract() + bwipe! + endfunc + ++func Test_crypt_sodium_short_body() ++ CheckFeature sodium ++ " A VimCrypt~04! file with a complete 36-byte header (12 magic + 16 salt + ++ " 8 seed) but a body shorter than one secretstream header (24 bytes) used to ++ " underflow the body length and crash with a wild out-of-bounds read in ++ " crypto_secretstream_xchacha20poly1305_pull(). It must now fail cleanly. ++ " Bytes: "VimCrypt~04!" + 16 salt + 8 seed + 8-byte body = 44 bytes. ++ call writefile(0z56696D43727970747E303421 ++ \ + 0zA0A1A2A3A4A5A6A7A8A9AAABACADAEAF ++ \ + 0zB0B1B2B3B4B5B6B7 ++ \ + 0z0000000000000000, 'Xtest_sodium_short') ++ ++ let v:errmsg = '' ++ try ++ call feedkeys(":split Xtest_sodium_short\foobar\", "xt") ++ catch /^Vim\%((\S\+)\)\=:E1198:/ ++ " no-op ++ endtry ++ ++ bwipe! ++ call delete('Xtest_sodium_short') ++ set key= ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 5a4778fe7c..938fdecaf3 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -41,6 +41,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-55693.patch \ file://CVE-2026-55892.patch \ file://CVE-2026-55895.patch \ + file://CVE-2026-57452.patch \ " PV .= ".1683" From patchwork Wed Jul 22 20:19:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93287 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DA239C4453A for ; Wed, 22 Jul 2026 20:22:23 +0000 (UTC) Received: from mail-pg1-f174.google.com (mail-pg1-f174.google.com [209.85.215.174]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.9357.1784751736731488787 for ; Wed, 22 Jul 2026 13:22:16 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=cuoRsSoA; spf=pass (domain: mvista.com, ip: 209.85.215.174, mailfrom: sdoshi@mvista.com) Received: by mail-pg1-f174.google.com with SMTP id 41be03b00d2f7-c9cf07d2df6so8215543a12.2 for ; Wed, 22 Jul 2026 13:22:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784751736; x=1785356536; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=fXdTaZyWKkwVjAQEYKXmUhUEp7G783ejPNvu6vGMr4w=; b=cuoRsSoA4E8FaVY9hIWFS5RbeYlTns9vrY+BX+WSUwEP/G8a42x5hDmd+GJtkpcXiQ dLkaYl6ZXT0nExzTyAEmgZYT/mA9JfEmugFzhN+4Eua3mqY5SumA8Vy9H5P0lQIPMoCm 5W5REuFMQGHQnOYmaRRg5V18U8iH10Qq4Dz2A= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784751736; x=1785356536; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=fXdTaZyWKkwVjAQEYKXmUhUEp7G783ejPNvu6vGMr4w=; b=dvAQMjw1OCSZlE5Wgm5rKU4j9TxKXsI+GWudpMb9UJFA13fLvVZC8Pc0zg0tW+D1hb oeS9eB2o4liv5JC2lAVF2Onh/Hw9qTJu4dGLikb1M4zoSeMASqU04nRTCeU3vYjbXlB8 pQN6HAlJeCrOqOkZJ8W3sNaESzyT1xMG8PPPxKf7AqkCqP+PZG+FIX4aaKPb6BGxH0l9 To6jfk5I8gMSC8ZC8W5DB3/CnGVyoXwwrRIF2Ni0sDkpbe5mKOXzjM09POkkMbVRfKjF 86gYolzIvkNAAbhBnc7A0FRotyZgDRm1+ckfVra5qPlW9jrTqZBDOiARGS2vDimzNl1b QhaQ== X-Gm-Message-State: AOJu0YywzKknftOdrSjui4Oga+B4FngUDrDoAbmMq5Dt87RROKVnnqRo mY63+UFn0KW56STDf6ULP9ebybD5ye0d0Tp/CwrJWSD0LV1PkIF5OTH+g12iesqrNwWDNOuH0VR oKetn9oo= X-Gm-Gg: AR+sD11RrrPuQOddIpqzRyG+CH+WVMhRJufWYk93usrtdT4quHWG3Xy1T9+1A9i1FkV D5LXzwaf9gWb83hXsjyjqwnQDAhNEHtIkFyyduk2Ple/bCHChJAi9z4rykp+Y39Alb8lLplbq5k wrNGOlsKxk07uamtCOmHImp7i+4vN1sGrQS24tgw01dEm75HJALOMe5FkOGIxyGRYMZ0yvmNCwi 8IOgX4wVdWZtYNkSDMeZIPTUHP8dAENjnvfmSqmT4Td8DWicAWtH82Hb+hft35Rabn0xTfR0e31 OKTZMWD+Djmf8Tz4UFGP7nzHA6zycWRsiKJ4bfhhxj7Yq7Nv6pp3WXzUt72D8Pdpli5cEB7LPOS 3LhbutK7IGDqBl9r/hSQRdMhsT8YtLUT2m4o29n8vAhdcKWshTsF8mQv0qvPkNsGfTkPqtn96Jr MxAU6Cg/1pdyLo X-Received: by 2002:a05:6a21:6e03:b0:3c3:96dd:9ecc with SMTP id adf61e73a8af0-3c44b201100mr7424637.57.1784751736059; Wed, 22 Jul 2026 13:22:16 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.199]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3147d47960dsm11699468eec.0.2026.07.22.13.22.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 13:22:15 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 10/13] vim: Security Fix for CVE-2026-57455 Date: Thu, 23 Jul 2026 01:49:02 +0530 Message-Id: <20260722201905.491897-10-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260722201905.491897-1-sdoshi@mvista.com> References: <20260722201905.491897-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 20:22:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241754 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57455 [2] https://security-tracker.debian.org/tracker/CVE-2026-57455 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-57455.patch | 72 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 73 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-57455.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-57455.patch b/meta/recipes-support/vim/files/CVE-2026-57455.patch new file mode 100644 index 0000000000..722238c794 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-57455.patch @@ -0,0 +1,72 @@ +From 497d2fb19b2af9bccf139bb910e4f91b583e769d Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Sun, 21 Jun 2026 19:20:03 +0000 +Subject: [PATCH 13/17] patch 9.2.0698: [security]: Out-of-bounds write with + soundfold() + +Problem: [security]: Out-of-bounds write with soundfold() + (cipher-creator) +Solution: Add an abort condition to the for loop to validate the buffer + size. + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-q8mh-6qm3-25g4 + +Supported by AI + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/497f931f85339d175d7f69588dd249e8ccfed41b] +CVE: CVE-2026-57455 +Signed-off-by: Siddharth Doshi +--- + src/spell.c | 2 +- + src/testdir/test_spellfile.vim | 21 +++++++++++++++++++++ + 2 files changed, 22 insertions(+), 1 deletion(-) + +diff --git a/src/spell.c b/src/spell.c +index 6ef3fa899b..a7909ef46e 100644 +--- a/src/spell.c ++++ b/src/spell.c +@@ -3273,7 +3273,7 @@ spell_soundfold_sofo(slang_T *slang, char_u *inword, char_u *res) + else + { + // The sl_sal_first[] table contains the translation. +- for (s = inword; (c = *s) != NUL; ++s) ++ for (s = inword; (c = *s) != NUL && ri < MAXWLEN - 1; ++s) + { + if (VIM_ISWHITE(c)) + c = ' '; +diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim +index e5f8c5778f..d04d024911 100644 +--- a/src/testdir/test_spellfile.vim ++++ b/src/testdir/test_spellfile.vim +@@ -1193,4 +1193,25 @@ func Test_spell_sug_tree_count_words_overflow() + bwipe! + endfunc + ++" A word longer than MAXWLEN must not overflow the soundfold result buffer in ++" the single-byte SOFO branch of spell_soundfold_sofo(). ++func Test_soundfold_overflow() ++ let _enc=&enc ++ set enc=latin1 ++ call writefile(['SOFOFROM ab', 'SOFOTO xy'], 'Xtest.aff', 'D') ++ call writefile(['1', 'foo'], 'Xtest.dic', 'D') ++ mkspell! Xtest Xtest ++ defer delete('Xtest.latin1.spl') ++ defer delete('Xtest.latin1.sug') ++ setl spelllang=Xtest.latin1.spl spell ++ ++ " Before the fix the copy loop wrote one byte per input byte into a ++ " MAXWLEN (254) stack buffer with no upper bound, smashing the stack. ++ let sound = soundfold(repeat('ab', 300)) ++ call assert_true(strlen(sound) < 254, 'soundfold result exceeds MAXWLEN') ++ ++ set spell& spelllang& ++ let &enc = _enc ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 938fdecaf3..a76cdc53ae 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -42,6 +42,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-55892.patch \ file://CVE-2026-55895.patch \ file://CVE-2026-57452.patch \ + file://CVE-2026-57455.patch \ " PV .= ".1683" From patchwork Wed Jul 22 20:19:03 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93286 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C0CDEC44536 for ; Wed, 22 Jul 2026 20:22:23 +0000 (UTC) Received: from mail-pg1-f175.google.com (mail-pg1-f175.google.com [209.85.215.175]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.9353.1784751739633965142 for ; Wed, 22 Jul 2026 13:22:19 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=dYqTL2Mm; spf=pass (domain: mvista.com, ip: 209.85.215.175, mailfrom: sdoshi@mvista.com) Received: by mail-pg1-f175.google.com with SMTP id 41be03b00d2f7-cbb85186d43so1502093a12.3 for ; Wed, 22 Jul 2026 13:22:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784751739; x=1785356539; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=5+8PYm7JkNVL8AfkNIe/0OqGlZ0HzSvCmex1Gyv1dCA=; b=dYqTL2MmUgwrg/LAXWZlcM87DvhTrZswkYM7ZH8L1LkCaKo5wTWRQWbUpEGlz5wRmV yFsRltMM1ILIl65A9hiP1bc7uFwgNhb7e19pZD1zwM+rCumTZBl91Mm0wFOM7h97IEw6 ULhjxL3R/avG/peUX7HXmCW6hzkfvVkbKUTug= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784751739; x=1785356539; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=5+8PYm7JkNVL8AfkNIe/0OqGlZ0HzSvCmex1Gyv1dCA=; b=eRW/pLFBbWNSRIATxJ8xooJgeGggwMl7+40EHyPPs/BmPL8crmOAHXboiDvf7sFx8D 44JVkz5ltQAAwHqK8W1qtL7rxtxZaV3oeaeOHV89XdEKUffSnjLWxCD9F71JlHJTCJLF qjwgZWrpB5FpxspO5sq/4Ym1cIuYQPFql0wItmv9PgpRPc+fB7fjFF4k0rMEEf9YnNXP 0g9xiKqHd8LcpY9clcJM9vvje3Fw+Q/xGEJ60HF9nv15fxYF1r/ndwi2kHayBENddNag jITkHvS0yAsh+o5BtHYCeX4v/LqagnorKO/V+rmpIyxUUeFM9zX0fo7jj3FVc/+YfwXD nk2A== X-Gm-Message-State: AOJu0YxLAnPKyXfVaTYkKWEwZnU04asjvHo04kl8SID1R7+ZGJAMsYtN m08FAj6hXVIMNHUBZFHgyGJcfQe52dWIGFlvz19XpYpbBX1T3r18excflveZE//TBL/w2FU2BzO E5fqD3TE= X-Gm-Gg: AR+sD10yErpirxxMeHrIRUKI9QuUdaQ8fK8v1t7akaaeLsfuGUFSWdB6KROb/nHKf01 aweVZD1lVjF7mN0HFUyAEvKpYd6kmVWfi363mLGEOi30r1myPlERTC7L9UUZS8FjkQOEOBcFIi7 1ngB61SIE+XIjkso4HG3p4FAt/fEcswg5qfbedt/EPhJa8qEcdj68JMC5sbzP7qIOR/dTcmZNK0 tHyzLjWNpLHHkB3aPVwHDu1pY2YUyTqxKtFh0EtdWKSjVufuc0lp8AJBECWfyFAJtvxqaRbJRAx 4mYBBHmI2EPvQn11+OhbSo2Ub8fT0PXHOKEx153z8aHZWcNfQ93LjMxZ7BBGUYo0lBuJ437HHBk KAkLkFj5s1Y1PV/x8sw2O3usKunoHCUbAZyYU6GOnE54E5tEqRwrvFJWqMwe1eVBeCxC354ESKy R/qx/KvoExUZG5 X-Received: by 2002:a05:6a21:7111:b0:3c0:9c1a:8953 with SMTP id adf61e73a8af0-3c44b2627b6mr2524637.75.1784751738858; Wed, 22 Jul 2026 13:22:18 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.199]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3147d47960dsm11699468eec.0.2026.07.22.13.22.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 13:22:18 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 11/13] vim: Security Fix for CVE-2026-59856 Date: Thu, 23 Jul 2026 01:49:03 +0530 Message-Id: <20260722201905.491897-11-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260722201905.491897-1-sdoshi@mvista.com> References: <20260722201905.491897-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 20:22:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241755 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-59856 [2] https://security-tracker.debian.org/tracker/CVE-2026-59856 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-59856.patch | 103 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 104 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-59856.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-59856.patch b/meta/recipes-support/vim/files/CVE-2026-59856.patch new file mode 100644 index 0000000000..de12e5c4f5 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-59856.patch @@ -0,0 +1,103 @@ +From 43afc581a37a35762dd0ef292f038b9dc5680a24 Mon Sep 17 00:00:00 2001 +From: Hirohito Higashi +Date: Fri, 26 Jun 2026 20:07:01 +0900 +Subject: [PATCH] patch 9.2.0736: potential command execution in PHP + omni-completion + +Problem: With PHP omni-completion, a crafted file can potentially + execute arbitrary commands when completing a class member. +Solution: Quote the class name before inserting it into the search() + pattern run via win_execute(). + +Co-Authored-By: Claude Opus 4.8 (1M context) +Signed-off-by: Hirohito Higashi +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/43afc581a37a35762dd0ef292f038b9dc5680a24] +CVE: CVE-2026-59856 +Signed-off-by: Siddharth Doshi +--- + runtime/autoload/phpcomplete.vim | 3 ++- + src/testdir/Make_all.mak | 2 ++ + src/testdir/test_plugin_phpcomplete.vim | 35 +++++++++++++++++++++++++ + 3 files changed, 39 insertions(+), 1 deletion(-) + create mode 100644 src/testdir/test_plugin_phpcomplete.vim + +diff --git a/runtime/autoload/phpcomplete.vim b/runtime/autoload/phpcomplete.vim +index 5b4263ae45..93f7d8b450 100644 +--- a/runtime/autoload/phpcomplete.vim ++++ b/runtime/autoload/phpcomplete.vim +@@ -2082,7 +2082,8 @@ function! phpcomplete#GetClassContentsStructure(file_path, file_lines, class_nam + let result = [] + let popup_id = popup_create(a:file_lines, {'hidden': v:true}) + +- call win_execute(popup_id, 'call search(''\c\(class\|interface\|trait\)\_s\+'.a:class_name.'\(\>\|$\)'')') ++ call win_execute(popup_id, 'call search(' ++ \ . string('\c\(class\|interface\|trait\)\_s\+' . a:class_name . '\(\>\|$\)') . ')') + call win_execute(popup_id, "let cfline = line('.')") + call win_execute(popup_id, "call search('{')") + call win_execute(popup_id, "let endline = line('.')") +diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak +index 0d4aeb0432..7d57b2e727 100644 +--- a/src/testdir/Make_all.mak ++++ b/src/testdir/Make_all.mak +@@ -247,6 +247,7 @@ NEW_TESTS = \ + test_plugin_helptoc \ + test_plugin_man \ + test_plugin_matchparen \ ++ test_plugin_phpcomplete \ + test_plugin_tar \ + test_plugin_termdebug \ + test_plugin_tohtml \ +@@ -520,6 +521,7 @@ NEW_TESTS_RES = \ + test_plugin_helptoc.res \ + test_plugin_man.res \ + test_plugin_matchparen.res \ ++ test_plugin_phpcomplete.res \ + test_plugin_tar.res \ + test_plugin_termdebug.res \ + test_plugin_tohtml.res \ +diff --git a/src/testdir/test_plugin_phpcomplete.vim b/src/testdir/test_plugin_phpcomplete.vim +new file mode 100644 +index 0000000000..7f66be47b7 +--- /dev/null ++++ b/src/testdir/test_plugin_phpcomplete.vim +@@ -0,0 +1,35 @@ ++" Tests for the PHP omni-completion plugin (runtime/autoload/phpcomplete.vim). ++ ++" A buffer class name is interpolated into a search() pattern run via ++" win_execute(). Without escaping, "'" closes the string and "|" starts a new ++" Ex command, so the name runs as an Ex command during completion. ++func Test_phpcomplete_no_exec_via_class_name() ++ unlet! g:phpcomplete_injected ++ let lines = [' 0, 'no class structure returned') ++ call assert_match('class Foo', result[0].content, ++ \ 'class body missing from returned content') ++ call assert_match('bar', result[0].content, ++ \ 'class member missing from returned content') ++endfunc ++ ++" vim: shiftwidth=2 sts=2 expandtab +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index a76cdc53ae..770872df01 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -43,6 +43,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-55895.patch \ file://CVE-2026-57452.patch \ file://CVE-2026-57455.patch \ + file://CVE-2026-59856.patch \ " PV .= ".1683" From patchwork Wed Jul 22 20:19:04 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93285 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CC17AC4453C for ; Wed, 22 Jul 2026 20:22:23 +0000 (UTC) Received: from mail-pl1-f171.google.com (mail-pl1-f171.google.com [209.85.214.171]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.9355.1784751742478078471 for ; Wed, 22 Jul 2026 13:22:22 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=PI5bPFyd; spf=pass (domain: mvista.com, ip: 209.85.214.171, mailfrom: sdoshi@mvista.com) Received: by mail-pl1-f171.google.com with SMTP id d9443c01a7336-2ceed7018c8so64586065ad.1 for ; Wed, 22 Jul 2026 13:22:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784751742; x=1785356542; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=KAnr4DfG96EQbUjFEAyG3/DKZ6T9l7h8nrH4+qzdin4=; b=PI5bPFyd0QxhWUgiIulOKLvukBXuo3r2nc57/jFrO/sEO51OZep/SAg7Mp5HPgjqVl DpteCIGxddF2ZerjaHmLhVtsBkVlTr/ob994xyIE9fUQYgvY31d1Py82wxQQrXfbSaAg Rc1V/LqSQTq/SEpHyG9cSpGEcvLeg7CnXCPD4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784751742; x=1785356542; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=KAnr4DfG96EQbUjFEAyG3/DKZ6T9l7h8nrH4+qzdin4=; b=BXUqwMnBf6mYZnmfLF+JqKDXkaJ1rtC4A3HuhF8bExab3lrTGR+zE7zCoJSLjpw6BH UvvgLstDXTlcAfD4D4gCZKUMaV9bi6jlw53y+Kg+717Sx1ikA3QyqEmTa0Ycvs9W8Zi6 7e36Xi1HCBNeleHlTGwkLnYTY9Znz/yU7g4gxQJIePnMUuWaJWIyfumyvzHuDtix+I4d LW3doAz1LzKQUA0Ltc3jBBCGps/6Qthh6PDezaT/f3aHR0ermhqKsEJ8yHi1iUGAlwIA GknkFfSxLwgwbPpTEZqWBVI1sQZ8S2rLD+0PmFVmSctKNP0ljpwdBNKvGCM87fCRCKnQ tJjg== X-Gm-Message-State: AOJu0Yzb96u7QeUxtRM1FSbxDr+oe1xayxNH+wo0yAk/mMj9cNi3FaUK R/tKFxLR+V8NDwA7hKSGWaexfuHqkPJaGaO+IGEiuB3pdxKLycsLrX8V5XChtzUGvA8uf60dBHH 78siWsEs= X-Gm-Gg: AR+sD10wRLGx2H+wVsi1ipeWlT9aT7hNeswD6KRpFP+yCsvDu4woPgE9wOZyFg3i+/+ xvL2eoFBFYCDc9oL1ZAWUWJ0NVAo2bNba3dWxtZym0oIp4CqK34tiretldwJ5wrVXijN/SjvZ3D Gb2niWSt4WcDc9iAGoa/NsBPjNZQ88BR3tKyUL8ycod9+AGzIKmQKQ+4ap0mshuM9rSY8Di8hVj +j+eftQPvMDN+p1g2GLf1Jx+2lrkST0WVy/Oo0mt2+h5Fi4/OaEioCMqeLcwuA+Q8w3w72wYhbN tG0xemFDoVdHqTbE1VwUB/XqXT4cTz6nhXE/up7925UEt1IYAd68ieotSL6FAJJzfr5VLLWF1ri IxrGCb6R+aqCmlasx6EUaPZGSqvHXLbowhA47JNEnHulyzDo5Uf/rYyXiJ1snr5KC9CKOlEK8dq Sswh8ehhCpIeEcUOB+vuqF5no= X-Received: by 2002:a17:903:198c:b0:2c9:97a7:f548 with SMTP id d9443c01a7336-2cfa6f875f2mr4186175ad.46.1784751741751; Wed, 22 Jul 2026 13:22:21 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.199]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3147d47960dsm11699468eec.0.2026.07.22.13.22.19 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 13:22:21 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 12/13] vim: Security Fix for CVE-2026-59857 Date: Thu, 23 Jul 2026 01:49:04 +0530 Message-Id: <20260722201905.491897-12-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260722201905.491897-1-sdoshi@mvista.com> References: <20260722201905.491897-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 20:22:23 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241756 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-59857 [2] https://security-tracker.debian.org/tracker/CVE-2026-59857 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-59857.patch | 110 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 111 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-59857.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-59857.patch b/meta/recipes-support/vim/files/CVE-2026-59857.patch new file mode 100644 index 0000000000..ed92190a95 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-59857.patch @@ -0,0 +1,110 @@ +From 48287480f53acfb5e6f9172e571ed2f0508dfab2 Mon Sep 17 00:00:00 2001 +From: Hirohito Higashi +Date: Mon, 22 Jun 2026 13:00:36 +0900 +Subject: [PATCH 16/17] patch 9.2.0725: [security]: Stack out-of-bounds write + in spell_soundfold_sal() + +Problem: [security]: A crafted spell file with non-collapsing SAL rules + can make soundfold() write one byte past the end of the + MAXWLEN result buffer. This is the same class of + out-of-bounds write as GHSA-q8mh-6qm3-25g4 (fixed in 9.2.0698 + for the SOFO branch), found while auditing the surrounding + code. +Solution: Bound the single-byte SAL result writes and the terminating + NUL to MAXWLEN - 1, matching the SOFO branch. + +The single-byte branch of spell_soundfold_sal() guarded its writes with +"reslen < MAXWLEN", allowing reslen to reach MAXWLEN (254). The trailing +"res[reslen] = NUL" then wrote at index 254 of the 254-byte stack buffer +res[MAXWLEN], an off-by-one out-of-bounds write. Input is case-folded to +about 253 characters, so a 253-character argument together with a SAL map +that does not collapse (collapse_result false) reaches the boundary. + +Related to previous issue +[GHSA-q8mh-6qm3-25g4](https://github.com/vim/vim/security/advisories/GHSA-q8mh-6qm3-25g4) +(9.2.0698) + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-m3hf-xcm3-xhm2 + +Co-Authored-By: Claude Opus 4.8 (1M context) +Signed-off-by: Hirohito Higashi +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/d22ff1c955ff87e8273210eae125aab0e85b6c30] +CVE: CVE-2026-59857 +Signed-off-by: Siddharth Doshi +--- + src/spell.c | 6 +++--- + src/testdir/test_spellfile.vim | 24 ++++++++++++++++++++++++ + 2 files changed, 27 insertions(+), 3 deletions(-) + +diff --git a/src/spell.c b/src/spell.c +index a7909ef46e..05d6f0159d 100644 +--- a/src/spell.c ++++ b/src/spell.c +@@ -3516,7 +3516,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res) + // no '<' rule used + i += k - 1; + z = 0; +- while (*s != NUL && s[1] != NUL && reslen < MAXWLEN) ++ while (*s != NUL && s[1] != NUL && reslen < MAXWLEN - 1) + { + if (reslen == 0 || res[reslen - 1] != *s) + res[reslen++] = *s; +@@ -3526,7 +3526,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res) + c = *s; + if (strstr((char *)pf, "^^") != NULL) + { +- if (c != NUL) ++ if (c != NUL && reslen < MAXWLEN - 1) + res[reslen++] = c; + STRMOVE(word, word + i + 1); + i = 0; +@@ -3545,7 +3545,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res) + + if (z0 == 0) + { +- if (k && !p0 && reslen < MAXWLEN && c != NUL ++ if (k && !p0 && reslen < MAXWLEN - 1 && c != NUL + && (!slang->sl_collapse || reslen == 0 + || res[reslen - 1] != c)) + // condense only double letters +diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim +index d04d024911..c8c7ac2642 100644 +--- a/src/testdir/test_spellfile.vim ++++ b/src/testdir/test_spellfile.vim +@@ -383,6 +383,30 @@ func Test_spellfile_format_error() + let &rtp = save_rtp + endfunc + ++" An over-length soundfold() argument must not overflow the MAXWLEN result ++" buffer in the single-byte branch of spell_soundfold_sal(). ++func Test_spellfile_soundfold_sal_overflow() ++ let save_enc = &encoding ++ set encoding=latin1 ++ " A SAL map that appends without collapsing, so the result is not shorter ++ " than the input. ++ call writefile(['SET ISO8859-1', 'SAL collapse_result false', ++ \ 'SAL a aaaa', 'SAL b bbbb'], 'Xsal.aff') ++ call writefile(['2', 'hello', 'world'], 'Xsal.dic') ++ mkspell! Xsal Xsal ++ set spl=Xsal.latin1.spl spell ++ ++ " 253 input characters hit the buffer boundary; the result must not exceed ++ " MAXWLEN - 1. ++ call assert_true(strlen(soundfold(repeat('a', 253))) <= 253) ++ ++ set nospell spl& spelllang& ++ call delete('Xsal.aff') ++ call delete('Xsal.dic') ++ call delete('Xsal.latin1.spl') ++ let &encoding = save_enc ++endfunc ++ + " Test for format errors in suggest file + func Test_sugfile_format_error() + let save_rtp = &rtp +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 770872df01..e659db50ed 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -44,6 +44,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-57452.patch \ file://CVE-2026-57455.patch \ file://CVE-2026-59856.patch \ + file://CVE-2026-59857.patch \ " PV .= ".1683" From patchwork Wed Jul 22 20:19:05 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93288 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D4913C44536 for ; Wed, 22 Jul 2026 20:22:33 +0000 (UTC) Received: from mail-pg1-f178.google.com (mail-pg1-f178.google.com [209.85.215.178]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.9359.1784751745463296844 for ; Wed, 22 Jul 2026 13:22:25 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=knAhJxZc; spf=pass (domain: mvista.com, ip: 209.85.215.178, mailfrom: sdoshi@mvista.com) Received: by mail-pg1-f178.google.com with SMTP id 41be03b00d2f7-c981c2c37cbso7795700a12.0 for ; Wed, 22 Jul 2026 13:22:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784751745; x=1785356545; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=WzapKopLlT2aB8UjLpGOpINDoKFiOP8N3+WGyjxqSBo=; b=knAhJxZcaqpdEEVMEPXQ6QHWF6N5t5UR4ZRuPiF/MomSf9jeXfv4+G4EXJk+2YFOTd NlnNQAaDu+sykht1DJfh+sxuJDHYkDV+0pikurOgsv99000+JH04/qbYlZVhcxGBdwxT GY3swuyZgzue5/ge6kgO8lzQr6kseGYk24xDo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784751745; x=1785356545; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=WzapKopLlT2aB8UjLpGOpINDoKFiOP8N3+WGyjxqSBo=; b=knwbAaxawCMlXc2Arn2/PCtOYv3CrCeeK4JBH7ofDhsN75+JTUqUIomvUN8divv3uL OFrx8kdhHZFdNZ+NpJj8nFnKuIoxNLpOJjNQuJ6q2rz4oj0fUJb5xGiE4j4QCjI6Pzas qdGPUsJPfkFVlxCWaYpVxDX1cdPcuZo9vnKo6RL0sYI/6BWuZNYei+EzhLwRZUmY6Coh TsdzRfSSELHrxQ3PY0w9AdLu6aARUqXG6OBKRJVuKKA2kT3VOYpPJj26QcoEcEV59jQt Jb/wL6uTxqisBnGnAgsvxBGyCjoozTofOxTns9MN3HVEcU88DucrCGTOqiFde1bysnwN 96aA== X-Gm-Message-State: AOJu0YzGjD1218k3JuI2RT7BIkpr6wS8jodzeTkedpGhqu5tojzdMRev shEfd9qNAjMLg1Zv7u7rVhioX6BCRecUu2YFE08yteWBey1jibHQyGcaUw9AA2vQqv3HPG2BXXS zeJ+EjOY= X-Gm-Gg: AR+sD10SA8De6k4tY6pu7m+NXQr9FvsgrqyB8qkzKFGPYYBDt7OZDWUq5ts0w2wHoXw ul1geCqttu998U7qGu8Eh/Z6z8bEoR4eqJGeX5NmL8H1ywlWIJqyY1GkhF3O/jIh/8FaRlXB1Sd Jn2mHs7xJU/AtqWGZN9G5NEPiyTT9WzLyG7dOoHAYKWWjrs3IeaqWU8hmY/iggVLzcVk8zsjSBY uzZdCecyKYACmFLVFMry/o3Ee++kfBb9S5S6pQEh5ulAUD11MlQYaRWzaRMvzhjQtLmUjOWGXRm jsNQbrqUkA2jWL7apnREPOkYDOxIN/mOn6IFyeWr2+ht+fdK/qwWdWCI+37UwiNGu7Es51lPN80 mh8l5kdcqjfcvXEpMK8+aRSX4ALJcfc/saeq5ElgqbkUn0iYuNk89AX8Dz5MQF99XK73i2LTY+Z oUe4aNzN508UT9 X-Received: by 2002:a05:6300:95:b0:3c3:b57b:6459 with SMTP id adf61e73a8af0-3c44afb5078mr41809637.7.1784751744608; Wed, 22 Jul 2026 13:22:24 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.199]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3147d47960dsm11699468eec.0.2026.07.22.13.22.22 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Jul 2026 13:22:24 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][scarthgap][PATCH 13/13] vim: Security Fix for CVE-2026-59858 Date: Thu, 23 Jul 2026 01:49:05 +0530 Message-Id: <20260722201905.491897-13-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260722201905.491897-1-sdoshi@mvista.com> References: <20260722201905.491897-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 22 Jul 2026 20:22:33 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241757 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-59858 [2] https://security-tracker.debian.org/tracker/CVE-2026-59858 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-59858.patch | 134 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 135 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-59858.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-59858.patch b/meta/recipes-support/vim/files/CVE-2026-59858.patch new file mode 100644 index 0000000000..0b754ec2d3 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-59858.patch @@ -0,0 +1,134 @@ +From 6b611b0d15603c52ebdad17172b0232b4f65704e Mon Sep 17 00:00:00 2001 +From: Hirohito Higashi +Date: Fri, 26 Jun 2026 15:41:24 +0900 +Subject: [PATCH] patch 9.2.0735: [security]: arbitrary Ex command execution + during C omni-completion + +Problem: [security]: With C omni-completion, a crafted tags file can execute + arbitrary Ex commands when completing a struct/union member + (cipher-creator) +Solution: Escape the type field before inserting it into the :vimgrep + pattern so it cannot close the pattern and start a new command + (Hirohito Higashi). + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-mf92-v4xw-j45x + +Co-Authored-By: Claude Opus 4.8 (1M context) " +Signed-off-by: Hirohito Higashi +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/6b611b0d15603c52ebdad17172b0232b4f65704e] +CVE: CVE-2026-59858 +Signed-off-by: Siddharth Doshi +--- + runtime/autoload/ccomplete.vim | 2 +- + src/testdir/Make_all.mak | 2 + + src/testdir/test_plugin_ccomplete.vim | 62 +++++++++++++++++++++++++++ + 3 files changed, 65 insertions(+), 1 deletion(-) + create mode 100644 src/testdir/test_plugin_ccomplete.vim + +diff --git a/runtime/autoload/ccomplete.vim b/runtime/autoload/ccomplete.vim +index cb4bb2c167..248d6f2e60 100644 +--- a/runtime/autoload/ccomplete.vim ++++ b/runtime/autoload/ccomplete.vim +@@ -593,7 +593,7 @@ def StructMembers( # {{{1 + return [] + endif + execute 'silent! keepjumps noautocmd ' +- .. n .. 'vimgrep ' .. '/\t' .. typename .. '\(\t\|$\)/j ' ++ .. n .. 'vimgrep ' .. '/\t' .. escape(typename, '/\') .. '\(\t\|$\)/j ' + .. fnames + + qflist = getqflist() +diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak +index 7d57b2e727..681e9b3b2a 100644 +--- a/src/testdir/Make_all.mak ++++ b/src/testdir/Make_all.mak +@@ -242,6 +242,7 @@ NEW_TESTS = \ + test_partial \ + test_paste \ + test_perl \ ++ test_plugin_ccomplete \ + test_plugin_comment \ + test_plugin_glvs \ + test_plugin_helptoc \ +@@ -516,6 +517,7 @@ NEW_TESTS_RES = \ + test_partial.res \ + test_paste.res \ + test_perl.res \ ++ test_plugin_ccomplete.res \ + test_plugin_comment.res \ + test_plugin_glvs.res \ + test_plugin_helptoc.res \ +diff --git a/src/testdir/test_plugin_ccomplete.vim b/src/testdir/test_plugin_ccomplete.vim +new file mode 100644 +index 0000000000..a635bd50bd +--- /dev/null ++++ b/src/testdir/test_plugin_ccomplete.vim +@@ -0,0 +1,62 @@ ++" Tests for the C omni-completion plugin (runtime/autoload/ccomplete.vim). ++ ++func s:WriteTags(lines) ++ " Mark unsorted so lookup is a linear scan regardless of entry order. ++ let tagsfile = tempname() ++ call writefile(["!_TAG_FILE_SORTED\t0\t/0/"] + a:lines, tagsfile) ++ return tagsfile ++endfunc ++ ++" A crafted typeref field is interpolated into the :vimgrep pattern in ++" StructMembers(). Without escaping, "/" closes the pattern and "|" starts a ++" new Ex command, so the field runs as an Ex command during completion. ++func Test_ccomplete_no_exec_via_typeref() ++ unlet! g:ccomplete_injected ++ let tagsfile = s:WriteTags([ ++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:x/|let g:ccomplete_injected = 1|\"", ++ \ ]) ++ ++ let save_tags = &tags ++ let &tags = tagsfile ++ ++ new ++ call ccomplete#Complete(1, '') ++ call ccomplete#Complete(0, 'myvar.x') ++ ++ call assert_false(exists('g:ccomplete_injected'), ++ \ 'typeref field was executed as an Ex command during omni-completion') ++ ++ bwipe! ++ let &tags = save_tags ++ unlet! g:ccomplete_injected ++endfunc ++ ++" A legitimate typeref must still drive struct-member completion: escaping the ++" field value must not break the normal path. ++func Test_ccomplete_typeref_completion_still_works() ++ let tagsfile = s:WriteTags([ ++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:struct:mystruct", ++ \ "alpha\tmain.c\t/^x$/;\"\tm\tstruct:mystruct", ++ \ "beta\tmain.c\t/^x$/;\"\tm\tstruct:mystruct", ++ \ ]) ++ ++ let save_tags = &tags ++ let &tags = tagsfile ++ ++ new ++ call ccomplete#Complete(1, '') ++ let items = ccomplete#Complete(0, 'myvar.') ++ ++ call assert_equal(type([]), type(items), ++ \ 'ccomplete#Complete did not return a list') ++ let names = map(copy(items), 'v:val.word') ++ call assert_true(index(names, 'alpha') >= 0, ++ \ 'struct member "alpha" missing from completion: ' . string(names)) ++ call assert_true(index(names, 'beta') >= 0, ++ \ 'struct member "beta" missing from completion: ' . string(names)) ++ ++ bwipe! ++ let &tags = save_tags ++endfunc ++ ++" vim: shiftwidth=2 sts=2 expandtab +-- +2.44.4 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index e659db50ed..16646dabff 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -45,6 +45,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \ file://CVE-2026-57455.patch \ file://CVE-2026-59856.patch \ file://CVE-2026-59857.patch \ + file://CVE-2026-59858.patch \ " PV .= ".1683"