From patchwork Sat Jul 25 14:32:26 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93492 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DCD18C53200 for ; Sat, 25 Jul 2026 14:32:44 +0000 (UTC) Received: from mail-pj1-f43.google.com (mail-pj1-f43.google.com [209.85.216.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.365.1784989961330559271 for ; Sat, 25 Jul 2026 07:32:41 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=elVpruMd; spf=pass (domain: mvista.com, ip: 209.85.216.43, mailfrom: sdoshi@mvista.com) Received: by mail-pj1-f43.google.com with SMTP id 98e67ed59e1d1-38e42560ebcso1013548a91.1 for ; Sat, 25 Jul 2026 07:32:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784989961; x=1785594761; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:from:to:cc:subject:date:message-id:reply-to :content-type; bh=+LtIBxL1/extq5pc/Yye6YGeESRKXyKCdnlJZvisBtc=; b=elVpruMd1w4Et88ci0yEjhPOjLaid83PQuDSgPa0stAgcdsQtJbVHK6CUkdq9FLoKQ P87xx0igb3dKrWMV7zGMVJvEuHmSRLQAoRGjq0AoIxUC896Yxaz5gvhwmswSxHizE1Wy a2267xTnNfg8+H3g6zKOnm1QccyZk1/vWsJ1k= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784989961; x=1785594761; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=+LtIBxL1/extq5pc/Yye6YGeESRKXyKCdnlJZvisBtc=; b=PAe0t8RmjHmxhpbxXtgVF+Ok+HOczoQK+4qRVoiQg6JrrSc1zUXY6dGLSXdyvwciL8 VJsb9wDaoLKwgvfI0bOqtNrVBxSBBUpGuJM4tDMWYnFu3MRHvFecYuC8pUkyYIhmX4qr yxO20fwps4+DPNc9XIkB4SCR/bVMne4anblEJCP8OVylnlOcYSgxNLFfCYxfImO3dqI+ M/kxcIdFihzEbinEns2xEACPbj9kLLCPHn18831E9NEajNIt14GyMUNOHa4UX637LLBn Q17U1L4C8v5yZIPO1ARUGynLZrk8hGFaKOCzdarD3ElQXi6rlRQWpidIvg2er9+mBHK5 rXNQ== X-Gm-Message-State: AOJu0YyaM6bknDmprLBaYqzYnNOCs+UOsxF7kPraW804GTaFQ59/yqYj wZklhxqbXRsShtex5L6nu5rltkVxD5Pr2CWoGpGJVRayIhusmGwKrqy2MbSp6E/h1NVGdU/CJq8 Q1whrcTg= X-Gm-Gg: AR+sD13YImAeXNGnn4tzb7AxoF78PVyJqbm98XU+plBMlemZrK5JSpuTm+agWLd7LWN 3wPldMwK9piBrrwM+RU4UqySbaeGCqoUKgFHN8G1G6H7hsdHFKO6JCOvd50bKrvC+xU9hqdJSSo djACohQZZ6SKEY+/qGNVr7GHjgKzYdUJgRYV0NsjOl1aNtLZHrbZ6k0mjZYDJ+8Gh1koBGlDPn0 XEG3VfcAkeY+Jx0DLAe6CQI0xyvMxX/2Dz/XcgZXWXRTSjOJAjcagBdeUXlt2H6MokbKgPPcfMe keXixgNN/X++Hx5FeaVaRwLhjAd9IAyEh7taqDbBfA7ISMYXdGmdux388/Z/LuFRAqJccJU6c8t fxuTrFrQmjiVoEKoZTduB4mqZ4FHWQ0X7kCzzZ1A+25QkCxWYdzmz/L5n98OvM+A5yXQT8kksAH ITbajT5329bFqF X-Received: by 2002:a17:90b:4d0f:b0:38e:9ef9:eb97 with SMTP id 98e67ed59e1d1-38f294ec03amr2443809a91.16.1784989960553; Sat, 25 Jul 2026 07:32:40 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.248]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13e585ae882sm1575845c88.6.2026.07.25.07.32.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 25 Jul 2026 07:32:40 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][wrynose][PATCH 1/6] vim: Security Fix for CVE-2026-42307 Date: Sat, 25 Jul 2026 20:02:26 +0530 Message-Id: <20260725143231.230059-1-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 25 Jul 2026 14:32:44 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241971 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-42307 [2] https://security-tracker.debian.org/tracker/CVE-2026-42307 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-42307.patch | 177 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 178 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-42307.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-42307.patch b/meta/recipes-support/vim/files/CVE-2026-42307.patch new file mode 100644 index 0000000000..037f6cba27 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-42307.patch @@ -0,0 +1,177 @@ +From 405e2fb6d54d5653523809e2853d99d1c000a5fc Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Tue, 21 Apr 2026 19:03:02 +0000 +Subject: [PATCH] patch 9.2.0383: [security]: runtime(netrw): shell-injection + via sftp: and file: URLs + +Problem: runtime(netrw): shell-injection via sftp: and file: URLs + (Joshua Rogers) +Solution: Escape temporary file names, harden filename suffix regex, + drop unused g:netrw_tmpfile_escape variable + +Supported by AI + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/405e2fb6d54d5653523809e2853d99d1c000a5fc] +CVE: CVE-2026-42307 +Signed-off-by: Siddharth Doshi +--- + runtime/doc/pi_netrw.txt | 4 --- + runtime/doc/tags | 1 - + .../pack/dist/opt/netrw/autoload/netrw.vim | 16 +++++----- + runtime/pack/dist/opt/netrw/doc/netrw.txt | 4 --- + src/testdir/test_plugin_netrw.vim | 30 +++++++++++++++++++ + src/version.c | 2 ++ + 6 files changed, 41 insertions(+), 16 deletions(-) + +diff --git a/runtime/doc/pi_netrw.txt b/runtime/doc/pi_netrw.txt +index a86cac36ba..2d98a8407b 100644 +--- a/runtime/doc/pi_netrw.txt ++++ b/runtime/doc/pi_netrw.txt +@@ -2854,10 +2854,6 @@ your browsing preferences. (see also: |netrw-settings|) + such as listing, file removal, etc. + default: ssh + +- *g:netrw_tmpfile_escape* =' &;' +- escape() is applied to all temporary files +- to escape these characters. +- + *g:netrw_timefmt* specify format string to vim's strftime(). + The default, "%c", is "the preferred date + and time representation for the current +diff --git a/runtime/doc/tags b/runtime/doc/tags +index 1e0720b21a..023996c0eb 100644 +--- a/runtime/doc/tags ++++ b/runtime/doc/tags +@@ -7966,7 +7966,6 @@ g:netrw_ssh_browse_reject pi_netrw.txt /*g:netrw_ssh_browse_reject* + g:netrw_ssh_cmd pi_netrw.txt /*g:netrw_ssh_cmd* + g:netrw_sshport pi_netrw.txt /*g:netrw_sshport* + g:netrw_timefmt pi_netrw.txt /*g:netrw_timefmt* +-g:netrw_tmpfile_escape pi_netrw.txt /*g:netrw_tmpfile_escape* + g:netrw_uid pi_netrw.txt /*g:netrw_uid* + g:netrw_use_noswf pi_netrw.txt /*g:netrw_use_noswf* + g:netrw_use_nt_rcp pi_netrw.txt /*g:netrw_use_nt_rcp* +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index 8e5fdb5397..78ce0cbc3c 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -398,7 +398,6 @@ else + call s:NetrwInit("g:netrw_glob_escape",'*[]?`{~$\') + endif + call s:NetrwInit("g:netrw_menu_escape",'.&? \') +-call s:NetrwInit("g:netrw_tmpfile_escape",' &;') + call s:NetrwInit("s:netrw_map_escape","<|\n\r\\\\"") + if has("gui_running") && (&enc == 'utf-8' || &enc == 'utf-16' || &enc == 'ucs-4') + let s:treedepthstring= "│ " +@@ -1819,14 +1818,14 @@ function netrw#NetRead(mode,...) + "......................................... + " NetRead: (sftp) NetRead Method #9 {{{3 + elseif b:netrw_method == 9 +- call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_sftp_cmd." ".netrw#os#Escape(g:netrw_machine.":".b:netrw_fname,1)." ".tmpfile) ++ call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_sftp_cmd." ".netrw#os#Escape(g:netrw_machine.":".b:netrw_fname,1)." ".netrw#os#Escape(tmpfile,1)) + let result = s:NetrwGetFile(readcmd, tmpfile, b:netrw_method) + let b:netrw_lastfile = choice + + "......................................... + " NetRead: (file) NetRead Method #10 {{{3 + elseif b:netrw_method == 10 && exists("g:netrw_file_cmd") +- call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_file_cmd." ".netrw#os#Escape(b:netrw_fname,1)." ".tmpfile) ++ call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_file_cmd." ".netrw#os#Escape(b:netrw_fname,1)." ".netrw#os#Escape(tmpfile,1)) + let result = s:NetrwGetFile(readcmd, tmpfile, b:netrw_method) + let b:netrw_lastfile = choice + +@@ -8959,14 +8958,17 @@ function s:GetTempfile(fname) + endif + + " use fname's suffix for the temporary file ++ " Restrict the suffix to word characters so shell metacharacters in a ++ " remote filename (e.g. sftp://host/foo.txt;id) cannot ride along into ++ " the tempfile name and out into a downstream shell command. + if a:fname != "" +- if a:fname =~ '\.[^./]\+$' ++ if a:fname =~ '\.\w\+$' + if a:fname =~ '\.tar\.gz$' || a:fname =~ '\.tar\.bz2$' || a:fname =~ '\.tar\.xz$' +- let suffix = ".tar".substitute(a:fname,'^.*\(\.[^./]\+\)$','\1','e') ++ let suffix = ".tar".substitute(a:fname,'^.*\(\.\w\+\)$','\1','e') + elseif a:fname =~ '.txz$' +- let suffix = ".txz".substitute(a:fname,'^.*\(\.[^./]\+\)$','\1','e') ++ let suffix = ".txz".substitute(a:fname,'^.*\(\.\w\+\)$','\1','e') + else +- let suffix = substitute(a:fname,'^.*\(\.[^./]\+\)$','\1','e') ++ let suffix = substitute(a:fname,'^.*\(\.\w\+\)$','\1','e') + endif + let tmpfile= substitute(tmpfile,'\.tmp$','','e') + let tmpfile .= suffix +diff --git a/runtime/pack/dist/opt/netrw/doc/netrw.txt b/runtime/pack/dist/opt/netrw/doc/netrw.txt +index 01a5bda597..144bab5fb3 100644 +--- a/runtime/pack/dist/opt/netrw/doc/netrw.txt ++++ b/runtime/pack/dist/opt/netrw/doc/netrw.txt +@@ -2854,10 +2854,6 @@ your browsing preferences. (see also: |netrw-settings|) + such as listing, file removal, etc. + default: ssh + +- *g:netrw_tmpfile_escape* =' &;' +- escape() is applied to all temporary files +- to escape these characters. +- + *g:netrw_timefmt* specify format string to vim's strftime(). + The default, "%c", is "the preferred date + and time representation for the current +diff --git a/src/testdir/test_plugin_netrw.vim b/src/testdir/test_plugin_netrw.vim +index b234670928..6be32911ce 100644 +--- a/src/testdir/test_plugin_netrw.vim ++++ b/src/testdir/test_plugin_netrw.vim +@@ -604,6 +604,36 @@ func Test_netrw_FileUrlEdit_pipe_injection() + call assert_false(filereadable(fname), 'Command injection via pipe in file URL') + endfunc + ++" The remote filename after '.' was allowed to contain shell metacharacters ++" and rode unescaped into the tempfile name passed to sftp/file_cmd, giving a ++" shell injection on :e sftp://host/foo.txt;. ++func Test_netrw_tempfile_suffix_injection() ++ CheckUnix ++ CheckExecutable id ++ let save_sftp = g:netrw_sftp_cmd ++ let save_file = exists('g:netrw_file_cmd') ? g:netrw_file_cmd : v:null ++ let g:netrw_sftp_cmd = 'true' ++ let g:netrw_file_cmd = 'true' ++ let fname = 'Xrce_marker' ++ try ++ call delete(fname) ++ sil! call netrw#NetRead(2, 'sftp://localhost/foo.txt;id>'..fname) ++ call assert_false(filereadable(fname), 'Command injection via sftp:// tempfile suffix') ++ ++ call delete(fname) ++ sil! call netrw#NetRead(2, 'file://localhost/foo.txt;id>'..fname) ++ call assert_false(filereadable(fname), 'Command injection via file:// tempfile suffix') ++ finally ++ call delete(fname) ++ let g:netrw_sftp_cmd = save_sftp ++ if save_file is v:null ++ unlet! g:netrw_file_cmd ++ else ++ let g:netrw_file_cmd = save_file ++ endif ++ endtry ++endfunc ++ + func Test_netrw_RFC2396() + let fname = 'a%20b' + call assert_equal('a b', netrw#RFC2396(fname)) +diff --git a/src/version.c b/src/version.c +index 560233fafc..4508ae3f18 100644 +--- a/src/version.c ++++ b/src/version.c +@@ -734,6 +734,8 @@ static char *(features[]) = + + static int included_patches[] = + { /* Add new patch number below this line */ ++/**/ ++ 383, + /**/ + 340, + /**/ +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 0642393db3..2a9846dfbb 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -33,6 +33,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-59856.patch \ file://CVE-2026-59857.patch \ file://CVE-2026-59858.patch \ + file://CVE-2026-42307.patch \ " PV .= ".0340" From patchwork Sat Jul 25 14:32:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93491 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7F623C531D0 for ; Sat, 25 Jul 2026 14:32:44 +0000 (UTC) Received: from mail-pj1-f52.google.com (mail-pj1-f52.google.com [209.85.216.52]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.366.1784989964108207545 for ; Sat, 25 Jul 2026 07:32:44 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=GmrMzXWC; spf=pass (domain: mvista.com, ip: 209.85.216.52, mailfrom: sdoshi@mvista.com) Received: by mail-pj1-f52.google.com with SMTP id 98e67ed59e1d1-38d489b6b71so1289677a91.0 for ; Sat, 25 Jul 2026 07:32:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784989963; x=1785594763; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=dbpCPZ1inzN5h6L0jtSUls8KZloO8KjZy9zpfh7GFLc=; b=GmrMzXWCLBVfm51sRxtzTtfVLgCk5qNNdr9qVemkB24rHe7vdVaLphFiB2a/HKpbAy WpUVxkXDMK2/UbUDtNcgK4Bwzoui2+x8YfWK6fIDThPM+bmL15bAGXDtvumddJix8LQj CEDlNtsEpX4rzRIvqp4XL/cn/JIUh/5gFIENU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784989963; x=1785594763; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=dbpCPZ1inzN5h6L0jtSUls8KZloO8KjZy9zpfh7GFLc=; b=qmXe+eQnyZEjQkk0IaStOU1hn8jqB9NONaxtDaNcZp9h7JBMYe2hzacJv6DuIndwYM sU/68n1EJLQAx383JFSDs2rylOllUqxjXlQUf7t6VMd3sr1IEUZRBRW+YnnTDEE2pOw0 umhqh2kCNBcRugDRVArUfonc6arEjx6Aggaq+tSHSBOB7WDuNNk1rnwNsk3AWtpa61Ld HnQWuOZohKtPCuLiIsvVX6mmS4ac6gfxvqhHUK5e0cwic+wEjQmpQsXGzVaKL9cClxoG j07RziccepUnyxVhnw7sYvWs6ZPaglrAc1Cawc3GuQK9sa1tDjrDyfVHtXSt3lP3SmfF IPCA== X-Gm-Message-State: AOJu0Yx62Vjuqu9ZUyYGWXX6Y83T3xokyQUaelXOCAl7GdfJ5ClqdQcI nXMKjIfA7jRceMpqYatSGyIqkmw2YP7T6kHx9pSnHQ0MTLXnms3fwboQIoXwYX2no1siz2ramPl 2yBytuT8= X-Gm-Gg: AR+sD11Vp3q2qtDPODqFRo8koQFPMGM5mh13+1fwBXTXrT9nr9rkThagGxg7fnyUj7A bsCR8gdo/0x0bWOHVPmLkqrYd6dURKX4z4iEyDJ0/dp3ZVK2r9M9alhC+uW4US9CCxfHn5yKqeG sRiVZlFgJ/pLxgqCql/3IPDYWdhwig+hi2jZgsJcJJzakAN3dGEYu0gHxygoxJgn9Ks9tPmba+W W5y6LL+UJJHDnBPEmNGEKJ0bfLR1qY87VowrQZdoaefqQUxh0lFlTe2rq80G03Ml0KRCz/78+5u T4agE4wh+rBWyPrk2WhdFEdTZQK2lNZlCEPHf0WvkoiW+nIHw6siyCuqQztngFbYxerhW0MY8uv DWh4vlDFEmySgREPj0/eFgnrFgn5Oab+Ik0P+JgdU7bp/6K/aBUDhdx81YpJhHR8xRQuaNEXOHA OvnR91mCbAe1Py X-Received: by 2002:a17:90b:4a08:b0:37e:b6a:6cdf with SMTP id 98e67ed59e1d1-38f2963d61amr2567471a91.20.1784989963302; Sat, 25 Jul 2026 07:32:43 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.248]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13e585ae882sm1575845c88.6.2026.07.25.07.32.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 25 Jul 2026 07:32:42 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][wrynose][PATCH 2/6] vim: Security Fix for CVE-2026-43961 Date: Sat, 25 Jul 2026 20:02:27 +0530 Message-Id: <20260725143231.230059-2-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260725143231.230059-1-sdoshi@mvista.com> References: <20260725143231.230059-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 25 Jul 2026 14:32:44 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241972 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://github.com/vim/vim/commit/8af0f098c3a42a28661d0295364e [2] https://security-tracker.debian.org/tracker/CVE-2026-43961 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-43961.patch | 104 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 105 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-43961.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-43961.patch b/meta/recipes-support/vim/files/CVE-2026-43961.patch new file mode 100644 index 0000000000..de4ece7bda --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-43961.patch @@ -0,0 +1,104 @@ +From 8af0f098c3a42a28661d0295364e6e0fd7dbc92c Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Thu, 14 May 2026 16:43:15 +0000 +Subject: [PATCH] patch 9.2.0480: [security]: runtime(netrw): code injection + via mf command + +Problem: [security]: runtime(netrw): code injection via mf command + (Christopher Lusk, Zdenek Dohnal) +Solution: Do not use string concatenation inside the filter() commands + (Zdenek Dohnal) + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-66hr-7p6x-x5j3 + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/8af0f098c3a42a28661d0295364e] +CVE: CVE-2026-43961 +Signed-off-by: Siddharth Doshi +--- + runtime/pack/dist/opt/netrw/autoload/netrw.vim | 7 +++---- + src/testdir/test_plugin_netrw.vim | 15 +++++++++++++++ + src/version.c | 2 ++ + 3 files changed, 20 insertions(+), 4 deletions(-) + +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index 78ce0cbc3c..3a460e675b 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -5175,7 +5175,7 @@ function s:NetrwMarkFile(islocal,fname) + + else + " remove filename from buffer's markfilelist +- call filter(s:netrwmarkfilelist_{curbufnr},'v:val != a:fname') ++ call filter(s:netrwmarkfilelist_{curbufnr}, {_, v -> v !=# a:fname}) + if s:netrwmarkfilelist_{curbufnr} == [] + " local markfilelist is empty; remove it entirely + call s:NetrwUnmarkList(curbufnr,curdir) +@@ -5196,7 +5196,6 @@ function s:NetrwMarkFile(islocal,fname) + + else + " initialize new markfilelist +- + let s:netrwmarkfilelist_{curbufnr}= [] + call add(s:netrwmarkfilelist_{curbufnr},substitute(a:fname,'[|@]$','','')) + +@@ -5216,7 +5215,7 @@ function s:NetrwMarkFile(islocal,fname) + call add(s:netrwmarkfilelist,netrw#fs#ComposePath(b:netrw_curdir,a:fname)) + else + " remove new filename from global markfilelist +- call filter(s:netrwmarkfilelist,'v:val != "'.dname.'"') ++ call filter(s:netrwmarkfilelist, {_, v -> v !=# dname}) + if s:netrwmarkfilelist == [] + unlet s:netrwmarkfilelist + endif +@@ -7235,7 +7234,7 @@ function s:NetrwTreeDisplay(dir,depth) + " hide given patterns + let listhide= split(g:netrw_list_hide,',') + for pat in listhide +- call filter(w:netrw_treedict[dir],'v:val !~ "'.escape(pat,'\\').'"') ++ call filter(w:netrw_treedict[dir], {_, v -> v !~# pat}) + endfor + + elseif g:netrw_hide == 2 +diff --git a/src/testdir/test_plugin_netrw.vim b/src/testdir/test_plugin_netrw.vim +index 6be32911ce..7b34b52562 100644 +--- a/src/testdir/test_plugin_netrw.vim ++++ b/src/testdir/test_plugin_netrw.vim +@@ -629,4 +629,19 @@ func Test_netrw_RFC2396() + endtry + endfunc + ++func Test_netrw_mf_command_injection() ++ CheckUnix ++ CheckExecutable touch ++ let path = tempname() ++ let fname = 'x" . execute("silent! !touch poc") . "' ++ call mkdir(path, 'R') ++ exe "cd " path ++ call writefile([], fname) ++ Explore . ++ call search('^x') ++ :norm mf ++ :norm mf ++ call assert_false(filereadable('poc'), 'Command injection via mf command') ++endfunc ++ + " vim:ts=8 sts=2 sw=2 et +diff --git a/src/version.c b/src/version.c +index 4508ae3f18..64008e0f37 100644 +--- a/src/version.c ++++ b/src/version.c +@@ -734,6 +734,8 @@ static char *(features[]) = + + static int included_patches[] = + { /* Add new patch number below this line */ ++/**/ ++ 480, + /**/ + 383, + /**/ +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 2a9846dfbb..3888c725e0 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -34,6 +34,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-59857.patch \ file://CVE-2026-59858.patch \ file://CVE-2026-42307.patch \ + file://CVE-2026-43961.patch \ " PV .= ".0340" From patchwork Sat Jul 25 14:32:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93494 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C4990C531C9 for ; Sat, 25 Jul 2026 14:32:54 +0000 (UTC) Received: from mail-pj1-f45.google.com (mail-pj1-f45.google.com [209.85.216.45]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.367.1784989967055198730 for ; Sat, 25 Jul 2026 07:32:47 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=j9L4R28w; spf=pass (domain: mvista.com, ip: 209.85.216.45, mailfrom: sdoshi@mvista.com) Received: by mail-pj1-f45.google.com with SMTP id 98e67ed59e1d1-381216921aaso1299895a91.1 for ; Sat, 25 Jul 2026 07:32:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784989966; x=1785594766; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hqx74PRTFDU8HFE5HxRn9VMp/GT5GmJFc0oZxeQ719Y=; b=j9L4R28wEIMi28CSluRCoHcBzD23jHEnKX8Gcc7ODbxZGNl0XcpnJaz/66vSvyK5K/ uCS5q/uNBPQnMcFdqVmdzSqi0V+2Yrco0EUwYj2vWk8HrEllm/P10WjnDE7J2WhXmPhx K2WrNVE/PqtGScVqRn5kT+GO2cXdH8Bry2+yI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784989966; x=1785594766; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=hqx74PRTFDU8HFE5HxRn9VMp/GT5GmJFc0oZxeQ719Y=; b=M9uQhIVj9AEV6wGFeDls4Ui/4rr61aCRa3tPiya2PcWhIl1BYnl0JPFJ9E+kppl2iy wadBYtlDjSRzp4yrgg0Vu0y0DwsfIGjiQBX/vEuYPUQwrB/QRSxDsY3oE+G3Nl6zixh3 UnEZeow65rXU/+vSr/CMCGl2JrpTAqwljHkkxNA10rvke6l/Yad6O34rxX6uCOGnoR/r U+lPg0k0JwLcOhNBRB1CFBu9LtRHN0aUrKrpTxKktIcQDu/wQkNHcqdyOIcFaH5fiLKc Cwx1yGpv+0okeFKeP9lvh2GUte3w2Kla7LWbqYP9SOKaKo4WcjpsgvJ6a86s/FrJgsEH w0BQ== X-Gm-Message-State: AOJu0YzYq6XJPM31Mgs7G3iISqV5P86axcZ4AXpfw8q8rNfPsQIdSfEH oNTnI43XmiVH212sbG/p6/R8g9ADp+r28VK+5mx85rqniNnzKZ33Lokvu0sBQakZfcBCZdTArZO FMaAyUpI= X-Gm-Gg: AR+sD13NqxZbw9sh6CbYuRjoOtF1kyzhpCo+x3scSXvXcp2IYeUNJIguTRw9cdDMdy4 mk8uuFFMLRL7IEl2uoUVV0Z4mSrSlgOJLWZUUbIw0To0dBhQUwR6xZGn4KB7X/rcYZuuCFp2WU3 MjVZBAtoPMASUQdNtfh2Wal9aeXsCrHufTtbgYZWQoe3ZTs9Bb1VQdj3TpFvyeN/ZU7YNYJRXcy vS1MAmKgtkktvvLc6PDlCwtuOI+jZnUH/SrWxnFAT8uBmvO5APEC4jQ6fTBgAANTxUPknUVtNzM hlBXQfTk9EziGq+4UJKYfslBjE25KIwnSdfRcfsvSp9NqmsPSPm+TmtVGElS6w9pD9xc7OoAZ4T mSOoNCzObL+15F7kgz66gTnhoztPs1n3xtwRMor6YY19rt0FHQcLIzmVP6CpGutgStd/8cOYTG4 XuYgqM705jTSPk X-Received: by 2002:a17:90b:184e:b0:38d:ecfe:41aa with SMTP id 98e67ed59e1d1-38f2978138amr2060436a91.43.1784989966413; Sat, 25 Jul 2026 07:32:46 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.248]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13e585ae882sm1575845c88.6.2026.07.25.07.32.43 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 25 Jul 2026 07:32:46 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][wrynose][PATCH 3/6] vim: Security Fix for CVE-2026-47162 Date: Sat, 25 Jul 2026 20:02:28 +0530 Message-Id: <20260725143231.230059-3-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260725143231.230059-1-sdoshi@mvista.com> References: <20260725143231.230059-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 25 Jul 2026 14:32:54 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241973 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-47162 [2] https://security-tracker.debian.org/tracker/CVE-2026-47162 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-47162.patch | 83 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 84 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-47162.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-47162.patch b/meta/recipes-support/vim/files/CVE-2026-47162.patch new file mode 100644 index 0000000000..69714493d4 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-47162.patch @@ -0,0 +1,83 @@ +From f08ab2f4d7d2947c8dd6c179ae08ee6146a2694b Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Sun, 17 May 2026 18:53:48 +0000 +Subject: [PATCH] patch 9.2.0495: [security]: runtime(netrw): code injection + via NetrwBookHistSave() + +Problem: [security]: runtime(netrw): code injection via + NetrwBookHistSave() +Solution: Properly quote the directory name using string() function + (Srinivas Piskala Ganesh Babu) + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-crm5-rh6j-2c7c + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/f08ab2f4d7d2947c8dd6c179ae08ee6146a2694b] +CVE: CVE-2026-47162 +Signed-off-by: Siddharth Doshi +--- + .../pack/dist/opt/netrw/autoload/netrw.vim | 2 +- + src/testdir/test_plugin_netrw.vim | 20 +++++++++++++++++++ + src/version.c | 2 ++ + 3 files changed, 23 insertions(+), 1 deletion(-) + +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index 3a460e675b..a04120d5f6 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -2957,7 +2957,7 @@ function s:NetrwBookHistSave() + while ( first || cnt != g:netrw_dirhistcnt ) + let lastline= lastline + 1 + if exists("g:netrw_dirhist_{cnt}") +- call setline(lastline,'let g:netrw_dirhist_'.cnt."='".g:netrw_dirhist_{cnt}."'") ++ call setline(lastline,'let g:netrw_dirhist_'.cnt.'='.string(g:netrw_dirhist_{cnt})) + endif + let first = 0 + let cnt = ( cnt - 1 ) % g:netrw_dirhistmax +diff --git a/src/testdir/test_plugin_netrw.vim b/src/testdir/test_plugin_netrw.vim +index 7b34b52562..cfce82f68a 100644 +--- a/src/testdir/test_plugin_netrw.vim ++++ b/src/testdir/test_plugin_netrw.vim +@@ -654,4 +654,24 @@ func Test_netrw_mf_command_injection() + call assert_false(filereadable('poc'), 'Command injection via mf command') + endfunc + ++func Test_netrw_injection() ++ let g:netrw_home = getcwd() ++ let savefile = g:netrw_home . '/.netrwhist' ++ let g:netrw_dirhistmax = 10 ++ let g:netrw_dirhistcnt = 1 ++ let g:netrw_dirhist_1 = "x'|let g:injected = 1|let y='z" ++ call delete(savefile) ++ try ++ call netrw#Call('NetrwBookHistSave') ++ call assert_true(filereadable(savefile), savefile . ' must be written') ++ unlet g:netrw_dirhist_1 ++ execute 'source ' . fnameescape(savefile) ++ call assert_false(exists("g:injected"), 'injected statement must not execute') ++ call assert_equal("x'|let g:injected = 1|let y='z", g:netrw_dirhist_1, 'dirname must round-trip') ++ finally ++ call delete(savefile) ++ unlet! g:netrw_home g:netrw_dirhistmax g:netrw_dirhistcnt g:netrw_dirhist_1 g:injected ++ endtry ++endfunc ++ + " vim:ts=8 sts=2 sw=2 et +diff --git a/src/version.c b/src/version.c +index 64008e0f37..cf62805e44 100644 +--- a/src/version.c ++++ b/src/version.c +@@ -734,6 +734,8 @@ static char *(features[]) = + + static int included_patches[] = + { /* Add new patch number below this line */ ++/**/ ++ 495, + /**/ + 480, + /**/ +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 3888c725e0..f70363c4ef 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -35,6 +35,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-59858.patch \ file://CVE-2026-42307.patch \ file://CVE-2026-43961.patch \ + file://CVE-2026-47162.patch \ " PV .= ".0340" From patchwork Sat Jul 25 14:32:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93493 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BDCC8C531D0 for ; Sat, 25 Jul 2026 14:32:54 +0000 (UTC) Received: from mail-pj1-f41.google.com (mail-pj1-f41.google.com [209.85.216.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.368.1784989969494806605 for ; Sat, 25 Jul 2026 07:32:49 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=Vv8koTNY; spf=pass (domain: mvista.com, ip: 209.85.216.41, mailfrom: sdoshi@mvista.com) Received: by mail-pj1-f41.google.com with SMTP id 98e67ed59e1d1-38e347638adso1181290a91.0 for ; Sat, 25 Jul 2026 07:32:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784989969; x=1785594769; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=0KPFGbWL4fN/AF2FWOPPqj3kAKd2VGKpnK0CKbs4BhU=; b=Vv8koTNYRCro4tUM98aSuyEyo+PVfsfj9r6P54TZAgat3lrIOKv+1QE46TURujbqcq eoyoH/IKlXfGr9CzWatJ5ISYfrFv3oDjCIeQqZmsjMlEHQSjgoMFEra+6HDhRmovRgfW hmVTDSbjlSo4NhBxXapM4E8RL9HQKbo7YYEW4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784989969; x=1785594769; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=0KPFGbWL4fN/AF2FWOPPqj3kAKd2VGKpnK0CKbs4BhU=; b=DTF57AkkqGkBAWdMmAOqglJCs82//E4DQBbohFsn57cUVBJpKUmmqtHHWPu5XqWqIv RJti7OP41rmKq2OkFNDuDZ8TXVxfFvApfym9hNjPZGNnUSYNoKrEOhRIqyFLMDPuaNmG aJ4sHp1MtJLBKzXwolniv4uzGUrTOkKmc7cgaLlIncgtsjaY24PL1m6c9ft395n1Aku7 vbZsXGo5D52Y+iA8httIoDfK0MzZrbuR8lvizLCtJZgxNwfI+FnmYIeuHqkuzFwLulCS eKQwI8l9oYNe0kB2gemUm5ThODY5NzOKz0eLG9ooRb63e6xkt/VKpe8evO96WvGC9l/W HhyQ== X-Gm-Message-State: AOJu0YyofvIqxXzRCgAd3WNHJMKKgh4NVMNisC0g4lLbONTkf1BbVAon mOPLgV616RIc37Bnf4zBMqu2xdKBzCPsYvZ6tAvXoIWF97TsYt1Nv2SGgod7AepHc13P7zwK1Kc W6P0Vqg0= X-Gm-Gg: AR+sD10TAsiZP1FS0QrBfKw7tbfyuhQv9iyRKqsB8uVD5nZu172kZuue3HEJluUFcNM V/Tj1i33SgosCjBkpEz5NOS8g2BCUQXFP5e3uurtjHPi+t9rybvmex1Xy29glD+DHNU4CoRViTV RvotoAVxpvHHCQk6Wcem75TfxX8s1FYXMmPgKkf+eBdxJ8ufAy2eb19s0aCR9rsHRPiJaXuRmCD CG84xD2hkbSd1G1m29uh7IEIX1VzT+8cjrzFGfC1O54nTboQQLA9VPJ2lMNAFaPfwYsnMXho+QG oowBxN69HaRShBLEs42EzWFJG2zN8JvHzBmRbxLwO9QNfy75KId194jcCF/NVsFxmVZuSmiFivh 2HsUW8G5oGW9p57Y1mWrnHXeqIUTmnH1VYw+VMW7fr2I7c3e+9FqNBnsEmqLKu52EiIuVRm6uGH CE4BkJJUhyme4Q X-Received: by 2002:a17:90a:d00f:b0:38e:9045:bac0 with SMTP id 98e67ed59e1d1-38f293cf348mr2371107a91.5.1784989968809; Sat, 25 Jul 2026 07:32:48 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.248]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13e585ae882sm1575845c88.6.2026.07.25.07.32.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 25 Jul 2026 07:32:48 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][wrynose][PATCH 4/6] vim: Security Fix for CVE-2026-47167 Date: Sat, 25 Jul 2026 20:02:29 +0530 Message-Id: <20260725143231.230059-4-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260725143231.230059-1-sdoshi@mvista.com> References: <20260725143231.230059-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 25 Jul 2026 14:32:54 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241974 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-47167 [2] https://security-tracker.debian.org/tracker/CVE-2026-47167 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-47167.patch | 102 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 103 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-47167.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-47167.patch b/meta/recipes-support/vim/files/CVE-2026-47167.patch new file mode 100644 index 0000000000..f9a989cf3a --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-47167.patch @@ -0,0 +1,102 @@ +From 5eb4bd1c12801f9ffb451f22b4d459ff2b7ff962 Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Sun, 17 May 2026 19:39:24 +0000 +Subject: [PATCH 4/6] patch 9.2.0496: [security]: Code Injection in cucumber + filetype plugin + +Problem: [security]: Code Injection in cucumber filetype plugin + (Christopher Lusk) +Solution: Use rubys Regexp.new() with the untrusted pattern + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-4473-94jm-w5x9 + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/a65a52d684bc58535ad28a4ae824d22e76399934] +CVE: CVE-2026-47167 +Signed-off-by: Siddharth Doshi +--- + runtime/ftplugin/cucumber.vim | 5 ++++- + src/testdir/test_filetype.vim | 30 ++++++++++++++++++++++++++++++ + src/version.c | 2 ++ + 3 files changed, 36 insertions(+), 1 deletion(-) + +diff --git a/runtime/ftplugin/cucumber.vim b/runtime/ftplugin/cucumber.vim +index f4848d1c60..9723898d15 100644 +--- a/runtime/ftplugin/cucumber.vim ++++ b/runtime/ftplugin/cucumber.vim +@@ -2,6 +2,8 @@ + " Language: Cucumber + " Maintainer: Tim Pope + " Last Change: 2016 Aug 29 ++" 2026 May 26 by Vim Project: prevent Code Injection ++" https://github.com/vim/vim/security/advisories/GHSA-4473-94jm-w5x9 + + " Only do this when not done yet for this buffer + if (exists("b:did_ftplugin")) +@@ -96,7 +98,8 @@ function! s:stepmatch(receiver,target) + catch + endtry + if has("ruby") && pattern !~ '\\\@ s:steps -> s:stepmatch on every discovered step, ++ " including the malicious one. Suppress preview and error messages. ++ silent! normal [d ++ call assert_false(filereadable(marker), 'Ruby injection executed') ++ bwipe! ++ filetype plugin off ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +diff --git a/src/version.c b/src/version.c +index cf62805e44..03a520b146 100644 +--- a/src/version.c ++++ b/src/version.c +@@ -734,6 +734,8 @@ static char *(features[]) = + + static int included_patches[] = + { /* Add new patch number below this line */ ++/**/ ++ 496, + /**/ + 495, + /**/ +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index f70363c4ef..50ef18878e 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -36,6 +36,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-42307.patch \ file://CVE-2026-43961.patch \ file://CVE-2026-47162.patch \ + file://CVE-2026-47167.patch \ " PV .= ".0340" From patchwork Sat Jul 25 14:32:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93495 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CD993C53219 for ; Sat, 25 Jul 2026 14:32:54 +0000 (UTC) Received: from mail-pg1-f173.google.com (mail-pg1-f173.google.com [209.85.215.173]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.371.1784989971950235731 for ; Sat, 25 Jul 2026 07:32:52 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=MSEHj6WG; spf=pass (domain: mvista.com, ip: 209.85.215.173, mailfrom: sdoshi@mvista.com) Received: by mail-pg1-f173.google.com with SMTP id 41be03b00d2f7-ca7bea5e5b3so1014826a12.1 for ; Sat, 25 Jul 2026 07:32:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784989971; x=1785594771; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=3jqf2VKfqxSyuyJJtp8kVMproI4H/rSpr+irXBepIXU=; b=MSEHj6WGoRREqRzh6WloeNGfYH1v/e1SGJmNqDD05RgFCGswTvYSFSA8ANPX/hBD5e fd65dvhK1tyVMC01p4vYI0iNIEROIG+jkuxqrgZgIl0wNX1+yDMsl0B6sERUbzXgl2Dp Uz9AX7gYEUfpBmwzRIULEHE6fKvRg+nawRTbA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784989971; x=1785594771; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=3jqf2VKfqxSyuyJJtp8kVMproI4H/rSpr+irXBepIXU=; b=MEL1FGe0Xj6fSQ9tm38WPAhcsDY3se6iEm05iysEe+/IaA5w/XKpAnvFptP2nRoe2D HFcFJ5iSHUyrrvYyXyP0K5Ma7kFVJhtvuJhfpHQUUhXAMZHYhoVEdjqRwhpH9peTWxFB e7bucjd/HiwwsDYOgVmXSDfW2lcSLArHczxLmT5QUuqfkBqhBUoQwEnV77v2pa7xq4nP uOvFNQPwN95RJgV0m9zI16sDmVnPEXhtmWWndXfuZ6FtchK5yyQCIIiDOh0PJ/y9dYJw Qz79RH+xBjoaRwypPZZzpHB3YQHOXIMZMjVGjG8E64z2DPXzc85FtWnqZYdlGIScLYak zhgw== X-Gm-Message-State: AOJu0Yygt5s2GshGs742tc1PUkcGV/3u9v/JvLm9JHHfaEfdDQ2bVoen sYr3yPgqJ9VX5gheDD73GJc8CJZu5/okiaPRvkopmMUDgrw0Y6Fo5p+Mqno+s5sM5CTqmbGKzc5 6aktD8n4= X-Gm-Gg: AR+sD11dHiL4Qxs2urJ5bHhqKisLcE9tLQ/3ARauX11O9t+JeiUV4zJKAXPH1clqoqn JZOLh9A+b1kShQBm2xX3lWpfQPEZ8XKp2i6A+5661fpYr7upYyRFleUIOyG/Z+NGnGs8x7Jkc+d 4btl/Ek5THOUiQ9Ffn7pNR6H6sLFjaoTgV6ahAUaa2bAveThbdtn+8TOwdOb3KZLoonIjA2grwd U0zVWJbmW+56+UXnOqnsQWa8LOeYtH4YISlXQ35jDnHvUgNzck4tbXGTjuYhRQD2XEHAYurxHQx xF/oJqeSnNStnboc1SIW8l+zyq/+GOsdx2LMLKr5xSjjSqdAT9SvE/zkJTQiaSyym/f5/BucUhP oWBMoSQCqRfD6Jmb0SjkZRfi6QzW1SnQGsBJPjYBbXA1ltxY2xCUzyUj15GDv947I9wF7be0Ftg IN1UTqSiAjVS2Z X-Received: by 2002:a05:6300:95:b0:3c0:9c19:65b3 with SMTP id adf61e73a8af0-3c67e19957bmr2309401637.75.1784989971301; Sat, 25 Jul 2026 07:32:51 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.248]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13e585ae882sm1575845c88.6.2026.07.25.07.32.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 25 Jul 2026 07:32:50 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][wrynose][PATCH 5/6] vim: Security Fix for CVE-2026-55892 Date: Sat, 25 Jul 2026 20:02:30 +0530 Message-Id: <20260725143231.230059-5-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260725143231.230059-1-sdoshi@mvista.com> References: <20260725143231.230059-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 25 Jul 2026 14:32:54 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241975 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-55892 [2] https://security-tracker.debian.org/tracker/CVE-2026-55892 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-55892.patch | 95 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 96 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-55892.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-55892.patch b/meta/recipes-support/vim/files/CVE-2026-55892.patch new file mode 100644 index 0000000000..fc43095362 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-55892.patch @@ -0,0 +1,95 @@ +From 8325b193bba5f01e7a7d8241fc8633d93dff996b Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Tue, 16 Jun 2026 20:32:21 +0000 +Subject: [PATCH] patch 9.2.0662: [security] Stack out-of-bounds write in + dump_prefixes() + +Problem: [security]: a crafted spell file with a self-referential + BY_INDEX node in the prefix tree can drive dump_prefixes() + past the end of its MAXWLEN-sized depth arrays on :spelldump + (cipher-creator) +Solution: only descend while depth < MAXWLEN - 1, as the sibling trie + walkers already do (Yasuhiro Matsumoto) + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-qm9w-fmpj-879h + +Supported by AI + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/8325b193bba5f01e7a7d8241fc8633d93dff996b] +CVE: CVE-2026-55892 +Signed-off-by: Siddharth Doshi +--- + src/spell.c | 2 +- + src/testdir/test_spell.vim | 27 +++++++++++++++++++++++++++ + src/version.c | 2 ++ + 3 files changed, 30 insertions(+), 1 deletion(-) + +diff --git a/src/spell.c b/src/spell.c +index 01eb57e3a9..72d1f0b521 100644 +--- a/src/spell.c ++++ b/src/spell.c +@@ -4325,7 +4325,7 @@ dump_prefixes( + } + } + } +- else ++ else if (depth < MAXWLEN - 1) + { + // Normal char, go one level deeper. + prefix[depth++] = c; +diff --git a/src/testdir/test_spell.vim b/src/testdir/test_spell.vim +index 58a2d58707..77eac49fd8 100644 +--- a/src/testdir/test_spell.vim ++++ b/src/testdir/test_spell.vim +@@ -1581,4 +1581,31 @@ func Test_suggest_spell_restore() + bwipe! + endfunc + ++" A crafted .spl with a self-referential BY_INDEX node in the PREFIXTREE drove ++" dump_prefixes() past its MAXWLEN-sized depth arrays (stack out-of-bounds ++" write). The tree parses cleanly (shared refs aren't recursed); the walk ++" happens on :spelldump. Reaching the assert means no OOB. Same class as the ++" tree_count_words() fix (9.2.0653). ++func Test_spelldump_prefixtree_overflow() ++ CheckUnix ++ call mkdir('Xrtp/spell', 'pR') ++ " VIMspell + v50, SN_PREFCOND(prefixcnt=1), SN_END, ++ " LWORDTREE word "a" with affixID=1 (so dump_prefixes runs), ++ " empty KWORDTREE, PREFIXTREE child BY_INDEX -> nodeidx 0 (self-cycle), 'A' ++ let spl = eval('0z56494D7370656C6C32030000000003000100FF00000004' ++ \ .. '0161010220010000000000000002010100000041') ++ call writefile(spl, 'Xrtp/spell/xx.utf-8.spl', 'b') ++ ++ new ++ set runtimepath+=./Xrtp ++ set spelllang=xx ++ set spell ++ spelldump ++ call assert_true(line('$') > 1) ++ ++ set spell& spelllang& runtimepath& ++ bwipe! ++ bwipe! ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +diff --git a/src/version.c b/src/version.c +index 03a520b146..b40bd9be93 100644 +--- a/src/version.c ++++ b/src/version.c +@@ -734,6 +734,8 @@ static char *(features[]) = + + static int included_patches[] = + { /* Add new patch number below this line */ ++/**/ ++ 662, + /**/ + 496, + /**/ +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 50ef18878e..445f5ff1cb 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -37,6 +37,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-43961.patch \ file://CVE-2026-47162.patch \ file://CVE-2026-47167.patch \ + file://CVE-2026-55892.patch \ " PV .= ".0340" From patchwork Sat Jul 25 14:32:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93496 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BFD35C531C9 for ; Sat, 25 Jul 2026 14:33:04 +0000 (UTC) Received: from mail-pj1-f41.google.com (mail-pj1-f41.google.com [209.85.216.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.372.1784989974730067701 for ; Sat, 25 Jul 2026 07:32:54 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=CKgpxOYt; spf=pass (domain: mvista.com, ip: 209.85.216.41, mailfrom: sdoshi@mvista.com) Received: by mail-pj1-f41.google.com with SMTP id 98e67ed59e1d1-38deea72eebso1530169a91.1 for ; Sat, 25 Jul 2026 07:32:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1784989974; x=1785594774; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=PHlqxpPPTqdowXO/+xK1yTvOkv50jFE8eXx9/PHLwPI=; b=CKgpxOYtPpVlmTK7drMtxYihtv0kuMjzXVm2d4DlemKkjHm8acEQTgbbtyJth7E2m6 EdZVT8JELA6gNzOgCCsMzhmKb2nH9ztV6TVlA19P6HBEc2w+ErP26bHlRTNTV0sZxTuU t6QPOTikmDN+K4SROddK37WfcVYyDrUxWVvN4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784989974; x=1785594774; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=PHlqxpPPTqdowXO/+xK1yTvOkv50jFE8eXx9/PHLwPI=; b=hKJmEWKLYgCyH0I2CX7UucjEoxLN+KHHtPTZfL7+WE7CyVCG4bovkRtRXU3dU1uaGD S1TZhjNP7sMfZS/VGX4sdi0rV8VF2Z9Nr+7fyZdTbuYzZQP3M4e3/l0Py+pgiovvK/cv PQ187RTiP04TC/nU0BdBODXbEgTLKQVl2EeOS8njW76n8I69d3b6fV+0ZKEocHTcoFWo sg8DTfK3ids7Kx+baFAMq99nvMXu3YXfv3VAbS120TraiypT4MweHJJ1SVQzDdFNfSEy 4KbleoFBrQa9NJ1ioTcaFb16fnB22rTNJb3TPmvTdYv8SAMk69IXzN3972ooTDhIjeQq CZig== X-Gm-Message-State: AOJu0YwgTV1n3/RmSB6xBNcO+XrWadFqpTUbH3w0Izta/jkm/61GDvQU sphB+PZ0DGpB3a7VDodc3RGCmbgXmbH875WnyqgN/umR7VydcCtOqxui19IWeKHXrJtO3P+h1rY 9tgdMbZ0= X-Gm-Gg: AR+sD10SSe8yIg1uwj89iO81y3fXiDkc+TeSz0Eqq5rJ5XEqlkLokvMXvetR2ZSIkZU VBcbt9Fx7s/yQD9qa54YGkzzDbHyDqTi98RMV40SSx5DV5wHst/Oop+MKK5lps40fu3Pjt5HNPk rf5XCDHSuaLKGe6QgVuEd9VUalRpWvqwJHXqT5B/Xi/uqXHMpDzN1xrkAcd2G/IxBJs6qarovA4 YmlQI9WH8eDknTFyXXng06cMkHZhBwYGPgI8jZZ64ZIjUVBTK/RYw7ghvC+M2pgdVl0l1YR1dgj oCy5FfkkjcQuG5WrLuHm7UuVOHdUJmktMurUfhQjlvJxSO7LM4VUPeVkK5U3pijDgTimRxpF+i6 +xGuM8B+ER9Ixe2kButCnGVAy9D0CVzTH4hlrHUrb9lZTNjF7wJ0CX2/qP7bjQwkSuhWIDtVV2v x7JUDGybLzamvVFPOx6BWxd04= X-Received: by 2002:a17:90b:3d4d:b0:38d:f710:63f0 with SMTP id 98e67ed59e1d1-38f298a4c6amr2327900a91.43.1784989974069; Sat, 25 Jul 2026 07:32:54 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.46.248]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13e585ae882sm1575845c88.6.2026.07.25.07.32.51 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 25 Jul 2026 07:32:53 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][wrynose][PATCH 6/6] vim: Security Fix for CVE-2026-57452 Date: Sat, 25 Jul 2026 20:02:31 +0530 Message-Id: <20260725143231.230059-6-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260725143231.230059-1-sdoshi@mvista.com> References: <20260725143231.230059-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Sat, 25 Jul 2026 14:33:04 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/241976 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57452 [2] https://security-tracker.debian.org/tracker/CVE-2026-57452 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-57452.patch | 90 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 91 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-57452.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-57452.patch b/meta/recipes-support/vim/files/CVE-2026-57452.patch new file mode 100644 index 0000000000..e87007c00a --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-57452.patch @@ -0,0 +1,90 @@ +From c8777cec25dcfae89c42e9aff51af61f71c5745f Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Thu, 18 Jun 2026 18:41:16 +0000 +Subject: [PATCH] patch 9.2.0671: [security]: possible out-of-bounds read with + sodium encrypted files + +Problem: [security]: possible out-of-bounds read with sodium encrypted + files (cipher-creator) +Solution: Verify that there is enough space before calling + crypto_secretstream_xchacha20poly1305_init_pull() + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-c4j9-wr9j-4486 + +Supported by AI + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/c8777cec25dcfae89c42e9aff51af61f71c5745f] +CVE: CVE-2026-57452 +Signed-off-by: Siddharth Doshi +--- + src/crypt.c | 3 ++- + src/testdir/test_crypt.vim | 24 ++++++++++++++++++++++++ + src/version.c | 2 ++ + 3 files changed, 28 insertions(+), 1 deletion(-) + +diff --git a/src/crypt.c b/src/crypt.c +index 2fade5db9d..879ecbf6ce 100644 +--- a/src/crypt.c ++++ b/src/crypt.c +@@ -1262,7 +1262,8 @@ crypt_sodium_buffer_decode( + + if (sod_st->count == 0) + { +- if (crypto_secretstream_xchacha20poly1305_init_pull(&sod_st->state, ++ if (len < crypto_secretstream_xchacha20poly1305_HEADERBYTES || ++ crypto_secretstream_xchacha20poly1305_init_pull(&sod_st->state, + from, sod_st->key) != 0) + { + emsg(_(e_libsodium_decryption_failed_header_incomplete)); +diff --git a/src/testdir/test_crypt.vim b/src/testdir/test_crypt.vim +index d540fbbd62..5c9dfe3baf 100644 +--- a/src/testdir/test_crypt.vim ++++ b/src/testdir/test_crypt.vim +@@ -491,4 +491,28 @@ func Test_crypt_off_by_one() + bwipe! + endfunc + ++func Test_crypt_sodium_short_body() ++ CheckFeature sodium ++ " A VimCrypt~04! file with a complete 36-byte header (12 magic + 16 salt + ++ " 8 seed) but a body shorter than one secretstream header (24 bytes) used to ++ " underflow the body length and crash with a wild out-of-bounds read in ++ " crypto_secretstream_xchacha20poly1305_pull(). It must now fail cleanly. ++ " Bytes: "VimCrypt~04!" + 16 salt + 8 seed + 8-byte body = 44 bytes. ++ call writefile(0z56696D43727970747E303421 ++ \ + 0zA0A1A2A3A4A5A6A7A8A9AAABACADAEAF ++ \ + 0zB0B1B2B3B4B5B6B7 ++ \ + 0z0000000000000000, 'Xtest_sodium_short') ++ ++ let v:errmsg = '' ++ try ++ call feedkeys(":split Xtest_sodium_short\foobar\", "xt") ++ catch /^Vim\%((\S\+)\)\=:E1198:/ ++ " no-op ++ endtry ++ ++ bwipe! ++ call delete('Xtest_sodium_short') ++ set key= ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +diff --git a/src/version.c b/src/version.c +index b40bd9be93..6eac3fc927 100644 +--- a/src/version.c ++++ b/src/version.c +@@ -734,6 +734,8 @@ static char *(features[]) = + + static int included_patches[] = + { /* Add new patch number below this line */ ++/**/ ++ 671, + /**/ + 662, + /**/ +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 445f5ff1cb..e3c6008531 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -38,6 +38,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-47162.patch \ file://CVE-2026-47167.patch \ file://CVE-2026-55892.patch \ + file://CVE-2026-57452.patch \ " PV .= ".0340"