From patchwork Mon Jul 27 06:18:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93546 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7E27DC531D0 for ; Mon, 27 Jul 2026 06:20:31 +0000 (UTC) Received: from mail-pj1-f41.google.com (mail-pj1-f41.google.com [209.85.216.41]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.25229.1785133227304596614 for ; Sun, 26 Jul 2026 23:20:27 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=j6AzHTZr; spf=pass (domain: mvista.com, ip: 209.85.216.41, mailfrom: sdoshi@mvista.com) Received: by mail-pj1-f41.google.com with SMTP id 98e67ed59e1d1-38e7109321dso1208545a91.3 for ; Sun, 26 Jul 2026 23:20:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1785133226; x=1785738026; darn=lists.openembedded.org; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:from:to:cc:subject:date:message-id:reply-to :content-type; bh=48JAIsc6SxT8wTT0U6kBtFAg6S6lfUR5gj0vR/5MjCU=; b=j6AzHTZrjLoazd2yVkbtRRkyKk2TlztTD+MU4krDJl/lTO2kwc72+9FNQ7icz7jiYz Hta5TLNWYrYUVDndpNVoPsieYumh2/sRGgOJBpYrXBAkp24C7VxEjWxgeJgm0HcK7JVl f49KFjNDLplaXzFWNAMawLoRe/eNsOS7zbSJg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785133226; x=1785738026; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=48JAIsc6SxT8wTT0U6kBtFAg6S6lfUR5gj0vR/5MjCU=; b=OIUWrkBElWZTITr+VcF9Z2rjSfBUXFZbnFGJHa3yOXqzyQHVmy+kp61rx5p36VEH05 RimCsceVWgutBbDbgjqxoZ4E2/FVbYFhQkfwF6r08ao/g1Ta0plnXwmeMbDobJmfjQUH nom2K7zuU4pPDsvWyTfe4l2tAstQqP8BtTugMP7Cmuomfw3IphFYuHafnQSzsbPzzV8X qyOjfW8Ty9HLil03kL/ee8nKiMLOuxN/BKNQHNBqY9LHmSzHAf63wFPl3c/NVkJmQeSf 0onmzbqJKs8Vib2NVRppIkpGrcREMB1q5u+iP0dl5A7qYdjrlCOkTE7bPdogpmDJUBu9 qfUg== X-Gm-Message-State: AOJu0YzUjW0G3iauIO4B3LdnoLEgaj41yQLC4tT0D3KK70bJ6cDf5sOm ZCXhvVCFPB2K2+BHeeyrJXg0xXEnM9oAihDFh+85xjY6DnJYmGWRlXPAJRPXdG/VF6wYaT0bb0W z/0D8Tw4= X-Gm-Gg: AR+sD11TMF3MjMJz431NDqtFanrjXBbVwe8K3NcmjT05QtYTumc0M8Bd9HuTyOPlhb2 8PSIpUEP8Z9kadp6ln+DGtpwiYn/jOh8AWiJzVZEBObGgRo+yYWTE+KmcQnYs+YqJWmORAunntH NNbx35Z+td5iMOzbqGc3A4SyJ85gzJLxL9KVj9YxmmddS293c2VBl1bzqb0+on+5IGJl0Snykb+ nQs9TiQb4edgB45hX/ESpAhrplsK8+KBXlmirVdP+Pqm+aKyTDhAz5e2zSgukjH2glIT/NvWAz5 7p5Up1J0bSHyK/M5YH6w1w0aICQRGEUeeI6ViTVOYJ/upuBcEaduZyrYHSe8afY6sy6+npidTBQ ZTU+P7lvpsbHPeWh//jG1M7jxZ6KbVPwdDAdQblz4ILEZQY4oDl36QNtk5keMyfW3p7Wvtq+C9b S1vRpZY2qnrArEw+t/a/IDtP8= X-Received: by 2002:a17:90b:1a8b:b0:38e:3a8:2374 with SMTP id 98e67ed59e1d1-38f2965e5c8mr5714525a91.30.1785133226473; Sun, 26 Jul 2026 23:20:26 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.44.234]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-314bc3e1255sm42733554eec.4.2026.07.26.23.20.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 23:20:26 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][wrynose][PATCHv2 1/6] vim: Security Fix for CVE-2026-42307 Date: Mon, 27 Jul 2026 11:48:12 +0530 Message-Id: <20260727061817.8586-1-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 27 Jul 2026 06:20:31 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242032 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-42307 [2] https://security-tracker.debian.org/tracker/CVE-2026-42307 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-42307.patch | 177 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 178 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-42307.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-42307.patch b/meta/recipes-support/vim/files/CVE-2026-42307.patch new file mode 100644 index 0000000000..037f6cba27 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-42307.patch @@ -0,0 +1,177 @@ +From 405e2fb6d54d5653523809e2853d99d1c000a5fc Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Tue, 21 Apr 2026 19:03:02 +0000 +Subject: [PATCH] patch 9.2.0383: [security]: runtime(netrw): shell-injection + via sftp: and file: URLs + +Problem: runtime(netrw): shell-injection via sftp: and file: URLs + (Joshua Rogers) +Solution: Escape temporary file names, harden filename suffix regex, + drop unused g:netrw_tmpfile_escape variable + +Supported by AI + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/405e2fb6d54d5653523809e2853d99d1c000a5fc] +CVE: CVE-2026-42307 +Signed-off-by: Siddharth Doshi +--- + runtime/doc/pi_netrw.txt | 4 --- + runtime/doc/tags | 1 - + .../pack/dist/opt/netrw/autoload/netrw.vim | 16 +++++----- + runtime/pack/dist/opt/netrw/doc/netrw.txt | 4 --- + src/testdir/test_plugin_netrw.vim | 30 +++++++++++++++++++ + src/version.c | 2 ++ + 6 files changed, 41 insertions(+), 16 deletions(-) + +diff --git a/runtime/doc/pi_netrw.txt b/runtime/doc/pi_netrw.txt +index a86cac36ba..2d98a8407b 100644 +--- a/runtime/doc/pi_netrw.txt ++++ b/runtime/doc/pi_netrw.txt +@@ -2854,10 +2854,6 @@ your browsing preferences. (see also: |netrw-settings|) + such as listing, file removal, etc. + default: ssh + +- *g:netrw_tmpfile_escape* =' &;' +- escape() is applied to all temporary files +- to escape these characters. +- + *g:netrw_timefmt* specify format string to vim's strftime(). + The default, "%c", is "the preferred date + and time representation for the current +diff --git a/runtime/doc/tags b/runtime/doc/tags +index 1e0720b21a..023996c0eb 100644 +--- a/runtime/doc/tags ++++ b/runtime/doc/tags +@@ -7966,7 +7966,6 @@ g:netrw_ssh_browse_reject pi_netrw.txt /*g:netrw_ssh_browse_reject* + g:netrw_ssh_cmd pi_netrw.txt /*g:netrw_ssh_cmd* + g:netrw_sshport pi_netrw.txt /*g:netrw_sshport* + g:netrw_timefmt pi_netrw.txt /*g:netrw_timefmt* +-g:netrw_tmpfile_escape pi_netrw.txt /*g:netrw_tmpfile_escape* + g:netrw_uid pi_netrw.txt /*g:netrw_uid* + g:netrw_use_noswf pi_netrw.txt /*g:netrw_use_noswf* + g:netrw_use_nt_rcp pi_netrw.txt /*g:netrw_use_nt_rcp* +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index 8e5fdb5397..78ce0cbc3c 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -398,7 +398,6 @@ else + call s:NetrwInit("g:netrw_glob_escape",'*[]?`{~$\') + endif + call s:NetrwInit("g:netrw_menu_escape",'.&? \') +-call s:NetrwInit("g:netrw_tmpfile_escape",' &;') + call s:NetrwInit("s:netrw_map_escape","<|\n\r\\\\"") + if has("gui_running") && (&enc == 'utf-8' || &enc == 'utf-16' || &enc == 'ucs-4') + let s:treedepthstring= "│ " +@@ -1819,14 +1818,14 @@ function netrw#NetRead(mode,...) + "......................................... + " NetRead: (sftp) NetRead Method #9 {{{3 + elseif b:netrw_method == 9 +- call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_sftp_cmd." ".netrw#os#Escape(g:netrw_machine.":".b:netrw_fname,1)." ".tmpfile) ++ call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_sftp_cmd." ".netrw#os#Escape(g:netrw_machine.":".b:netrw_fname,1)." ".netrw#os#Escape(tmpfile,1)) + let result = s:NetrwGetFile(readcmd, tmpfile, b:netrw_method) + let b:netrw_lastfile = choice + + "......................................... + " NetRead: (file) NetRead Method #10 {{{3 + elseif b:netrw_method == 10 && exists("g:netrw_file_cmd") +- call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_file_cmd." ".netrw#os#Escape(b:netrw_fname,1)." ".tmpfile) ++ call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_file_cmd." ".netrw#os#Escape(b:netrw_fname,1)." ".netrw#os#Escape(tmpfile,1)) + let result = s:NetrwGetFile(readcmd, tmpfile, b:netrw_method) + let b:netrw_lastfile = choice + +@@ -8959,14 +8958,17 @@ function s:GetTempfile(fname) + endif + + " use fname's suffix for the temporary file ++ " Restrict the suffix to word characters so shell metacharacters in a ++ " remote filename (e.g. sftp://host/foo.txt;id) cannot ride along into ++ " the tempfile name and out into a downstream shell command. + if a:fname != "" +- if a:fname =~ '\.[^./]\+$' ++ if a:fname =~ '\.\w\+$' + if a:fname =~ '\.tar\.gz$' || a:fname =~ '\.tar\.bz2$' || a:fname =~ '\.tar\.xz$' +- let suffix = ".tar".substitute(a:fname,'^.*\(\.[^./]\+\)$','\1','e') ++ let suffix = ".tar".substitute(a:fname,'^.*\(\.\w\+\)$','\1','e') + elseif a:fname =~ '.txz$' +- let suffix = ".txz".substitute(a:fname,'^.*\(\.[^./]\+\)$','\1','e') ++ let suffix = ".txz".substitute(a:fname,'^.*\(\.\w\+\)$','\1','e') + else +- let suffix = substitute(a:fname,'^.*\(\.[^./]\+\)$','\1','e') ++ let suffix = substitute(a:fname,'^.*\(\.\w\+\)$','\1','e') + endif + let tmpfile= substitute(tmpfile,'\.tmp$','','e') + let tmpfile .= suffix +diff --git a/runtime/pack/dist/opt/netrw/doc/netrw.txt b/runtime/pack/dist/opt/netrw/doc/netrw.txt +index 01a5bda597..144bab5fb3 100644 +--- a/runtime/pack/dist/opt/netrw/doc/netrw.txt ++++ b/runtime/pack/dist/opt/netrw/doc/netrw.txt +@@ -2854,10 +2854,6 @@ your browsing preferences. (see also: |netrw-settings|) + such as listing, file removal, etc. + default: ssh + +- *g:netrw_tmpfile_escape* =' &;' +- escape() is applied to all temporary files +- to escape these characters. +- + *g:netrw_timefmt* specify format string to vim's strftime(). + The default, "%c", is "the preferred date + and time representation for the current +diff --git a/src/testdir/test_plugin_netrw.vim b/src/testdir/test_plugin_netrw.vim +index b234670928..6be32911ce 100644 +--- a/src/testdir/test_plugin_netrw.vim ++++ b/src/testdir/test_plugin_netrw.vim +@@ -604,6 +604,36 @@ func Test_netrw_FileUrlEdit_pipe_injection() + call assert_false(filereadable(fname), 'Command injection via pipe in file URL') + endfunc + ++" The remote filename after '.' was allowed to contain shell metacharacters ++" and rode unescaped into the tempfile name passed to sftp/file_cmd, giving a ++" shell injection on :e sftp://host/foo.txt;. ++func Test_netrw_tempfile_suffix_injection() ++ CheckUnix ++ CheckExecutable id ++ let save_sftp = g:netrw_sftp_cmd ++ let save_file = exists('g:netrw_file_cmd') ? g:netrw_file_cmd : v:null ++ let g:netrw_sftp_cmd = 'true' ++ let g:netrw_file_cmd = 'true' ++ let fname = 'Xrce_marker' ++ try ++ call delete(fname) ++ sil! call netrw#NetRead(2, 'sftp://localhost/foo.txt;id>'..fname) ++ call assert_false(filereadable(fname), 'Command injection via sftp:// tempfile suffix') ++ ++ call delete(fname) ++ sil! call netrw#NetRead(2, 'file://localhost/foo.txt;id>'..fname) ++ call assert_false(filereadable(fname), 'Command injection via file:// tempfile suffix') ++ finally ++ call delete(fname) ++ let g:netrw_sftp_cmd = save_sftp ++ if save_file is v:null ++ unlet! g:netrw_file_cmd ++ else ++ let g:netrw_file_cmd = save_file ++ endif ++ endtry ++endfunc ++ + func Test_netrw_RFC2396() + let fname = 'a%20b' + call assert_equal('a b', netrw#RFC2396(fname)) +diff --git a/src/version.c b/src/version.c +index 560233fafc..4508ae3f18 100644 +--- a/src/version.c ++++ b/src/version.c +@@ -734,6 +734,8 @@ static char *(features[]) = + + static int included_patches[] = + { /* Add new patch number below this line */ ++/**/ ++ 383, + /**/ + 340, + /**/ +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index e34cc17fe5..0ad78ab4f0 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -23,6 +23,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-52858.patch \ file://CVE-2026-52859.patch \ file://CVE-2026-52860.patch \ + file://CVE-2026-42307.patch \ " PV .= ".0340" From patchwork Mon Jul 27 06:18:13 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93545 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6A111C531FC for ; Mon, 27 Jul 2026 06:20:31 +0000 (UTC) Received: from mail-pl1-f173.google.com (mail-pl1-f173.google.com [209.85.214.173]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.25231.1785133230122747186 for ; Sun, 26 Jul 2026 23:20:30 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=dnzHMACQ; spf=pass (domain: mvista.com, ip: 209.85.214.173, mailfrom: sdoshi@mvista.com) Received: by mail-pl1-f173.google.com with SMTP id d9443c01a7336-2ceae1ed204so23496065ad.0 for ; Sun, 26 Jul 2026 23:20:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1785133229; x=1785738029; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=qPIThyWG+Q6GQl1X7bhA60cOH+S1041+ORS1QAMzjj0=; b=dnzHMACQEP9ww/TTDJaX3F09WUsrtW3l/WMScgzbKIf4VHjenEQ3I/0Utv5aqKZEUJ lAlDidj6vMyuAQzUNgiWG/DVOeBfq4X6mc57t6ZT2w3MiNAxhgr3KVbPbbPFt96Qh32o rWq0GYAEi17WBUfI0K8uyDUac0OfweAi1G730= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785133229; x=1785738029; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=qPIThyWG+Q6GQl1X7bhA60cOH+S1041+ORS1QAMzjj0=; b=Ap9FGNB9PBDkb2f0gGeEKlzqhYtL2gBL1ut2cw7pFPDnhF025BZx/rc9B9Gojcji39 c7hnwg3i3JuTap7wsBvZOy1nCpIyN7m83ACcn0LAFrlLVlfW7fJXV5pESrmBeIFVwHer w5H3/5Qkw9Hzg1Kw3JD4flNEYxoTfB035w6VCDRfXdIezGlIUhGJ02cIiNq4/dd6SnFw XI7L8lF7MqrcQGdPL6g7Qt0Q93aOD1UIT5X+YQFyaObL9cK590VJ7IRSSj8OJ29AR8kv byShMcM6CnELcYvtMd4fNuduQl/HJ9sPUtYphDE9x5mIac9mwNnubbMLCNyREmKXSG0j Pfww== X-Gm-Message-State: AOJu0YwiTZIySlR2mv2AY90RmmtjZlWFXGurkr77wu98Duae59jvmKuN BfNpKhWk3zhSC80j0tIXdTgVkXgKOgBuRGD50V2GgUULAyVUqnyIVxEdsbZ7Sn7iJttXcRT+MBG ydUwz1ZM= X-Gm-Gg: AR+sD113PSYCTZgaxiMAsE4OqKsde171P++nAX5SEIl7YRzqePlkHYTM2NCA4Wkn6mT mmZBj8YmKOD+xOhRskSt9rBYCEwEP83qasnp0gkKzwM0MDUwZWq/CRb2a3hMiE9t/bJLPUYtJ/G MvH1zT/F7ZgjEzSCgJgl0Ap674CV13ixibuSOVvsbwXMbKi42QicUxmkQ3jaYwnDIdl8/yMuoz4 q719mDFyY32cqWJ9HbwI+keynDeO/WmxGQYVAeYqHHaRp6ozpHccrqiv8dY3PH9tLaXV3atatJ8 WLlTiWQZ4mm3nGQjW8WC8PmxomwkLuVECST84r5LK5QD/h0Nh5UJ3+eqE+zDfBQzsif28el3slu 7iHwz/MoP/2tL7oJ9twSsMAmzyC1KkmCSYF9ioM5AR5ZSz4k8GAFf0eA3uYOEeaOfxc9I6SaIXX nDPMIKs5pgMFSh X-Received: by 2002:a17:903:2d0:b0:2cf:7ffb:82aa with SMTP id d9443c01a7336-2cfde899299mr63564705ad.45.1785133229364; Sun, 26 Jul 2026 23:20:29 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.44.234]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-314bc3e1255sm42733554eec.4.2026.07.26.23.20.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 23:20:28 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][wrynose][PATCHv2 2/6] vim: Security Fix for CVE-2026-43961 Date: Mon, 27 Jul 2026 11:48:13 +0530 Message-Id: <20260727061817.8586-2-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260727061817.8586-1-sdoshi@mvista.com> References: <20260727061817.8586-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 27 Jul 2026 06:20:31 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242033 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://github.com/vim/vim/commit/8af0f098c3a42a28661d0295364e [2] https://security-tracker.debian.org/tracker/CVE-2026-43961 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-43961.patch | 104 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 105 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-43961.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-43961.patch b/meta/recipes-support/vim/files/CVE-2026-43961.patch new file mode 100644 index 0000000000..e2633ac04f --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-43961.patch @@ -0,0 +1,104 @@ +From 8af0f098c3a42a28661d0295364e6e0fd7dbc92c Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Thu, 14 May 2026 16:43:15 +0000 +Subject: [PATCH] patch 9.2.0480: [security]: runtime(netrw): code injection + via mf command + +Problem: [security]: runtime(netrw): code injection via mf command + (Christopher Lusk, Zdenek Dohnal) +Solution: Do not use string concatenation inside the filter() commands + (Zdenek Dohnal) + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-66hr-7p6x-x5j3 + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/8af0f098c3a42a28661d0295364e] +CVE: CVE-2026-43961 +Signed-off-by: Siddharth Doshi +--- + runtime/pack/dist/opt/netrw/autoload/netrw.vim | 7 +++---- + src/testdir/test_plugin_netrw.vim | 15 +++++++++++++++ + src/version.c | 2 ++ + 3 files changed, 20 insertions(+), 4 deletions(-) + +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index 78ce0cbc3c..3a460e675b 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -5175,7 +5175,7 @@ function s:NetrwMarkFile(islocal,fname) + + else + " remove filename from buffer's markfilelist +- call filter(s:netrwmarkfilelist_{curbufnr},'v:val != a:fname') ++ call filter(s:netrwmarkfilelist_{curbufnr}, {_, v -> v !=# a:fname}) + if s:netrwmarkfilelist_{curbufnr} == [] + " local markfilelist is empty; remove it entirely + call s:NetrwUnmarkList(curbufnr,curdir) +@@ -5196,7 +5196,6 @@ function s:NetrwMarkFile(islocal,fname) + + else + " initialize new markfilelist +- + let s:netrwmarkfilelist_{curbufnr}= [] + call add(s:netrwmarkfilelist_{curbufnr},substitute(a:fname,'[|@]$','','')) + +@@ -5216,7 +5215,7 @@ function s:NetrwMarkFile(islocal,fname) + call add(s:netrwmarkfilelist,netrw#fs#ComposePath(b:netrw_curdir,a:fname)) + else + " remove new filename from global markfilelist +- call filter(s:netrwmarkfilelist,'v:val != "'.dname.'"') ++ call filter(s:netrwmarkfilelist, {_, v -> v !=# dname}) + if s:netrwmarkfilelist == [] + unlet s:netrwmarkfilelist + endif +@@ -7235,7 +7234,7 @@ function s:NetrwTreeDisplay(dir,depth) + " hide given patterns + let listhide= split(g:netrw_list_hide,',') + for pat in listhide +- call filter(w:netrw_treedict[dir],'v:val !~ "'.escape(pat,'\\').'"') ++ call filter(w:netrw_treedict[dir], {_, v -> v !~# pat}) + endfor + + elseif g:netrw_hide == 2 +diff --git a/src/testdir/test_plugin_netrw.vim b/src/testdir/test_plugin_netrw.vim +index 6be32911ce..7b34b52562 100644 +--- a/src/testdir/test_plugin_netrw.vim ++++ b/src/testdir/test_plugin_netrw.vim +@@ -639,4 +639,19 @@ func Test_netrw_RFC2396() + call assert_equal('a b', netrw#RFC2396(fname)) + endfunc + ++func Test_netrw_mf_command_injection() ++ CheckUnix ++ CheckExecutable touch ++ let path = tempname() ++ let fname = 'x" . execute("silent! !touch poc") . "' ++ call mkdir(path, 'R') ++ exe "cd " path ++ call writefile([], fname) ++ Explore . ++ call search('^x') ++ :norm mf ++ :norm mf ++ call assert_false(filereadable('poc'), 'Command injection via mf command') ++endfunc ++ + " vim:ts=8 sts=2 sw=2 et +diff --git a/src/version.c b/src/version.c +index 4508ae3f18..64008e0f37 100644 +--- a/src/version.c ++++ b/src/version.c +@@ -734,6 +734,8 @@ static char *(features[]) = + + static int included_patches[] = + { /* Add new patch number below this line */ ++/**/ ++ 480, + /**/ + 383, + /**/ +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 0ad78ab4f0..fd835a3cdb 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -24,6 +24,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-52859.patch \ file://CVE-2026-52860.patch \ file://CVE-2026-42307.patch \ + file://CVE-2026-43961.patch \ " PV .= ".0340" From patchwork Mon Jul 27 06:18:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93548 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5EF87C53209 for ; Mon, 27 Jul 2026 06:20:41 +0000 (UTC) Received: from mail-pl1-f179.google.com (mail-pl1-f179.google.com [209.85.214.179]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.25233.1785133232843344981 for ; Sun, 26 Jul 2026 23:20:32 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=CKNTG+pG; spf=pass (domain: mvista.com, ip: 209.85.214.179, mailfrom: sdoshi@mvista.com) Received: by mail-pl1-f179.google.com with SMTP id d9443c01a7336-2cf50c6f235so27833465ad.0 for ; Sun, 26 Jul 2026 23:20:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1785133232; x=1785738032; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=9sW5Z9myf+0s3LdIxRbM14JNy9pC/+InvfBU/v1BXnw=; b=CKNTG+pG+hJLpoeFL/CPb9uYDoIsAw+aDpb8YsorBdCQp9JQ9KqqJifD9IWlljXdMM imp3Wno8a78gEkPe1gONM1tVOh4ATtO7KH0M8w9Ru64etdZzyvF7Pc11iInLcbK0TbbV A1gf0K+WAdy1ksomJH+N0z3g8pMDuSqodRW9U= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785133232; x=1785738032; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=9sW5Z9myf+0s3LdIxRbM14JNy9pC/+InvfBU/v1BXnw=; b=ZAQGlPlLeK6ezx7i/2y10AOWsMaVxek49yrjg8GyncNye4T2ID660x0wJcgo6jfwKq bFLH1PhkaK46LkKDD6ArTkpOw6NN/boMCBUl7epxBBUA9IWNT7Z1Fzm77FK8Yj1DmGl8 XU8osb7ud8awCplr5sUje8JEHXD81KBXFUDY+bC5iYHRUz4GaSfP0W2Q9jCp1iNrKOKg GR7q2zL5BWoUmkvD6vMUh8iwmdUqiyOwNswfroGgug/128GcVcwh7Tw3M/wXFvtpcvUf 9obaJJ+Y2+4huzx2WXhAz1cy/05v3fRdzfBSkJTjm8dOdEiHKp9eurUuGinHwRR1Aimz GZew== X-Gm-Message-State: AOJu0Yz4sZq+eVU5+igIVEAOolpgh4ewjt5uXdtfy/3kFSbMTA01H3Ns RXn7i36va+YQw6StpLJjuvLZ4G+nh5zIpiE6VsEDyWeiOiPKUeZoTCNWBLTRhpWugo/oS+O25KH RLCUNtcw= X-Gm-Gg: AR+sD12e9RefgGKTKe0SHZQWPf2k47SwwC1jCeFOVLXJeV8JmxsYAzqS8vyQcMyGio5 dLY3mqIQPrYCo8kcARA9QEaZ762PP7R5K3ju9qwqJFG8vxO0wA9fKfhgXmlm5cbLnz2rGD8Cb3S xWWAR9QX8FOtfZD91N68w0RW0Aae4Lc4ucsxXcgkCCKOWNRuBY638zHyOAwBPzuharPNyxkCspG PEyKe5j3IfA2oXlwcVUoBpnT5ybe7OuaSOzlhCXusIFMzKg45DeqLp+ig1Q1UtvUBgZt/ZJlrJp +U5cYED+WLB3Qz/FtmsoJeSE1QbcrKGGz8jHMyOY1Q5PJ4TOdaSTwdi4qbpYefTSbIqr+hw4k8H t7R1T4ldmpNC+GYcoPhg2B0p7MwfrqTPGnvjXubmmcQmO/4lVFdOILaIZqfwO5hiwLo+KUyoXVC YYSxvpY2CSBmak X-Received: by 2002:a05:6a21:99a6:b0:3c6:3c5b:f32f with SMTP id adf61e73a8af0-3c67e0b93b9mr6779463637.51.1785133232135; Sun, 26 Jul 2026 23:20:32 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.44.234]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-314bc3e1255sm42733554eec.4.2026.07.26.23.20.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 23:20:31 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][wrynose][PATCHv2 3/6] vim: Security Fix for CVE-2026-47162 Date: Mon, 27 Jul 2026 11:48:14 +0530 Message-Id: <20260727061817.8586-3-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260727061817.8586-1-sdoshi@mvista.com> References: <20260727061817.8586-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 27 Jul 2026 06:20:41 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242034 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-47162 [2] https://security-tracker.debian.org/tracker/CVE-2026-47162 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-47162.patch | 83 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 84 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-47162.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-47162.patch b/meta/recipes-support/vim/files/CVE-2026-47162.patch new file mode 100644 index 0000000000..69714493d4 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-47162.patch @@ -0,0 +1,83 @@ +From f08ab2f4d7d2947c8dd6c179ae08ee6146a2694b Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Sun, 17 May 2026 18:53:48 +0000 +Subject: [PATCH] patch 9.2.0495: [security]: runtime(netrw): code injection + via NetrwBookHistSave() + +Problem: [security]: runtime(netrw): code injection via + NetrwBookHistSave() +Solution: Properly quote the directory name using string() function + (Srinivas Piskala Ganesh Babu) + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-crm5-rh6j-2c7c + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/f08ab2f4d7d2947c8dd6c179ae08ee6146a2694b] +CVE: CVE-2026-47162 +Signed-off-by: Siddharth Doshi +--- + .../pack/dist/opt/netrw/autoload/netrw.vim | 2 +- + src/testdir/test_plugin_netrw.vim | 20 +++++++++++++++++++ + src/version.c | 2 ++ + 3 files changed, 23 insertions(+), 1 deletion(-) + +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index 3a460e675b..a04120d5f6 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -2957,7 +2957,7 @@ function s:NetrwBookHistSave() + while ( first || cnt != g:netrw_dirhistcnt ) + let lastline= lastline + 1 + if exists("g:netrw_dirhist_{cnt}") +- call setline(lastline,'let g:netrw_dirhist_'.cnt."='".g:netrw_dirhist_{cnt}."'") ++ call setline(lastline,'let g:netrw_dirhist_'.cnt.'='.string(g:netrw_dirhist_{cnt})) + endif + let first = 0 + let cnt = ( cnt - 1 ) % g:netrw_dirhistmax +diff --git a/src/testdir/test_plugin_netrw.vim b/src/testdir/test_plugin_netrw.vim +index 7b34b52562..cfce82f68a 100644 +--- a/src/testdir/test_plugin_netrw.vim ++++ b/src/testdir/test_plugin_netrw.vim +@@ -654,4 +654,24 @@ func Test_netrw_mf_command_injection() + call assert_false(filereadable('poc'), 'Command injection via mf command') + endfunc + ++func Test_netrw_injection() ++ let g:netrw_home = getcwd() ++ let savefile = g:netrw_home . '/.netrwhist' ++ let g:netrw_dirhistmax = 10 ++ let g:netrw_dirhistcnt = 1 ++ let g:netrw_dirhist_1 = "x'|let g:injected = 1|let y='z" ++ call delete(savefile) ++ try ++ call netrw#Call('NetrwBookHistSave') ++ call assert_true(filereadable(savefile), savefile . ' must be written') ++ unlet g:netrw_dirhist_1 ++ execute 'source ' . fnameescape(savefile) ++ call assert_false(exists("g:injected"), 'injected statement must not execute') ++ call assert_equal("x'|let g:injected = 1|let y='z", g:netrw_dirhist_1, 'dirname must round-trip') ++ finally ++ call delete(savefile) ++ unlet! g:netrw_home g:netrw_dirhistmax g:netrw_dirhistcnt g:netrw_dirhist_1 g:injected ++ endtry ++endfunc ++ + " vim:ts=8 sts=2 sw=2 et +diff --git a/src/version.c b/src/version.c +index 64008e0f37..cf62805e44 100644 +--- a/src/version.c ++++ b/src/version.c +@@ -734,6 +734,8 @@ static char *(features[]) = + + static int included_patches[] = + { /* Add new patch number below this line */ ++/**/ ++ 495, + /**/ + 480, + /**/ +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index fd835a3cdb..8360b1622d 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -25,6 +25,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-52860.patch \ file://CVE-2026-42307.patch \ file://CVE-2026-43961.patch \ + file://CVE-2026-47162.patch \ " PV .= ".0340" From patchwork Mon Jul 27 06:18:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93549 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5462DC54EFC for ; Mon, 27 Jul 2026 06:20:41 +0000 (UTC) Received: from mail-pl1-f177.google.com (mail-pl1-f177.google.com [209.85.214.177]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.25234.1785133235269689601 for ; Sun, 26 Jul 2026 23:20:35 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=cs6P2rKj; spf=pass (domain: mvista.com, ip: 209.85.214.177, mailfrom: sdoshi@mvista.com) Received: by mail-pl1-f177.google.com with SMTP id d9443c01a7336-2ceae1ed204so23496925ad.0 for ; Sun, 26 Jul 2026 23:20:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1785133235; x=1785738035; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ebJipnB3B25wYqBUeVYS2HrqWXtMD6lMMAAB7ASitIo=; b=cs6P2rKj2sIDT/sItdR0c2JWCCxHsbVrJbuG/riU+W2LWcfBWbyMAmjH4rwdpiHL3S 8DMh00+Iyy+YTOtfIsRE3bZG7Ua1tpYgn1ZLfU5mWSiGXqiwA4d7G8E3KdnBY8NsbV4K 7Q4C6/wSzD/v+Xb8GC1jp6Th38sXWi/RKu31A= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785133235; x=1785738035; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=ebJipnB3B25wYqBUeVYS2HrqWXtMD6lMMAAB7ASitIo=; b=mTm/sbGBBOIqRp2G9E+PkKqf/W9ZK1PBWUCZGgcpDCMhgdJCbU9pog6rLhiTIAKi0o HycQw/5ao/jjwkZ7F+WqaINW0FhhyWo5cZNiwph866dERKwVTsRLSdip7oK734Y/my8+ QLlWeRKEmw+UP0gnoMRpG+dPU/Fi3F+7AzeiNvho7JXAEWZxXfKWCvMpp1Ry/HiksIj8 1elkugWaVMN50NOKnEUsXIWp8NMPdnxbPCO7tFAc5jUlTKSyyqXXiql7Q3wzpB9zYDXl OJqepks4S6oAwCFcFUg+TVnAa9R/vF3N4ta5GCoVbUkVXWA1vjFrUhs0Sjt9WuQQQmzn sfJg== X-Gm-Message-State: AOJu0Yz8H675fDaMMq7QlkoUwdAjBeaNkE1sp20peuX9ENfly6CkTLpu ksCNWcOjuZwaPSmXcCqPg4HBAk6w/pss+HVEcbQzGLAvqt7uL3wa4ZfIXgtF/dBnWLTiAT81xqj Our1XfDQ= X-Gm-Gg: AR+sD12clGdKN68jH1JXt//S3O5dYmNUWiZEYnuNIoGt69aS1qR8B1zaVdBnB1816iO ngeUuFXZuDibtdiJnJdM3cF20K2nttmmJzErW7w6D8qS7/63HRfZdP0+gHB2W9zzCoNyYwpmIeO H2jqkO8jsopAZjJc+LDr8EtrU+kwEhIaPqTVygOAaQdcpCyqQPcLwGWV21Azpb1xX5fg7L+z7ZI ZKmwh0StSWsj7vmwcIdvqF+eOsJFdtJq83hs4YyxQj/P8am3X/daZAJUAM29cwVmA+nw0AAkOro huMPgydotoAdD8GXDWiIW4mwVDYHVbAQSnu3qkhSnDDOl3OYY+KAYNLNrTQ+zn01RQI2QQd+lBD xWmXAVm0Xu619cWktTqkfvyMDkoBx55CRjzzGvxtURkf4+inerE9bq70nECAJ/0gZ2G0wf4AuMF PH26ctaj+THidN X-Received: by 2002:a17:902:f542:b0:2c9:bd64:8c8b with SMTP id d9443c01a7336-2cfde8457bcmr66082925ad.31.1785133234648; Sun, 26 Jul 2026 23:20:34 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.44.234]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-314bc3e1255sm42733554eec.4.2026.07.26.23.20.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 23:20:34 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][wrynose][PATCHv2 4/6] vim: Security Fix for CVE-2026-47167 Date: Mon, 27 Jul 2026 11:48:15 +0530 Message-Id: <20260727061817.8586-4-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260727061817.8586-1-sdoshi@mvista.com> References: <20260727061817.8586-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 27 Jul 2026 06:20:41 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242035 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-47167 [2] https://security-tracker.debian.org/tracker/CVE-2026-47167 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-47167.patch | 102 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 103 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-47167.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-47167.patch b/meta/recipes-support/vim/files/CVE-2026-47167.patch new file mode 100644 index 0000000000..f9a989cf3a --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-47167.patch @@ -0,0 +1,102 @@ +From 5eb4bd1c12801f9ffb451f22b4d459ff2b7ff962 Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Sun, 17 May 2026 19:39:24 +0000 +Subject: [PATCH 4/6] patch 9.2.0496: [security]: Code Injection in cucumber + filetype plugin + +Problem: [security]: Code Injection in cucumber filetype plugin + (Christopher Lusk) +Solution: Use rubys Regexp.new() with the untrusted pattern + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-4473-94jm-w5x9 + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/a65a52d684bc58535ad28a4ae824d22e76399934] +CVE: CVE-2026-47167 +Signed-off-by: Siddharth Doshi +--- + runtime/ftplugin/cucumber.vim | 5 ++++- + src/testdir/test_filetype.vim | 30 ++++++++++++++++++++++++++++++ + src/version.c | 2 ++ + 3 files changed, 36 insertions(+), 1 deletion(-) + +diff --git a/runtime/ftplugin/cucumber.vim b/runtime/ftplugin/cucumber.vim +index f4848d1c60..9723898d15 100644 +--- a/runtime/ftplugin/cucumber.vim ++++ b/runtime/ftplugin/cucumber.vim +@@ -2,6 +2,8 @@ + " Language: Cucumber + " Maintainer: Tim Pope + " Last Change: 2016 Aug 29 ++" 2026 May 26 by Vim Project: prevent Code Injection ++" https://github.com/vim/vim/security/advisories/GHSA-4473-94jm-w5x9 + + " Only do this when not done yet for this buffer + if (exists("b:did_ftplugin")) +@@ -96,7 +98,8 @@ function! s:stepmatch(receiver,target) + catch + endtry + if has("ruby") && pattern !~ '\\\@ s:steps -> s:stepmatch on every discovered step, ++ " including the malicious one. Suppress preview and error messages. ++ silent! normal [d ++ call assert_false(filereadable(marker), 'Ruby injection executed') ++ bwipe! ++ filetype plugin off ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +diff --git a/src/version.c b/src/version.c +index cf62805e44..03a520b146 100644 +--- a/src/version.c ++++ b/src/version.c +@@ -734,6 +734,8 @@ static char *(features[]) = + + static int included_patches[] = + { /* Add new patch number below this line */ ++/**/ ++ 496, + /**/ + 495, + /**/ +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 8360b1622d..7a4a0bc932 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -26,6 +26,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-42307.patch \ file://CVE-2026-43961.patch \ file://CVE-2026-47162.patch \ + file://CVE-2026-47167.patch \ " PV .= ".0340" From patchwork Mon Jul 27 06:18:16 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93547 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4713AC531D0 for ; Mon, 27 Jul 2026 06:20:41 +0000 (UTC) Received: from mail-pf1-f171.google.com (mail-pf1-f171.google.com [209.85.210.171]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.25235.1785133238261119834 for ; Sun, 26 Jul 2026 23:20:38 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=bb7A47CH; spf=pass (domain: mvista.com, ip: 209.85.210.171, mailfrom: sdoshi@mvista.com) Received: by mail-pf1-f171.google.com with SMTP id d2e1a72fcca58-8487b7b3fc8so2266980b3a.3 for ; Sun, 26 Jul 2026 23:20:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1785133238; x=1785738038; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=SdscDaBZX1vtERVeJxudMsHJt9M9Ls4jHAcE2HS+EBk=; b=bb7A47CHGROcr3ewx4GT/wFRZWP/B+V7A76/7Qa4spkbkYJIsBWAITrU7pxlU33drb suycRntEXTPAjtPJetbU6BjGJEa9dxOaK3VmcvOrHgaLdTh/ljc8xN7AKj4613GS92W+ lmeW1LzFz5JG2vEih1BePhC7YuF4i/IeRstv8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785133238; x=1785738038; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=SdscDaBZX1vtERVeJxudMsHJt9M9Ls4jHAcE2HS+EBk=; b=iBBf/8hBJdT0mttNJmhc/pF2qTz2+oTMFJol+B/xaDU3dfTBpTDqgds+duDOcr4I3y CEHVFz6latq2xdSd5FDSKlLanGnXycKYsaLU6L97lxxyRCZOhVqJjyCQtpzzdwxjnlJu BFtsBp0kco7gRkWuJIe2kMIweZ/9+SUw4UsBwqXKJZdGLSnEFiT5mwHjfZ0uJOw3I4ce 0toIg3UmPtgQvCN+fEt2D32VdF7NDORaEDkzG6s+NqcQEsxZusWVsbKTeXp5fi9jabj2 6hyjb2uuLVQ2mAQ6f5oeQPyRsZPoXWaSiOVxGwAs1d5dAyxTJPWXze0D7094tL6/yttp uYaw== X-Gm-Message-State: AOJu0YzAGHtJGOwYCAIY9UzGosSscIkH3y6AN6Ro++B5xm1yxJm+U8fv hYSGqt2kCCCZROp1js2SlOIdCwTbc5WOtsgbddns+tF9Ii9+ToBzJJAovBzBjmLVVR1JYW1Kwrc nyD977iQ= X-Gm-Gg: AR+sD10ooQOO6VRiYf6NHvf6iXVEfL1c6PMPFaw4HTXgLtJBNo0tH5kcofKcpHOpISG 6vHS9vDYnVu8HJ0QUgtsKgnsVoUe6YtwjhdM9H2asioRndIyFwqMk526BGhQZaSOFSYkvcAxRNx tIhYjPYZm+/rxo1bP8OQJB46VYUcKgRkipe7yISDAj3TvxF0vkGEEi2CJ3RmHTN9rtEfIToJDjw v9sviGNRdlQZIS0K0rRFWPwkJDVIt3W9C73b8Rpxz5AQg8zmpSEizJbw1E+Fl8IBowqj83Hx5hV B+bJePHULc+3LmYIVjQ3uZWevQOBOLynqtyFVgp1li6Qei44wYo1Gl5fx+zzO9rC0RIp3JCyYP+ gXvG0CinVmw8JzS3Zitw/fr5JSrMujAkyqxLfgM220p6YZdidMkla3lRr88YPTgQpv6K2IaLLMJ /vWDC+dvmGnREs X-Received: by 2002:a05:6a20:6a27:b0:3c0:9c1a:893c with SMTP id adf61e73a8af0-3c67e16412fmr6847019637.68.1785133237560; Sun, 26 Jul 2026 23:20:37 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.44.234]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-314bc3e1255sm42733554eec.4.2026.07.26.23.20.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 23:20:37 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][wrynose][PATCHv2 5/6] vim: Security Fix for CVE-2026-55892 Date: Mon, 27 Jul 2026 11:48:16 +0530 Message-Id: <20260727061817.8586-5-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260727061817.8586-1-sdoshi@mvista.com> References: <20260727061817.8586-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 27 Jul 2026 06:20:41 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242036 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-55892 [2] https://security-tracker.debian.org/tracker/CVE-2026-55892 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-55892.patch | 95 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 96 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-55892.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-55892.patch b/meta/recipes-support/vim/files/CVE-2026-55892.patch new file mode 100644 index 0000000000..fc43095362 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-55892.patch @@ -0,0 +1,95 @@ +From 8325b193bba5f01e7a7d8241fc8633d93dff996b Mon Sep 17 00:00:00 2001 +From: Yasuhiro Matsumoto +Date: Tue, 16 Jun 2026 20:32:21 +0000 +Subject: [PATCH] patch 9.2.0662: [security] Stack out-of-bounds write in + dump_prefixes() + +Problem: [security]: a crafted spell file with a self-referential + BY_INDEX node in the prefix tree can drive dump_prefixes() + past the end of its MAXWLEN-sized depth arrays on :spelldump + (cipher-creator) +Solution: only descend while depth < MAXWLEN - 1, as the sibling trie + walkers already do (Yasuhiro Matsumoto) + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-qm9w-fmpj-879h + +Supported by AI + +Signed-off-by: Yasuhiro Matsumoto +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/8325b193bba5f01e7a7d8241fc8633d93dff996b] +CVE: CVE-2026-55892 +Signed-off-by: Siddharth Doshi +--- + src/spell.c | 2 +- + src/testdir/test_spell.vim | 27 +++++++++++++++++++++++++++ + src/version.c | 2 ++ + 3 files changed, 30 insertions(+), 1 deletion(-) + +diff --git a/src/spell.c b/src/spell.c +index 01eb57e3a9..72d1f0b521 100644 +--- a/src/spell.c ++++ b/src/spell.c +@@ -4325,7 +4325,7 @@ dump_prefixes( + } + } + } +- else ++ else if (depth < MAXWLEN - 1) + { + // Normal char, go one level deeper. + prefix[depth++] = c; +diff --git a/src/testdir/test_spell.vim b/src/testdir/test_spell.vim +index 58a2d58707..77eac49fd8 100644 +--- a/src/testdir/test_spell.vim ++++ b/src/testdir/test_spell.vim +@@ -1581,4 +1581,31 @@ func Test_suggest_spell_restore() + bwipe! + endfunc + ++" A crafted .spl with a self-referential BY_INDEX node in the PREFIXTREE drove ++" dump_prefixes() past its MAXWLEN-sized depth arrays (stack out-of-bounds ++" write). The tree parses cleanly (shared refs aren't recursed); the walk ++" happens on :spelldump. Reaching the assert means no OOB. Same class as the ++" tree_count_words() fix (9.2.0653). ++func Test_spelldump_prefixtree_overflow() ++ CheckUnix ++ call mkdir('Xrtp/spell', 'pR') ++ " VIMspell + v50, SN_PREFCOND(prefixcnt=1), SN_END, ++ " LWORDTREE word "a" with affixID=1 (so dump_prefixes runs), ++ " empty KWORDTREE, PREFIXTREE child BY_INDEX -> nodeidx 0 (self-cycle), 'A' ++ let spl = eval('0z56494D7370656C6C32030000000003000100FF00000004' ++ \ .. '0161010220010000000000000002010100000041') ++ call writefile(spl, 'Xrtp/spell/xx.utf-8.spl', 'b') ++ ++ new ++ set runtimepath+=./Xrtp ++ set spelllang=xx ++ set spell ++ spelldump ++ call assert_true(line('$') > 1) ++ ++ set spell& spelllang& runtimepath& ++ bwipe! ++ bwipe! ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +diff --git a/src/version.c b/src/version.c +index 03a520b146..b40bd9be93 100644 +--- a/src/version.c ++++ b/src/version.c +@@ -734,6 +734,8 @@ static char *(features[]) = + + static int included_patches[] = + { /* Add new patch number below this line */ ++/**/ ++ 662, + /**/ + 496, + /**/ +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index 7a4a0bc932..f423e4d5cb 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -27,6 +27,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-43961.patch \ file://CVE-2026-47162.patch \ file://CVE-2026-47167.patch \ + file://CVE-2026-55892.patch \ " PV .= ".0340" From patchwork Mon Jul 27 06:18:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siddharth X-Patchwork-Id: 93550 X-Patchwork-Delegate: yoann.congal@smile.fr Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 59B6DC531D0 for ; Mon, 27 Jul 2026 06:20:51 +0000 (UTC) Received: from mail-pl1-f169.google.com (mail-pl1-f169.google.com [209.85.214.169]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.24932.1785133245629802987 for ; Sun, 26 Jul 2026 23:20:45 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@mvista.com header.s=google header.b=GKTCDk19; spf=pass (domain: mvista.com, ip: 209.85.214.169, mailfrom: sdoshi@mvista.com) Received: by mail-pl1-f169.google.com with SMTP id d9443c01a7336-2cc7ef7ec27so29185675ad.1 for ; Sun, 26 Jul 2026 23:20:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mvista.com; s=google; t=1785133245; x=1785738045; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=e8ssfdKECoKCR1PLLocuG0vKVF3QjDnK+ITIC1VABm4=; b=GKTCDk19TNsIdrWxr0diEFS+G2Gdnye0TvtTeUtgjj+84QHp9YDGKu6ugFY4rstawg 85Pzf1bo53kJBBrlLmLAkilNwy+Tbe0SBw2KTQ2MoYdpxKGNVfiaOFvjhUG8F0KEWsAh nrJvYByoBQoGFulMa7RuJ9p23lwRI4dErHE2w= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785133245; x=1785738045; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=e8ssfdKECoKCR1PLLocuG0vKVF3QjDnK+ITIC1VABm4=; b=FnuxCsQ179wQRSVFgGS2DS3tF2xNQN6875sD8o7HX9zrdGFXN+2q82Z741XvxCA/WR qmY9h9KKganmeIuBD3AnMI+VP12nUPrj4Eo26oftpy2u2yM8TDadtcGcepq9IJU3JRJL xr4IoHqf7YMpv8lpTRGcyZBw8RGGTfVLT4b9Z8NZ4cblKvln+fRK9ChiM5mrk2bGZ6rg zcFwNJHqoX/oheAdCeYwEPh16HNXd8F5FlU8hapnGflBXmG5p724x57V1XMzmXz8xCDO Di/oGde8swtUNQnDwYc/PNcAApGYaRy+vRgDDJZSzojNTJ4us3Y9TtpI24EgjdcNB2B3 KKZg== X-Gm-Message-State: AOJu0Yy8ZF2rI6Gtqs+o4FfilCU/5ZtTfrBqtfglunmsiVVSS/6ZW03e zteKT87m0cXwK4s+yC6yCQq6HJ/aSchggOlmLSfNfrtM3TaAtxfWHuIrgFiTLeyO5alIzm/00cf sXL/h0PE= X-Gm-Gg: AR+sD13WG2HRRi5L6EPeqorRVqqhkoJla5mBEJpqD8SiHxvzVjs3L16bTnkXM/4BB0+ t+1kSr5GYxxvQ8oeqphzn9tMKlg0SRQGlo4msmgtu3hwjYBQ0gf+L5Wb/IUGOVAo11misC04aic fdL6oinyGiaiZk2zQVnMgedA2E9XcBYmaCZWzo0vfPkMPjGA+d6/q1vwCXVjmIk6sNjws7GtKtP 7d1LzE0iHSnDTWswf3twj589Vd04c7DP1R8Ty1LVNGDWAX8Lo2YWpzua+SV5/mvS+wqFzF8yJGZ eLKfqUVK+GIPUDuzyVDphg+MD9hiEPoyeIfh6gD90s4hbkwQ9HHCiYRo3eWRXbTi4BklYD6i88y i/IBr+g/L0Q+aowEFsBXyucsebasMmTiodjuTbXSc7qSR1a9et7mKUv+VpVEz+XhybRVkPQ6mC5 SMEQTDiHl0+9rwvD8xOwl/wMs= X-Received: by 2002:a17:903:1845:b0:2ca:e565:7b15 with SMTP id d9443c01a7336-2cfde78b647mr64257845ad.10.1785133244954; Sun, 26 Jul 2026 23:20:44 -0700 (PDT) Received: from MVIN00030.mvista.com ([157.32.44.234]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-314bc3e1255sm42733554eec.4.2026.07.26.23.20.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 23:20:44 -0700 (PDT) From: Siddharth To: openembedded-core@lists.openembedded.org Cc: Siddharth Doshi Subject: [OE-core][wrynose][PATCHv2 6/6] vim: Security Fix for CVE-2026-57452 Date: Mon, 27 Jul 2026 11:48:17 +0530 Message-Id: <20260727061817.8586-6-sdoshi@mvista.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260727061817.8586-1-sdoshi@mvista.com> References: <20260727061817.8586-1-sdoshi@mvista.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 27 Jul 2026 06:20:51 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/242037 From: Siddharth Doshi Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57452 [2] https://security-tracker.debian.org/tracker/CVE-2026-57452 Signed-off-by: Siddharth Doshi --- .../vim/files/CVE-2026-57452.patch | 90 +++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 91 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-57452.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-57452.patch b/meta/recipes-support/vim/files/CVE-2026-57452.patch new file mode 100644 index 0000000000..e87007c00a --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-57452.patch @@ -0,0 +1,90 @@ +From c8777cec25dcfae89c42e9aff51af61f71c5745f Mon Sep 17 00:00:00 2001 +From: Christian Brabandt +Date: Thu, 18 Jun 2026 18:41:16 +0000 +Subject: [PATCH] patch 9.2.0671: [security]: possible out-of-bounds read with + sodium encrypted files + +Problem: [security]: possible out-of-bounds read with sodium encrypted + files (cipher-creator) +Solution: Verify that there is enough space before calling + crypto_secretstream_xchacha20poly1305_init_pull() + +Github Security Advisory: +https://github.com/vim/vim/security/advisories/GHSA-c4j9-wr9j-4486 + +Supported by AI + +Signed-off-by: Christian Brabandt + +Upstream-Status: Backport [https://github.com/vim/vim/commit/c8777cec25dcfae89c42e9aff51af61f71c5745f] +CVE: CVE-2026-57452 +Signed-off-by: Siddharth Doshi +--- + src/crypt.c | 3 ++- + src/testdir/test_crypt.vim | 24 ++++++++++++++++++++++++ + src/version.c | 2 ++ + 3 files changed, 28 insertions(+), 1 deletion(-) + +diff --git a/src/crypt.c b/src/crypt.c +index 2fade5db9d..879ecbf6ce 100644 +--- a/src/crypt.c ++++ b/src/crypt.c +@@ -1262,7 +1262,8 @@ crypt_sodium_buffer_decode( + + if (sod_st->count == 0) + { +- if (crypto_secretstream_xchacha20poly1305_init_pull(&sod_st->state, ++ if (len < crypto_secretstream_xchacha20poly1305_HEADERBYTES || ++ crypto_secretstream_xchacha20poly1305_init_pull(&sod_st->state, + from, sod_st->key) != 0) + { + emsg(_(e_libsodium_decryption_failed_header_incomplete)); +diff --git a/src/testdir/test_crypt.vim b/src/testdir/test_crypt.vim +index d540fbbd62..5c9dfe3baf 100644 +--- a/src/testdir/test_crypt.vim ++++ b/src/testdir/test_crypt.vim +@@ -491,4 +491,28 @@ func Test_crypt_off_by_one() + bwipe! + endfunc + ++func Test_crypt_sodium_short_body() ++ CheckFeature sodium ++ " A VimCrypt~04! file with a complete 36-byte header (12 magic + 16 salt + ++ " 8 seed) but a body shorter than one secretstream header (24 bytes) used to ++ " underflow the body length and crash with a wild out-of-bounds read in ++ " crypto_secretstream_xchacha20poly1305_pull(). It must now fail cleanly. ++ " Bytes: "VimCrypt~04!" + 16 salt + 8 seed + 8-byte body = 44 bytes. ++ call writefile(0z56696D43727970747E303421 ++ \ + 0zA0A1A2A3A4A5A6A7A8A9AAABACADAEAF ++ \ + 0zB0B1B2B3B4B5B6B7 ++ \ + 0z0000000000000000, 'Xtest_sodium_short') ++ ++ let v:errmsg = '' ++ try ++ call feedkeys(":split Xtest_sodium_short\foobar\", "xt") ++ catch /^Vim\%((\S\+)\)\=:E1198:/ ++ " no-op ++ endtry ++ ++ bwipe! ++ call delete('Xtest_sodium_short') ++ set key= ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +diff --git a/src/version.c b/src/version.c +index b40bd9be93..6eac3fc927 100644 +--- a/src/version.c ++++ b/src/version.c +@@ -734,6 +734,8 @@ static char *(features[]) = + + static int included_patches[] = + { /* Add new patch number below this line */ ++/**/ ++ 671, + /**/ + 662, + /**/ +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index f423e4d5cb..20a5f7a054 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -28,6 +28,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-47162.patch \ file://CVE-2026-47167.patch \ file://CVE-2026-55892.patch \ + file://CVE-2026-57452.patch \ " PV .= ".0340"