On Wed, Aug 26, 2026 at 11:00 AM, Devansh Patel wrote: > > From: Devansh Patel > > The older Vim patch 9.2.0073 fixed CVE-2026-28417 by tightening netrw > hostname validation. That CVE fix requires follow-up regression patches > because it rejects valid hostnames containing optional ports or > underscores. > > Vim 9.2.0340 already contains that CVE fix and patch 9.2.0089, which > corrects optional-port handling. It still needs patch 9.2.0553 to accept > underscores, so backport that commit and retain its _gateway regression > test. > > The netrw history hunk is adapted to preserve Wrynose's existing > multi-line history and append the upstream 2026 May 28 entry. The > src/version.c hunk is omitted because this backport does not change the > recipe version or Vim's upstream patch-number table. > > [1] https://github.com/vim/vim/commit/79348dbbc09332130f4c86045e1541d68514fcc1 > > [2] https://github.com/vim/vim/commit/a6198523fb28a50d96945458792cdb4787d3cdda > > [3] https://github.com/vim/vim/commit/93d177cd2b69bac58fc51a5a514d7bc71e264b11 > > [4] https://github.com/vim/vim/security/advisories/GHSA-m3xh-9434-g336 > > Signed-off-by: Devansh Patel > --- > .../files/CVE-2026-28417-regression_p1.patch | 64 +++++++++++++++++++ > meta/recipes-support/vim/vim.inc | 1 + > 2 files changed, 65 insertions(+) > create mode 100644 > meta/recipes-support/vim/files/CVE-2026-28417-regression_p1.patch Hi Yoann, Gentle reminder to review the above Vim regression patch when convenient. Please share your feedback. Thanks, Devansh