Openembedded Core Discussions
 help / color / mirror / Atom feed
* [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693
@ 2026-07-22 12:33 Vijay Anusuri
  2026-07-22 12:33 ` [OE-core][wrynose][patch 02/10] vim: Fix CVE-2026-55895 Vijay Anusuri
                   ` (8 more replies)
  0 siblings, 9 replies; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
  To: openembedded-core; +Cc: Vijay Anusuri

Pick patch per [1].

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-55693
[2] https://security-tracker.debian.org/tracker/CVE-2026-55693

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
 .../vim/files/CVE-2026-55693.patch            | 88 +++++++++++++++++++
 meta/recipes-support/vim/vim.inc              |  1 +
 2 files changed, 89 insertions(+)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-55693.patch

diff --git a/meta/recipes-support/vim/files/CVE-2026-55693.patch b/meta/recipes-support/vim/files/CVE-2026-55693.patch
new file mode 100644
index 0000000000..41f48ebfa5
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-55693.patch
@@ -0,0 +1,88 @@
+From a80874d9b84a01040e3d1aef2d4a59e1934dafb7 Mon Sep 17 00:00:00 2001
+From: Christian Brabandt <cb@256bit.org>
+Date: Mon, 15 Jun 2026 19:39:08 +0000
+Subject: [PATCH] patch 9.2.0653: [security]: out-of-bounds write in
+ tree_count_words()
+
+Problem:  [security]: a crafted spell file can drive tree_count_words()
+          past the end of its MAXWLEN-sized depth arrays; the descent
+          loop has no depth bound.
+Solution: only descend while depth < MAXWLEN - 1, as the sibling trie
+          walkers already do; apply the same guard to sug_filltree().
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-wgh4-64f7-q3jq
+
+Supported by AI.
+
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/a80874d9b84a01040e3d1aef2d4a59e1934dafb7]
+CVE: CVE-2026-55693
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/spellfile.c                |  4 ++--
+ src/testdir/test_spellfile.vim | 26 ++++++++++++++++++++++++++
+ 2 files changed, 28 insertions(+), 2 deletions(-)
+
+diff --git a/src/spellfile.c b/src/spellfile.c
+index 5102dad5b6..b3ee9c0d63 100644
+--- a/src/spellfile.c
++++ b/src/spellfile.c
+@@ -642,7 +642,7 @@ tree_count_words(char_u *byts, idx_T *idxs)
+ 		    ++curi[depth];
+ 		}
+ 	    }
+-	    else
++	    else if (depth < MAXWLEN - 1)
+ 	    {
+ 		// Normal char, go one level deeper to count the words.
+ 		++depth;
+@@ -5656,7 +5656,7 @@ sug_filltree(spellinfo_T *spin, slang_T *slang)
+ 		    ++curi[depth];
+ 		}
+ 	    }
+-	    else
++	    else if (depth < MAXWLEN - 1)
+ 	    {
+ 		// Normal char, go one level deeper.
+ 		tword[depth++] = c;
+diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim
+index 8f3ef4907d..4da270acea 100644
+--- a/src/testdir/test_spellfile.vim
++++ b/src/testdir/test_spellfile.vim
+@@ -1196,5 +1196,31 @@ func Test_mkspell_no_buffer_overflow()
+   defer delete('Xbof2.spl')
+ endfunc
+ 
++func Test_spell_sug_tree_count_words_overflow()
++  " A crafted .spl/.sug pair with a BY_INDEX self-cycle in the fold word tree
++  " parses cleanly (shared refs aren't recursed, so read_tree_node()'s depth
++  " cap never trips), but drove tree_count_words() past its MAXWLEN-sized depth
++  " arrays -> stack out-of-bounds write.  The walk only happens when
++  " spellsuggest() loads the matching .sug.  Reaching the assert == no OOB.
++  call mkdir('Xrtp/spell', 'pR')
++  " VIMspell + v50, SN_SUGFILE(ts), SN_END, LWORDTREE{node:1,BY_INDEX->0,'A'},
++  " empty KWORDTREE/PREFIXTREE
++  let spl = eval('0z56494D7370656C6C320B0000000008000000001234'
++        \ .. '5678FF000000020101000000410000000000000000')
++  " VIMsug + v1, matching ts, SUGWORDTREE word "a", empty SUGTABLE
++  let sug = 0z56494D737567010000000012345678000000040161010000000000
++  call writefile(spl, 'Xrtp/spell/xx.utf-8.spl', 'b')
++  call writefile(sug, 'Xrtp/spell/xx.utf-8.sug', 'b')
++
++  new
++  set runtimepath+=./Xrtp
++  set spelllang=xx
++  set spell
++  " Unpatched: OOB write here (ASan abort, or crash).  Patched: returns a list.
++  call assert_equal(v:t_list, type(spellsuggest('helloo')))
++
++  set spell& spelllang& runtimepath&
++  bwipe!
++endfunc
+ 
+ " vim: shiftwidth=2 sts=2 expandtab
+-- 
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index e34cc17fe5..c0315dfed6 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -23,6 +23,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-52858.patch \
            file://CVE-2026-52859.patch \
            file://CVE-2026-52860.patch \
+           file://CVE-2026-55693.patch \
            "
 
 PV .= ".0340"
-- 
2.43.0



^ permalink raw reply related	[flat|nested] 15+ messages in thread

* [OE-core][wrynose][patch 02/10] vim: Fix CVE-2026-55895
  2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
  2026-07-22 12:33 ` [OE-core][wrynose][patch 03/10] vim: Fix CVE-2026-57453 Vijay Anusuri
                   ` (7 subsequent siblings)
  8 siblings, 0 replies; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
  To: openembedded-core; +Cc: Vijay Anusuri

Pick patch per [1].

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-55895
[2] https://github.com/vim/vim/security/advisories/GHSA-vhh8-v6wx-hjjh

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
 .../vim/files/CVE-2026-55895.patch            | 83 +++++++++++++++++++
 meta/recipes-support/vim/vim.inc              |  1 +
 2 files changed, 84 insertions(+)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-55895.patch

diff --git a/meta/recipes-support/vim/files/CVE-2026-55895.patch b/meta/recipes-support/vim/files/CVE-2026-55895.patch
new file mode 100644
index 0000000000..cc335ea2a6
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-55895.patch
@@ -0,0 +1,83 @@
+From 55bc757a5d436e59d50fe43f7cda94b118f86cb2 Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Tue, 16 Jun 2026 21:00:28 +0000
+Subject: [PATCH] patch 9.2.0663: [security]: runtime(netrw): code injection in
+ local file deletion
+
+Problem:  [security]: s:NetrwLocalRmFile() escapes only the backslash in
+          the file name before passing it to :execute, so a name
+          containing "|" injects arbitrary Ex commands when the file is
+          deleted (cipher-creator)
+Solution: Use fnameescape() to correctly escape the file name
+          (Yasuhiro Matsumoto).
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-vhh8-v6wx-hjjh
+
+Supported by AI
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/55bc757a5d436e59d50fe43f7cda94b118f86cb2]
+CVE: CVE-2026-55895
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ .../pack/dist/opt/netrw/autoload/netrw.vim    |  4 ++--
+ src/testdir/test_plugin_netrw.vim             | 20 +++++++++++++++++++
+ 2 files changed, 22 insertions(+), 2 deletions(-)
+
+diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim
+index 8e5fdb5397..ebb856800c 100644
+--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim
++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim
+@@ -3062,7 +3062,7 @@ function s:NetrwBrowse(islocal,dirname)
+     elseif !a:islocal && dirname !~ '[\/]$' && dirname !~ '^"'
+         " s:NetrwBrowse :  remote regular file handler {{{3
+         if bufname(dirname) != ""
+-            exe "NetrwKeepj b ".bufname(dirname)
++            exe "NetrwKeepj b ".fnameescape(bufname(dirname))
+         else
+             " attempt transfer of remote regular file
+ 
+@@ -8772,7 +8772,7 @@ function s:NetrwLocalRmFile(path, fname, all)
+             call netrw#msg#Notify('ERROR', printf("unable to delete <%s>!", rmfile))
+         else
+             " Remove file only if there are no pending changes
+-            execute printf('silent! bwipeout %s', rmfile)
++            execute printf('silent! bwipeout %s', fnameescape(rmfile))
+         endif
+ 
+     elseif dir && (all || empty(ok))
+diff --git a/src/testdir/test_plugin_netrw.vim b/src/testdir/test_plugin_netrw.vim
+index b234670928..4d5fc9a065 100644
+--- a/src/testdir/test_plugin_netrw.vim
++++ b/src/testdir/test_plugin_netrw.vim
+@@ -609,4 +609,24 @@ func Test_netrw_RFC2396()
+   call assert_equal('a b', netrw#RFC2396(fname))
+ endfunc
+ 
++" Deleting a file whose name contains an Ex command separator must not let the
++" name inject commands into the :execute in s:NetrwLocalRmFile().
++func Test_netrw_local_rm_injection()
++  CheckUnix
++  let dir   = getcwd() . '/Xnetrwrm'
++  let fname = "x|let g:injected = 1"
++  call mkdir(dir, 'pR')
++  call writefile([], dir . '/' . fname)
++  try
++    call netrw#Call('NetrwLocalRmFile', dir, fname, 1)
++    call assert_false(exists('g:injected'), 'filename must not inject Ex commands')
++    " The file is removed before the sink, so its absence also confirms the
++    " vulnerable code path was actually exercised (not skipped on an error).
++    call assert_false(filereadable(dir . '/' . fname), 'crafted file must be deleted')
++  finally
++    call delete(dir . '/' . fname)
++    unlet! g:injected
++  endtry
++endfunc
++
+ " vim:ts=8 sts=2 sw=2 et
+-- 
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index c0315dfed6..b9f6ef987c 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -24,6 +24,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-52859.patch \
            file://CVE-2026-52860.patch \
            file://CVE-2026-55693.patch \
+           file://CVE-2026-55895.patch \
            "
 
 PV .= ".0340"
-- 
2.43.0



^ permalink raw reply related	[flat|nested] 15+ messages in thread

* [OE-core][wrynose][patch 03/10] vim: Fix CVE-2026-57453
  2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
  2026-07-22 12:33 ` [OE-core][wrynose][patch 02/10] vim: Fix CVE-2026-55895 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
  2026-07-26 21:45   ` Yoann Congal
  2026-07-22 12:33 ` [OE-core][wrynose][patch 04/10] vim: Fix CVE-2026-57451 Vijay Anusuri
                   ` (6 subsequent siblings)
  8 siblings, 1 reply; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
  To: openembedded-core; +Cc: Vijay Anusuri

Pick patch per [1].

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57453
[2] https://github.com/vim/vim/security/advisories/GHSA-x5fg-h5w9-9frf

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
 .../vim/files/CVE-2026-57453.patch            | 248 ++++++++++++++++++
 meta/recipes-support/vim/vim.inc              |   1 +
 2 files changed, 249 insertions(+)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-57453.patch

diff --git a/meta/recipes-support/vim/files/CVE-2026-57453.patch b/meta/recipes-support/vim/files/CVE-2026-57453.patch
new file mode 100644
index 0000000000..d1ad6d6f54
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-57453.patch
@@ -0,0 +1,248 @@
+From b2cc9be119d51212bf0d3f2a994c7e517c73f4a9 Mon Sep 17 00:00:00 2001
+From: Christian Brabandt <cb@256bit.org>
+Date: Sat, 20 Jun 2026 15:35:58 +0000
+Subject: [PATCH] patch 9.2.0678: [security]: potential powershell code
+ execution in zip.vim
+
+Problem:  [security]: potential powershell code execution in zip.vim
+          (DDugs)
+Solution: Cleanup zip.vim, introduce PSEscape() to escape() potential powershell code,
+          use consistent s:Escape() in the various PowerShell functions
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-x5fg-h5w9-9frf
+
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/b2cc9be119d51212bf0d3f2a994c7e517c73f4a9]
+CVE: CVE-2026-57453
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ runtime/autoload/zip.vim | 78 +++++++++++++++++++---------------------
+ runtime/doc/pi_zip.txt   | 10 ------
+ 2 files changed, 36 insertions(+), 52 deletions(-)
+
+diff --git a/runtime/autoload/zip.vim b/runtime/autoload/zip.vim
+index f4482fd7fc..752503a626 100644
+--- a/runtime/autoload/zip.vim
++++ b/runtime/autoload/zip.vim
+@@ -22,6 +22,7 @@
+ " 2026 Mar 08 by Vim Project: Make ZipUpdatePS() check for powershell
+ " 2026 Apr 01 by Vim Project: Detect more path traversal attacks
+ " 2026 Apr 05 by Vim Project: Detect more path traversal attacks
++" 2026 Jun 20 by Vim Project: Fix wrong escaping for the powershell calls
+ " License:	Vim License  (see vim's :help license)
+ " Copyright:	Copyright (C) 2005-2019 Charles E. Campbell {{{1
+ "		Permission is hereby granted to use and distribute this code,
+@@ -49,15 +50,6 @@ let s:NOTE           = 0
+ 
+ " ---------------------------------------------------------------------
+ "  Global Values: {{{1
+-if !exists("g:zip_shq")
+- if &shq != ""
+-  let g:zip_shq= &shq
+- elseif has("unix")
+-  let g:zip_shq= "'"
+- else
+-  let g:zip_shq= '"'
+- endif
+-endif
+ if !exists("g:zip_zipcmd")
+  let g:zip_zipcmd= "zip"
+ endif
+@@ -133,7 +125,7 @@ function! s:ZipBrowsePS(zipfile)
+   " Browse the contents of a zip file using PowerShell's
+   " Equivalent `unzip -Z1 -- zipfile`
+   let cmds = [
+-        \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:Escape(a:zipfile, 1) . ');',
++        \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:PSEscape(a:zipfile) . ');',
+         \ '$zip.Entries | ForEach-Object { $_.FullName };',
+         \ '$zip.Dispose()'
+         \ ]
+@@ -147,16 +139,16 @@ function! s:ZipReadPS(zipfile, fname, tempfile)
+     call s:Mess('WarningMsg', "***warning*** PowerShell can display, but cannot update, files in archive subfolders")
+   endif
+   let cmds = [
+-        \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:Escape(a:zipfile, 1) . ');',
+-        \ '$fileEntry = $zip.Entries | Where-Object { $_.FullName -eq ' . s:Escape(a:fname, 1) . ' };',
++        \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:PSEscape(a:zipfile) . ');',
++        \ '$fileEntry = $zip.Entries | Where-Object { $_.FullName -eq ' . s:PSEscape(a:fname) . ' };',
+         \ '$stream = $fileEntry.Open();',
+-        \ '$fileStream = [System.IO.File]::Create(' . s:Escape(a:tempfile, 1) . ');',
++        \ '$fileStream = [System.IO.File]::Create(' . s:PSEscape(a:tempfile) . ');',
+         \ '$stream.CopyTo($fileStream);',
+         \ '$fileStream.Close();',
+         \ '$stream.Close();',
+         \ '$zip.Dispose()'
+         \ ]
+-  return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' '), 1)
++  return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' '))
+ endfunction
+ 
+ function! s:ZipUpdatePS(zipfile, fname)
+@@ -166,7 +158,7 @@ function! s:ZipUpdatePS(zipfile, fname)
+     call s:Mess('Error', "***error*** PowerShell cannot update files in archive subfolders")
+     return ':'
+   endif
+-  return 'Compress-Archive -Path ' . a:fname . ' -Update -DestinationPath ' . a:zipfile
++  return 'Compress-Archive -Path ' . s:PSEscape(a:fname) . ' -Update -DestinationPath ' . s:PSEscape(a:zipfile)
+ endfunction
+ 
+ function! s:ZipExtractFilePS(zipfile, fname)
+@@ -177,16 +169,16 @@ function! s:ZipExtractFilePS(zipfile, fname)
+     return ':'
+   endif
+   let cmds = [
+-        \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:Escape(a:zipfile, 1) . ');',
+-        \ '$fileEntry = $zip.Entries | Where-Object { $_.FullName -eq ' . a:fname . ' };',
++        \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:PSEscape(a:zipfile) . ');',
++        \ '$fileEntry = $zip.Entries | Where-Object { $_.FullName -eq ' . s:PSEscape(a:fname) . ' };',
+         \ '$stream = $fileEntry.Open();',
+-        \ '$fileStream = [System.IO.File]::Create(' . a:fname . ');',
++        \ '$fileStream = [System.IO.File]::Create(' . s:PSEscape(a:fname) . ');',
+         \ '$stream.CopyTo($fileStream);',
+         \ '$fileStream.Close();',
+         \ '$stream.Close();',
+         \ '$zip.Dispose()'
+         \ ]
+-  return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' '), 1)
++  return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' '))
+ endfunction
+ 
+ function! s:ZipDeleteFilePS(zipfile, fname)
+@@ -194,12 +186,12 @@ function! s:ZipDeleteFilePS(zipfile, fname)
+   " Equivalent to `zip -d zipfile fname`
+   let cmds = [
+         \ 'Add-Type -AssemblyName System.IO.Compression.FileSystem;',
+-        \ '$zip = [System.IO.Compression.ZipFile]::Open(' . s:Escape(a:zipfile, 1) . ', ''Update'');',
+-        \ '$entry = $zip.Entries | Where-Object { $_.Name -eq ' . s:Escape(a:fname, 1) . ' };',
++        \ '$zip = [System.IO.Compression.ZipFile]::Open(' . s:PSEscape(a:zipfile) . ', ''Update'');',
++        \ '$entry = $zip.Entries | Where-Object { $_.Name -eq ' . s:PSEscape(a:fname) . ' };',
+         \ 'if ($entry) { $entry.Delete(); $zip.Dispose() }',
+         \ 'else { $zip.Dispose() }'
+         \ ]
+-  return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' '), 1)
++  return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' '))
+ endfunction
+ 
+ " ----------------
+@@ -339,9 +331,9 @@ fun! zip#Read(fname,mode)
+   let temp = tempname()
+   let fn   = expand('%:p')
+ 
+-  let gnu_cmd = g:zip_unzipcmd . ' -p -- ' . s:Escape(zipfile, 0) . ' ' . s:Escape(fname, 0) . ' > ' . s:Escape(temp, 0)
+-  let gnu_cmd = 'call system(''' . substitute(gnu_cmd, "'", "''", 'g') . ''')'
+-  let ps_cmd = 'sil !' . s:ZipReadPS(zipfile, fname, temp)
++  let gnu_cmd = g:zip_unzipcmd . ' -p -- ' . s:Escape(zipfile) . ' ' . s:Escape(fname) . ' > ' . s:Escape(temp)
++  let gnu_cmd = 'call system(' . string(gnu_cmd) . ')'
++  let ps_cmd = $"call system({string(s:ZipDeleteFilePS(zipfile, fname))})"
+   call s:TryExecGnuFallBackToPs(g:zip_unzipcmd, gnu_cmd, ps_cmd)
+ 
+   sil exe 'keepalt file '.temp
+@@ -408,9 +400,9 @@ fun! zip#Write(fname)
+     " TODO: what to check on MS-Windows to avoid writing absolute paths?
+   endif
+   if fname =~ '^[.]\{1,2}/'
+-    let gnu_cmd = g:zip_zipcmd . ' -d ' . s:Escape(fnamemodify(zipfile,":p"),0) . ' ' . s:Escape(fname,0)
+-    let gnu_cmd = 'call system(''' . substitute(gnu_cmd, "'", "''", 'g') . ''')'
+-    let ps_cmd = $"call system({s:Escape(s:ZipDeleteFilePS(zipfile, fname), 1)})"
++    let gnu_cmd = g:zip_zipcmd . ' -d ' . s:Escape(fnamemodify(zipfile,":p")) . ' ' . s:Escape(fname)
++    let gnu_cmd = 'call system(' . string(gnu_cmd) . ')'
++    let ps_cmd = $"call system({string(s:ZipDeleteFilePS(zipfile, fname))})"
+     call s:TryExecGnuFallBackToPs(g:zip_zipcmd, gnu_cmd, ps_cmd)
+     let fname = fname->substitute('^\([.]\{1,2}/\)\+', '', 'g')
+     let need_rename = 1
+@@ -419,7 +411,7 @@ fun! zip#Write(fname)
+   if fname =~ '/'
+     let dirpath = substitute(fname,'/[^/]\+$','','e')
+     if has("win32unix") && executable("cygpath")
+-    let dirpath = substitute(system("cygpath ".s:Escape(dirpath,0)),'\n','','e')
++    let dirpath = substitute(system("cygpath ".s:Escape(dirpath)),'\n','','e')
+     endif
+     call mkdir(dirpath,"p")
+   endif
+@@ -430,16 +422,17 @@ fun! zip#Write(fname)
+   " don't overwrite files forcefully
+   exe "w ".fnameescape(fname)
+   if has("win32unix") && executable("cygpath")
+-    let zipfile = substitute(system("cygpath ".s:Escape(zipfile,0)),'\n','','e')
++    let zipfile = substitute(system("cygpath ".s:Escape(zipfile)),'\n','','e')
+   endif
+ 
+   if (has("win32") || has("win95") || has("win64") || has("win16")) && &shell !~? 'sh$'
+     let fname = substitute(fname, '[', '[[]', 'g')
+   endif
+ 
+-  let gnu_cmd = g:zip_zipcmd . ' -u '. s:Escape(fnamemodify(zipfile,":p"),0) . ' ' . s:Escape(fname,0)
++  let gnu_cmd = g:zip_zipcmd . ' -u '. s:Escape(fnamemodify(zipfile,":p")) . ' ' . s:Escape(fname)
+   let gnu_cmd = 'call system(''' . substitute(gnu_cmd, "'", "''", 'g') . ''')'
+-  let ps_cmd = s:ZipUpdatePS(s:Escape(fnamemodify(zipfile, ':p'), 0), s:Escape(fname, 0))
++  let zip = fnamemodify(zipfile, ':p')
++  let ps_cmd = s:ZipUpdatePS(zip, fname)
+   let ps_cmd = 'call system(''' . substitute(ps_cmd, "'", "''", 'g') . ''')'
+   call s:TryExecGnuFallBackToPs(g:zip_zipcmd, gnu_cmd, ps_cmd)
+   if &shell =~ 'pwsh'
+@@ -522,8 +515,8 @@ fun! zip#Extract()
+ 
+   " extract the file mentioned under the cursor
+   let gnu_cmd = g:zip_extractcmd . ' -o '. shellescape(b:zipfile) . ' ' . target
+-  let gnu_cmd = 'call system(''' . substitute(gnu_cmd, "'", "''", 'g') . ''')'
+-  let ps_cmd = $"call system({s:Escape(s:ZipExtractFilePS(b:zipfile, target), 1)})"
++  let gnu_cmd = 'call system(' . string(gnu_cmd) . ')'
++  let ps_cmd = 'call system(' . string(s:ZipExtractFilePS(b:zipfile, fname)) . ')'
+   call s:TryExecGnuFallBackToPs(g:zip_extractcmd, gnu_cmd, ps_cmd)
+ 
+   if v:shell_error != 0
+@@ -537,19 +530,20 @@ endfun
+ 
+ " ---------------------------------------------------------------------
+ " s:Escape: {{{2
+-fun! s:Escape(fname,isfilt)
+-  if exists("*shellescape")
+-   if a:isfilt
+-    let qnameq= shellescape(a:fname,1)
+-   else
+-    let qnameq= shellescape(a:fname)
+-   endif
++fun! s:Escape(fname, isfilt = 0)
++  if a:isfilt
++   let qnameq = shellescape(a:fname, 1)
+   else
+-   let qnameq= g:zip_shq.escape(a:fname,g:zip_shq).g:zip_shq
++   let qnameq = shellescape(a:fname)
+   endif
+   return qnameq
+ endfun
+ 
++" s:PSEscape: Escape a string for Powershell, shellescape() does not work here {{{2
++fun! s:PSEscape(str)
++  return "'" .. substitute(a:str, "'", "''", 'g') .. "'"
++endfun
++
+ " ---------------------------------------------------------------------
+ " s:ChgDir: {{{2
+ fun! s:ChgDir(newdir,errlvl,errmsg)
+diff --git a/runtime/doc/pi_zip.txt b/runtime/doc/pi_zip.txt
+index e9294b4059..b1800dfcc5 100644
+--- a/runtime/doc/pi_zip.txt
++++ b/runtime/doc/pi_zip.txt
+@@ -48,16 +48,6 @@ Copyright: Copyright (C) 2005-2015 Charles E Campbell	 *zip-copyright*
+    If this variable exists and is true, the file window will not be
+    automatically maximized when opened.
+ 
+-							*g:zip_shq*
+-   Different operating systems may use one or more shells to execute
+-   commands.  Zip will try to guess the correct quoting mechanism to
+-   allow spaces and whatnot in filenames; however, if it is incorrectly
+-   guessing the quote to use for your setup, you may use >
+-	g:zip_shq
+-<   which by default is a single quote under Unix (') and a double quote
+-   under Windows (").  If you'd rather have no quotes, simply set
+-   g:zip_shq to the empty string (let g:zip_shq= "") in your <.vimrc>.
+-
+ 							*g:zip_unzipcmd*
+    Use this option to specify the program which does the duty of "unzip".
+    It's used during browsing. By default: >
+-- 
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index b9f6ef987c..ecdf7cb5b9 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -25,6 +25,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-52860.patch \
            file://CVE-2026-55693.patch \
            file://CVE-2026-55895.patch \
+           file://CVE-2026-57453.patch \
            "
 
 PV .= ".0340"
-- 
2.43.0



^ permalink raw reply related	[flat|nested] 15+ messages in thread

* [OE-core][wrynose][patch 04/10] vim: Fix CVE-2026-57451
  2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
  2026-07-22 12:33 ` [OE-core][wrynose][patch 02/10] vim: Fix CVE-2026-55895 Vijay Anusuri
  2026-07-22 12:33 ` [OE-core][wrynose][patch 03/10] vim: Fix CVE-2026-57453 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
  2026-07-26 21:53   ` Yoann Congal
  2026-07-22 12:33 ` [OE-core][wrynose][patch 05/10] vim: Fix CVE-2026-57454 Vijay Anusuri
                   ` (5 subsequent siblings)
  8 siblings, 1 reply; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
  To: openembedded-core; +Cc: Vijay Anusuri

Pick patch per [1].

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57451
[2] https://github.com/vim/vim/security/advisories/GHSA-f36c-2qcp-7gpw

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
 .../vim/files/CVE-2026-57451.patch            | 177 ++++++++++++++++++
 meta/recipes-support/vim/vim.inc              |   1 +
 2 files changed, 178 insertions(+)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-57451.patch

diff --git a/meta/recipes-support/vim/files/CVE-2026-57451.patch b/meta/recipes-support/vim/files/CVE-2026-57451.patch
new file mode 100644
index 0000000000..22a0cfc03e
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-57451.patch
@@ -0,0 +1,177 @@
+From b2338ca90643e2f01ecb6547c1172716aaec4f79 Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Wed, 17 Jun 2026 21:06:59 +0000
+Subject: [PATCH] patch 9.2.0670: [security]: Out-of-bounds read with text
+ properties
+
+Problem:  [security]: Out-of-bounds read with text properties
+          (cipher-creator)
+Solution: Add out-of-bound checks (Yasuhiro Matsumoto)
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-f36c-2qcp-7gpw
+
+Supported by AI
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/b2338ca90643e2f01ecb6547c1172716aaec4f79]
+CVE: CVE-2026-57451
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/memline.c                  |  7 ++++
+ src/proto/textprop.pro         |  1 +
+ src/testdir/test_textprop2.vim | 59 ++++++++++++++++++++++++++++++++++
+ src/textprop.c                 | 20 ++++++++++++
+ 4 files changed, 87 insertions(+)
+
+diff --git a/src/memline.c b/src/memline.c
+index c15946a6eb..07c7a07d38 100644
+--- a/src/memline.c
++++ b/src/memline.c
+@@ -3796,6 +3796,11 @@ adjust_text_props_for_delete(
+ 		uint16_t pc;
+ 
+ 		mch_memmove(&pc, text + textlen, PROP_COUNT_SIZE);
++		if (!text_prop_count_valid(pc, (size_t)(line_size - (long)textlen)))
++		{
++		    internal_error("text property count too large");
++		    return;
++		}
+ 		this_props_len = pc * (int)sizeof(textprop_T);
+ 	    }
+ 
+@@ -4034,6 +4039,8 @@ theend:
+ 	mch_memmove(&pc, textprop_save, PROP_COUNT_SIZE);
+ 	props_data = textprop_save + PROP_COUNT_SIZE;
+ 	props_bytes = pc * (int)sizeof(textprop_T);
++	if (!text_prop_count_valid(pc, (size_t)textprop_len))
++	    props_bytes = 0;
+ 
+ 	// Adjust text properties in the line above and below.
+ 	if (lnum > 1)
+diff --git a/src/proto/textprop.pro b/src/proto/textprop.pro
+index d3ecf6d14c..a01c2f3b2d 100644
+--- a/src/proto/textprop.pro
++++ b/src/proto/textprop.pro
+@@ -35,4 +35,5 @@ void clear_buf_prop_types(buf_T *buf);
+ int adjust_prop_columns(linenr_T lnum, colnr_T col, int bytes_added, int flags);
+ void adjust_props_for_split(linenr_T lnum_props, linenr_T lnum_top, int kept, int deleted, int at_eol);
+ void prepend_joined_props(unpacked_memline_T *um, linenr_T lnum, int last_line, long col, int removed);
++bool text_prop_count_valid(int prop_count, size_t propdata_len);
+ /* vim: set ft=c : */
+diff --git a/src/testdir/test_textprop2.vim b/src/testdir/test_textprop2.vim
+index 193a808415..48387d1c04 100644
+--- a/src/testdir/test_textprop2.vim
++++ b/src/testdir/test_textprop2.vim
+@@ -428,4 +428,63 @@ func Test_multiline_prop_delete_penultimate_line()
+   call s:CleanupPropTypes(['1', '2', '3'])
+ endfunc
+ 
++func s:ManipulateUndoBlob(name)
++  " Patch the saved old line in the undo file:
++  "   00 00 00 08 'QQQQQQQQ'  ->  00 00 00 27 'AAAA' NUL count=0xFFFF <32x00>
++  " i.e. textlen 8 text-only  ->  39-byte blob: text "AAAA", NUL, prop_count
++  "   0xFFFF, one zeroed textprop_T(32).  propdata_len becomes 34, count 65535.
++  let blob   = readfile(a:name, 'B')
++  let marker = 0z000000085151515151515151
++  let repl   = 0z000000274141414100FFFF + repeat(0z00, 32)
++  let mlen   = len(marker)
++  let idx    = -1
++  let i      = 0
++  while i <= len(blob) - mlen
++    if blob[i : i + mlen - 1] ==# marker
++      let idx = i
++      break
++    endif
++    let i += 1
++  endwhile
++  call assert_true(idx >= 0, 'saved-line marker not found in undo file')
++
++  let head = idx > 0 ? blob[0 : idx - 1] : 0z
++  call writefile(head + repl + blob[idx + mlen :], a:name)
++
++  exe "rundo" a:name
++endfunc
++
++" A crafted undo file can restore a line whose declared text-property count is
++" far larger than the data, making get_text_props() / consumers read past the
++" line buffer.  Restore such a line and force a consumer; reaching the asserts
++" (no ASan abort / crash) means the count is bounded.
++func Test_textprop_undo_bad_prop_count()
++  CheckFeature persistent_undo
++
++  new
++  call setline(1, ['QQQQQQQQ', 'DECOYLINE'])
++  let &ul = &ul
++  call setline(1, 'BBBB')           " undo step saves old line 1 = "QQQQQQQQ"
++  wundo Xtpundo
++  call s:ManipulateUndoBlob('Xtpundo')
++
++  undo
++
++  " Safety: prove the malicious line was actually restored before the consumer
++  " runs, so the test can't pass vacuously if the patch missed.
++  call assert_equal('AAAA', getline(1))
++
++  " Adding a property anywhere sets b_has_textprop, so get_text_props() will
++  " actually inspect line 1 instead of returning early.
++  call prop_type_add('Xtp', {})
++  call prop_add(2, 1, {'type': 'Xtp', 'length': 1})
++
++  " this caused OOB read, now it triggers internal error
++  call assert_fails('call prop_list(1)', ['E340:', 'corrupted'])
++
++  call prop_type_delete('Xtp')
++  bwipe!
++  call delete('Xtpundo')
++endfunc
++
+ " vim: shiftwidth=2 sts=2 expandtab
+diff --git a/src/textprop.c b/src/textprop.c
+index 33165a8e43..931fb78d25 100644
+--- a/src/textprop.c
++++ b/src/textprop.c
+@@ -109,6 +109,12 @@ um_goto_line(unpacked_memline_T *um, linenr_T lnum, int extra_props)
+     char_u	    *props_start;
+ 
+     mch_memmove(&prop_count, count_ptr, PROP_COUNT_SIZE);
++    if (!text_prop_count_valid(prop_count, propdata_len))
++    {
++    iemsg(e_text_property_info_corrupted);
++    um->buf = NULL;
++    return false;
++    }
+     proplen = (int)prop_count;
+     props_start = count_ptr + PROP_COUNT_SIZE;
+ 
+@@ -1235,6 +1241,11 @@ get_text_props(buf_T *buf, linenr_T lnum, char_u **props, int will_change)
+ 	return 0;
+     }
+     mch_memmove(&prop_count, text + textlen, PROP_COUNT_SIZE);
++    if (!text_prop_count_valid(prop_count, propdata_len))
++    {
++    iemsg(e_text_property_info_corrupted);
++    return 0;
++    }
+     *props = text + textlen + PROP_COUNT_SIZE;
+     return (int)prop_count;
+ }
+@@ -3219,4 +3230,13 @@ prepend_joined_props(
+     um_abort(&r_um);
+ }
+ 
++    bool
++text_prop_count_valid(int prop_count, size_t propdata_len)
++{
++    if (propdata_len < PROP_COUNT_SIZE)
++    return false;
++    return (size_t)prop_count * sizeof(textprop_T)
++	    <= propdata_len - PROP_COUNT_SIZE;
++}
++
+ #endif // FEAT_PROP_POPUP
+-- 
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index ecdf7cb5b9..b9acb4665a 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -26,6 +26,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-55693.patch \
            file://CVE-2026-55895.patch \
            file://CVE-2026-57453.patch \
+           file://CVE-2026-57451.patch \
            "
 
 PV .= ".0340"
-- 
2.43.0



^ permalink raw reply related	[flat|nested] 15+ messages in thread

* [OE-core][wrynose][patch 05/10] vim: Fix CVE-2026-57454
  2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
                   ` (2 preceding siblings ...)
  2026-07-22 12:33 ` [OE-core][wrynose][patch 04/10] vim: Fix CVE-2026-57451 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
  2026-07-26 22:05   ` Yoann Congal
  2026-07-22 12:33 ` [OE-core][wrynose][patch 06/10] vim: Fix CVE-2026-57455 Vijay Anusuri
                   ` (4 subsequent siblings)
  8 siblings, 1 reply; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
  To: openembedded-core; +Cc: Vijay Anusuri

Pick patch per [1].

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57454
[2] https://security-tracker.debian.org/tracker/CVE-2026-57454

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
 .../vim/files/CVE-2026-57454.patch            | 188 ++++++++++++++++++
 meta/recipes-support/vim/vim.inc              |   1 +
 2 files changed, 189 insertions(+)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-57454.patch

diff --git a/meta/recipes-support/vim/files/CVE-2026-57454.patch b/meta/recipes-support/vim/files/CVE-2026-57454.patch
new file mode 100644
index 0000000000..579ffbf11b
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-57454.patch
@@ -0,0 +1,188 @@
+From b3faeecc976d3031d7c0675623516ec60c30f949 Mon Sep 17 00:00:00 2001
+From: Hirohito Higashi <h.east.727@gmail.com>
+Date: Sat, 20 Jun 2026 16:06:58 +0000
+Subject: [PATCH] patch 9.2.0679: [security]: Out-of-bounds read with text
+ property virtual text
+
+Problem:  [security]: Out-of-bounds read with text property virtual text.
+          A crafted undo file can declare a virtual-text property whose
+          offset points outside the line's property data, so reading the
+          virtual text reads out of bounds.  This completes the count-only
+          check added in 9.2.0670.
+Solution: Validate the virtual-text offset and length of each property
+          against the available property data before turning the offset
+          into a pointer.
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-ww8h-47xp-hp4w
+
+Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
+Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/b3faeecc976d3031d7c0675623516ec60c30f949]
+CVE: CVE-2026-57454
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/proto/textprop.pro         |  1 +
+ src/testdir/test_textprop2.vim | 60 ++++++++++++++++++++++++++++++----
+ src/textprop.c                 | 36 ++++++++++++++++++++
+ 3 files changed, 90 insertions(+), 7 deletions(-)
+
+diff --git a/src/proto/textprop.pro b/src/proto/textprop.pro
+index a01c2f3b2d..4e6fcc89a4 100644
+--- a/src/proto/textprop.pro
++++ b/src/proto/textprop.pro
+@@ -36,4 +36,5 @@ int adjust_prop_columns(linenr_T lnum, colnr_T col, int bytes_added, int flags);
+ void adjust_props_for_split(linenr_T lnum_props, linenr_T lnum_top, int kept, int deleted, int at_eol);
+ void prepend_joined_props(unpacked_memline_T *um, linenr_T lnum, int last_line, long col, int removed);
+ bool text_prop_count_valid(int prop_count, size_t propdata_len);
++bool text_prop_vtext_valid(char_u *props, int prop_count, size_t propdata_len);
+ /* vim: set ft=c : */
+diff --git a/src/testdir/test_textprop2.vim b/src/testdir/test_textprop2.vim
+index 48387d1c04..689096209c 100644
+--- a/src/testdir/test_textprop2.vim
++++ b/src/testdir/test_textprop2.vim
+@@ -428,14 +428,12 @@ func Test_multiline_prop_delete_penultimate_line()
+   call s:CleanupPropTypes(['1', '2', '3'])
+ endfunc
+ 
+-func s:ManipulateUndoBlob(name)
+-  " Patch the saved old line in the undo file:
+-  "   00 00 00 08 'QQQQQQQQ'  ->  00 00 00 27 'AAAA' NUL count=0xFFFF <32x00>
+-  " i.e. textlen 8 text-only  ->  39-byte blob: text "AAAA", NUL, prop_count
+-  "   0xFFFF, one zeroed textprop_T(32).  propdata_len becomes 34, count 65535.
++func s:ManipulateUndoBlob(name, repl)
++  " Replace the saved old line (00 00 00 08 'QQQQQQQQ') in the undo file with
++  " the crafted "repl" blob, then read it back in.
+   let blob   = readfile(a:name, 'B')
+   let marker = 0z000000085151515151515151
+-  let repl   = 0z000000274141414100FFFF + repeat(0z00, 32)
++  let repl   = a:repl
+   let mlen   = len(marker)
+   let idx    = -1
+   let i      = 0
+@@ -466,7 +464,10 @@ func Test_textprop_undo_bad_prop_count()
+   let &ul = &ul
+   call setline(1, 'BBBB')           " undo step saves old line 1 = "QQQQQQQQ"
+   wundo Xtpundo
+-  call s:ManipulateUndoBlob('Xtpundo')
++  " 39-byte blob: "AAAA" NUL count=0xFFFF, one zeroed textprop_T(32).
++  " propdata_len becomes 34 while the count claims 65535 properties.
++  call s:ManipulateUndoBlob('Xtpundo', 0z000000274141414100FFFF
++    \ + repeat(0z00, 32))
+ 
+   undo
+ 
+@@ -487,4 +488,49 @@ func Test_textprop_undo_bad_prop_count()
+   call delete('Xtpundo')
+ endfunc
+ 
++" A crafted undo file can restore a line whose virtual-text property declares an
++" out-of-range tp_text_offset.  Turning that offset into a pointer and reading
++" the virtual text would read past the line buffer.  Restore such a line and
++" force a consumer; reaching the asserts (no ASan abort / crash) means the
++" offset is bounded.
++func Test_textprop_undo_bad_vtext_offset()
++  CheckFeature persistent_undo
++
++  new
++  call setline(1, ['QQQQQQQQ', 'DECOYLINE'])
++  let &ul = &ul
++  call setline(1, 'BBBB')           " undo step saves old line 1 = "QQQQQQQQ"
++  wundo Xtpundo
++
++  " One textprop_T for a virtual text prop (tp_id < 0) whose tp_text_offset
++  " (0x00100000) points far past the 34-byte property data.  The count (1) is
++  " valid, so only the offset/length check can reject this.
++  let prop  = 0z01000000          " tp_col = 1
++  let prop += 0z04000000          " tp_len = 4
++  let prop += 0zFFFFFFFF          " tp_id = -1 (virtual text)
++  let prop += 0z00000000          " tp_type = 0
++  let prop += 0z00000000          " tp_flags = 0
++  let prop += 0z00000000          " tp_padleft = 0
++  let prop += 0z00001000          " u.tp_text_offset = 0x00100000
++  let prop += 0z00000000          " union upper bytes
++  call s:ManipulateUndoBlob('Xtpundo', 0z000000274141414100 + 0z0100 + prop)
++
++  undo
++
++  " Safety: prove the malicious line was actually restored before the consumer
++  " runs, so the test can't pass vacuously if the patch missed.
++  call assert_equal('AAAA', getline(1))
++
++  call prop_type_add('Xtp', {})
++  call prop_add(2, 1, {'type': 'Xtp', 'length': 1})
++
++  " this caused OOB read, now it is rejected as a corrupted (untrusted) undo
++  " file with a catchable error
++  call assert_fails('call prop_list(1)', 'E967:')
++
++  call prop_type_delete('Xtp')
++  bwipe!
++  call delete('Xtpundo')
++endfunc
++
+ " vim: shiftwidth=2 sts=2 expandtab
+diff --git a/src/textprop.c b/src/textprop.c
+index 931fb78d25..463a477e4d 100644
+--- a/src/textprop.c
++++ b/src/textprop.c
+@@ -118,6 +118,13 @@ um_goto_line(unpacked_memline_T *um, linenr_T lnum, int extra_props)
+     proplen = (int)prop_count;
+     props_start = count_ptr + PROP_COUNT_SIZE;
+ 
++    if (!text_prop_vtext_valid(props_start, proplen, propdata_len))
++    {
++    emsg(e_text_property_info_corrupted);
++    um->buf = NULL;
++    return false;
++    }
++
+     um->props = ALLOC_MULT(textprop_T, proplen + extra_props);
+     if (um->props == NULL)
+     {
+@@ -1246,6 +1253,12 @@ get_text_props(buf_T *buf, linenr_T lnum, char_u **props, int will_change)
+     iemsg(e_text_property_info_corrupted);
+     return 0;
+     }
++    if (!text_prop_vtext_valid(text + textlen + PROP_COUNT_SIZE,
++		       (int)prop_count, propdata_len))
++    {
++    emsg(e_text_property_info_corrupted);
++    return 0;
++    }
+     *props = text + textlen + PROP_COUNT_SIZE;
+     return (int)prop_count;
+ }
+@@ -3239,4 +3252,27 @@ text_prop_count_valid(int prop_count, size_t propdata_len)
+ 	    <= propdata_len - PROP_COUNT_SIZE;
+ }
+ 
++/*
++ * Return true when every virtual text property's offset and length stay within
++ * "propdata_len", so tp_text_offset can be safely turned into a pointer.
++ * "props" may be unaligned.
++ */
++    bool
++text_prop_vtext_valid(char_u *props, int prop_count, size_t propdata_len)
++{
++    for (int i = 0; i < prop_count; ++i)
++    {
++    textprop_T  prop;
++
++    mch_memmove(&prop, props + (size_t)i * sizeof(textprop_T),
++			      sizeof(textprop_T));
++    if (prop.tp_id >= 0 || prop.u.tp_text_offset <= 0)
++	continue;
++    if (prop.tp_len < 0 || (size_t)prop.u.tp_text_offset
++		+ (size_t)prop.tp_len + 1 > propdata_len)
++	return false;
++    }
++    return true;
++}
++
+ #endif // FEAT_PROP_POPUP
+-- 
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index b9acb4665a..82f63f6067 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -27,6 +27,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-55895.patch \
            file://CVE-2026-57453.patch \
            file://CVE-2026-57451.patch \
+           file://CVE-2026-57454.patch \
            "
 
 PV .= ".0340"
-- 
2.43.0



^ permalink raw reply related	[flat|nested] 15+ messages in thread

* [OE-core][wrynose][patch 06/10] vim: Fix CVE-2026-57455
  2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
                   ` (3 preceding siblings ...)
  2026-07-22 12:33 ` [OE-core][wrynose][patch 05/10] vim: Fix CVE-2026-57454 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
  2026-07-22 12:33 ` [OE-core][wrynose][patch 07/10] vim: Fix CVE-2026-57456 Vijay Anusuri
                   ` (3 subsequent siblings)
  8 siblings, 0 replies; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
  To: openembedded-core; +Cc: Vijay Anusuri

Pick patch per [1].

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57455
[2] https://security-tracker.debian.org/tracker/CVE-2026-57455

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
 .../vim/files/CVE-2026-57455.patch            | 72 +++++++++++++++++++
 meta/recipes-support/vim/vim.inc              |  1 +
 2 files changed, 73 insertions(+)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-57455.patch

diff --git a/meta/recipes-support/vim/files/CVE-2026-57455.patch b/meta/recipes-support/vim/files/CVE-2026-57455.patch
new file mode 100644
index 0000000000..51f0eb7fe0
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-57455.patch
@@ -0,0 +1,72 @@
+From 497f931f85339d175d7f69588dd249e8ccfed41b Mon Sep 17 00:00:00 2001
+From: Christian Brabandt <cb@256bit.org>
+Date: Sun, 21 Jun 2026 19:20:03 +0000
+Subject: [PATCH] patch 9.2.0698: [security]: Out-of-bounds write with
+ soundfold()
+
+Problem:  [security]: Out-of-bounds write with soundfold()
+          (cipher-creator)
+Solution: Add an abort condition to the for loop to validate the buffer
+          size.
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-q8mh-6qm3-25g4
+
+Supported by AI
+
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/497f931f85339d175d7f69588dd249e8ccfed41b]
+CVE: CVE-2026-57455
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/spell.c                    |  2 +-
+ src/testdir/test_spellfile.vim | 21 +++++++++++++++++++++
+ 2 files changed, 22 insertions(+), 1 deletion(-)
+
+diff --git a/src/spell.c b/src/spell.c
+index 01eb57e3a9..060a2251a4 100644
+--- a/src/spell.c
++++ b/src/spell.c
+@@ -3270,7 +3270,7 @@ spell_soundfold_sofo(slang_T *slang, char_u *inword, char_u *res)
+     else
+     {
+ 	// The sl_sal_first[] table contains the translation.
+-	for (s = inword; (c = *s) != NUL; ++s)
++	for (s = inword; (c = *s) != NUL && ri < MAXWLEN - 1; ++s)
+ 	{
+ 	    if (VIM_ISWHITE(c))
+ 		c = ' ';
+diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim
+index 4da270acea..c0c46a32d2 100644
+--- a/src/testdir/test_spellfile.vim
++++ b/src/testdir/test_spellfile.vim
+@@ -1223,4 +1223,25 @@ func Test_spell_sug_tree_count_words_overflow()
+   bwipe!
+ endfunc
+ 
++" A word longer than MAXWLEN must not overflow the soundfold result buffer in
++" the single-byte SOFO branch of spell_soundfold_sofo().
++func Test_soundfold_overflow()
++  let _enc=&enc
++  set enc=latin1
++  call writefile(['SOFOFROM ab', 'SOFOTO xy'], 'Xtest.aff', 'D')
++  call writefile(['1', 'foo'], 'Xtest.dic', 'D')
++  mkspell! Xtest Xtest
++  defer delete('Xtest.latin1.spl')
++  defer delete('Xtest.latin1.sug')
++  setl spelllang=Xtest.latin1.spl spell
++
++  " Before the fix the copy loop wrote one byte per input byte into a
++  " MAXWLEN (254) stack buffer with no upper bound, smashing the stack.
++  let sound = soundfold(repeat('ab', 300))
++  call assert_true(strlen(sound) < 254, 'soundfold result exceeds MAXWLEN')
++
++  set spell& spelllang&
++  let &enc = _enc
++endfunc
++
+ " vim: shiftwidth=2 sts=2 expandtab
+-- 
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 82f63f6067..dec5b68324 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -28,6 +28,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-57453.patch \
            file://CVE-2026-57451.patch \
            file://CVE-2026-57454.patch \
+           file://CVE-2026-57455.patch \
            "
 
 PV .= ".0340"
-- 
2.43.0



^ permalink raw reply related	[flat|nested] 15+ messages in thread

* [OE-core][wrynose][patch 07/10] vim: Fix CVE-2026-57456
  2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
                   ` (4 preceding siblings ...)
  2026-07-22 12:33 ` [OE-core][wrynose][patch 06/10] vim: Fix CVE-2026-57455 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
  2026-07-22 12:33 ` [OE-core][wrynose][patch 08/10] vim: Fix CVE-2026-59856 Vijay Anusuri
                   ` (2 subsequent siblings)
  8 siblings, 0 replies; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
  To: openembedded-core; +Cc: Vijay Anusuri

Pick patch per [1].

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57456
[2] https://security-tracker.debian.org/tracker/CVE-2026-57456

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
 .../vim/files/CVE-2026-57456.patch            | 149 ++++++++++++++++++
 meta/recipes-support/vim/vim.inc              |   1 +
 2 files changed, 150 insertions(+)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-57456.patch

diff --git a/meta/recipes-support/vim/files/CVE-2026-57456.patch b/meta/recipes-support/vim/files/CVE-2026-57456.patch
new file mode 100644
index 0000000000..9a4155ef04
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-57456.patch
@@ -0,0 +1,149 @@
+From cce141c42740f122dd8486ae04e21c2a81016ba8 Mon Sep 17 00:00:00 2001
+From: Christian Brabandt <cb@256bit.org>
+Date: Sun, 21 Jun 2026 19:50:56 +0000
+Subject: [PATCH] patch 9.2.0699: [security]: possible code execution with
+ python complete
+
+Problem:  [security]: possible code execution with python complete
+          (morningbread)
+Solution: Use repr() to quote the doc strings correctly
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-ppj8-wqjf-6fp3
+
+Supported by AI
+
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/cce141c42740f122dd8486ae04e21c2a81016ba8]
+CVE: CVE-2026-57456
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ runtime/autoload/python3complete.vim        |  9 +++++----
+ runtime/autoload/pythoncomplete.vim         |  9 +++++----
+ src/testdir/test_plugin_python3complete.vim | 15 +++++++++++++++
+ 3 files changed, 25 insertions(+), 8 deletions(-)
+
+diff --git a/runtime/autoload/python3complete.vim b/runtime/autoload/python3complete.vim
+index c4ef19d82f..f90cca74b3 100644
+--- a/runtime/autoload/python3complete.vim
++++ b/runtime/autoload/python3complete.vim
+@@ -2,7 +2,7 @@
+ " Maintainer: <vacancy>
+ " Previous Maintainer: Aaron Griffin <aaronmgriffin@gmail.com>
+ " Version: 0.10
+-" Last Updated: 2026 Jun 04
++" Last Updated: 2026 Jun 21
+ "
+ " Roland Puntaier: this file contains adaptations for python3 and is parallel to pythoncomplete.vim
+ "
+@@ -22,6 +22,7 @@
+ "     previous code passed buffer-supplied expressions to exec() which
+ "     Python evaluates at definition time, allowing arbitrary code
+ "     execution via crafted def/class headers
++"   * use repr() on doc strings to prevent code execution
+ "
+ " v 0.9
+ "   * Fixed docstring parsing for classes and functions
+@@ -335,7 +336,7 @@ class Scope(object):
+ 
+     def get_code(self):
+         str = ""
+-        if len(self.docstr) > 0: str += '"""'+self.docstr+'"""\n'
++        if len(self.docstr) > 0: str += repr(self.docstr)+'\n'
+         str += 'class _PyCmplNoType:\n    def __getattr__(self,name):\n        return None\n'
+         for sub in self.subscopes:
+             str += sub.get_code()
+@@ -378,7 +379,7 @@ class Class(Scope):
+                        if _DOTTED_NAME_RE.match(s.strip())]
+         if len(safe_supers) > 0: str += '(%s)' % ','.join(safe_supers)
+         str += ':\n'
+-        if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
++        if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n'
+         if len(self.subscopes) > 0:
+             for s in self.subscopes: str += s.get_code()
+         else:
+@@ -401,7 +402,7 @@ class Function(Scope):
+         safe_params = [p for p in safe_params if p]
+         str = "%sdef %s(%s):\n" % \
+             (self.currentindent(),self.name,','.join(safe_params))
+-        if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
++        if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n'
+         str += "%spass\n" % self.childindent()
+         return str
+ 
+diff --git a/runtime/autoload/pythoncomplete.vim b/runtime/autoload/pythoncomplete.vim
+index 39b1efd299..d2f5d57b0c 100644
+--- a/runtime/autoload/pythoncomplete.vim
++++ b/runtime/autoload/pythoncomplete.vim
+@@ -2,7 +2,7 @@
+ " Maintainer: <vacancy>
+ " Previous Maintainer: Aaron Griffin <aaronmgriffin@gmail.com>
+ " Version: 0.10
+-" Last Updated: 2026 Jun 04
++" Last Updated: 2026 Jun 21
+ "
+ " Changes
+ " TODO:
+@@ -20,6 +20,7 @@
+ "     previous code passed buffer-supplied expressions to exec() which
+ "     Python evaluates at definition time, allowing arbitrary code
+ "     execution via crafted def/class headers
++"   * use repr() on doc strings to prevent code execution
+ "
+ " v 0.9
+ "   * Fixed docstring parsing for classes and functions
+@@ -350,7 +351,7 @@ class Scope(object):
+ 
+     def get_code(self):
+         str = ""
+-        if len(self.docstr) > 0: str += '"""'+self.docstr+'"""\n'
++        if len(self.docstr) > 0: str += repr(self.docstr)+'\n'
+         str += 'class _PyCmplNoType:\n    def __getattr__(self,name):\n        return None\n'
+         for sub in self.subscopes:
+             str += sub.get_code()
+@@ -393,7 +394,7 @@ class Class(Scope):
+                        if _DOTTED_NAME_RE.match(s.strip())]
+         if len(safe_supers) > 0: str += '(%s)' % ','.join(safe_supers)
+         str += ':\n'
+-        if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
++        if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n'
+         if len(self.subscopes) > 0:
+             for s in self.subscopes: str += s.get_code()
+         else:
+@@ -416,7 +417,7 @@ class Function(Scope):
+         safe_params = [p for p in safe_params if p]
+         str = "%sdef %s(%s):\n" % \
+             (self.currentindent(),self.name,','.join(safe_params))
+-        if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
++        if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n'
+         str += "%spass\n" % self.childindent()
+         return str
+ 
+diff --git a/src/testdir/test_plugin_python3complete.vim b/src/testdir/test_plugin_python3complete.vim
+index e2b0c6616d..590348ee4a 100644
+--- a/src/testdir/test_plugin_python3complete.vim
++++ b/src/testdir/test_plugin_python3complete.vim
+@@ -221,4 +221,19 @@ func Test_python3complete_allow_import_on_runs_imports()
+         \ 'g:pythoncomplete_allow_import=1 did not run the buffer import')
+ endfunc
+ 
++func Test_python3complete_no_exec_via_class_docstring()
++  " A class-body docstring is emitted verbatim between triple quotes by
++  " get_code() and runs at class-definition time during exec().  A single-
++  " quoted source docstring lets an embedded """ survive doc()'s leading/
++  " trailing quote strip and break out of the generated literal.
++  let marker = tempname()
++  call s:CompleteAndExpectNoMarker([
++        \ 'class Foo:',
++        \ '    ''x"""+open("' . marker . '", "w").close()+"""y''',
++        \ '    pass',
++        \ 'Foo.',
++        \ ], marker,
++        \ 'class docstring expression was evaluated during omni-completion')
++endfunc
++
+ " vim: shiftwidth=2 sts=2 expandtab
+-- 
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index dec5b68324..008dbdb8df 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -29,6 +29,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-57451.patch \
            file://CVE-2026-57454.patch \
            file://CVE-2026-57455.patch \
+           file://CVE-2026-57456.patch \
            "
 
 PV .= ".0340"
-- 
2.43.0



^ permalink raw reply related	[flat|nested] 15+ messages in thread

* [OE-core][wrynose][patch 08/10] vim: Fix CVE-2026-59856
  2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
                   ` (5 preceding siblings ...)
  2026-07-22 12:33 ` [OE-core][wrynose][patch 07/10] vim: Fix CVE-2026-57456 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
  2026-07-22 12:33 ` [OE-core][wrynose][patch 09/10] vim: Fix CVE-2026-59857 Vijay Anusuri
  2026-07-22 12:33 ` [OE-core][wrynose][patch 10/10] vim: Fix CVE-2026-59858 Vijay Anusuri
  8 siblings, 0 replies; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
  To: openembedded-core; +Cc: Vijay Anusuri

Pick patch per [1].

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-59856
[2] https://security-tracker.debian.org/tracker/CVE-2026-59856

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
 .../vim/files/CVE-2026-59856.patch            | 103 ++++++++++++++++++
 meta/recipes-support/vim/vim.inc              |   1 +
 2 files changed, 104 insertions(+)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-59856.patch

diff --git a/meta/recipes-support/vim/files/CVE-2026-59856.patch b/meta/recipes-support/vim/files/CVE-2026-59856.patch
new file mode 100644
index 0000000000..42636161d0
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-59856.patch
@@ -0,0 +1,103 @@
+From 43afc581a37a35762dd0ef292f038b9dc5680a24 Mon Sep 17 00:00:00 2001
+From: Hirohito Higashi <h.east.727@gmail.com>
+Date: Fri, 26 Jun 2026 20:07:01 +0900
+Subject: [PATCH] patch 9.2.0736: potential command execution in PHP
+ omni-completion
+
+Problem:  With PHP omni-completion, a crafted file can potentially
+          execute arbitrary commands when completing a class member.
+Solution: Quote the class name before inserting it into the search()
+          pattern run via win_execute().
+
+Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
+Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/43afc581a37a35762dd0ef292f038b9dc5680a24]
+CVE: CVE-2026-59856
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ runtime/autoload/phpcomplete.vim        |  3 ++-
+ src/testdir/Make_all.mak                |  2 ++
+ src/testdir/test_plugin_phpcomplete.vim | 35 +++++++++++++++++++++++++
+ 3 files changed, 39 insertions(+), 1 deletion(-)
+ create mode 100644 src/testdir/test_plugin_phpcomplete.vim
+
+diff --git a/runtime/autoload/phpcomplete.vim b/runtime/autoload/phpcomplete.vim
+index 5b4263ae45..ec54352586 100644
+--- a/runtime/autoload/phpcomplete.vim
++++ b/runtime/autoload/phpcomplete.vim
+@@ -2082,7 +2082,8 @@ function! phpcomplete#GetClassContentsStructure(file_path, file_lines, class_nam
+ 	let result = []
+ 	let popup_id = popup_create(a:file_lines, {'hidden': v:true})
+ 
+-	call win_execute(popup_id, 'call search(''\c\(class\|interface\|trait\)\_s\+'.a:class_name.'\(\>\|$\)'')')
++	call win_execute(popup_id, 'call search('
++	    \ . string('\c\(class\|interface\|trait\)\_s\+' . a:class_name . '\(\>\|$\)') . ')')
+ 	call win_execute(popup_id, "let cfline = line('.')")
+ 	call win_execute(popup_id, "call search('{')")
+ 	call win_execute(popup_id, "let endline = line('.')")
+diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak
+index b06d1af431..b5735b6c3c 100644
+--- a/src/testdir/Make_all.mak
++++ b/src/testdir/Make_all.mak
+@@ -250,6 +250,7 @@ NEW_TESTS = \
+ 	test_plugin_man \
+ 	test_plugin_matchparen \
+ 	test_plugin_netrw \
++	test_plugin_phpcomplete \
+ 	test_plugin_python3complete \
+ 	test_plugin_osc52 \
+ 	test_plugin_tar \
+@@ -529,6 +530,7 @@ NEW_TESTS_RES = \
+ 	test_plugin_man.res \
+ 	test_plugin_matchparen.res \
+ 	test_plugin_netrw.res \
++	test_plugin_phpcomplete.res \
+ 	test_plugin_python3complete.res \
+ 	test_plugin_osc52.res \
+ 	test_plugin_tar.res \
+diff --git a/src/testdir/test_plugin_phpcomplete.vim b/src/testdir/test_plugin_phpcomplete.vim
+new file mode 100644
+index 0000000000..7f66be47b7
+--- /dev/null
++++ b/src/testdir/test_plugin_phpcomplete.vim
+@@ -0,0 +1,35 @@
++" Tests for the PHP omni-completion plugin (runtime/autoload/phpcomplete.vim).
++
++" A buffer class name is interpolated into a search() pattern run via
++" win_execute().  Without escaping, "'" closes the string and "|" starts a new
++" Ex command, so the name runs as an Ex command during completion.
++func Test_phpcomplete_no_exec_via_class_name()
++  unlet! g:phpcomplete_injected
++  let lines = ['<?php', 'class x {}', '']
++  let payload = "x')|let g:phpcomplete_injected = 1|call search('"
++
++  try
++    call phpcomplete#GetClassContentsStructure('x.php', lines, payload)
++  catch
++  endtry
++
++  call assert_false(exists('g:phpcomplete_injected'),
++        \ 'class name was executed as an Ex command during completion')
++
++  unlet! g:phpcomplete_injected
++endfunc
++
++func Test_phpcomplete_class_lookup_still_works()
++  let lines = ['<?php', 'class Foo {', '    public $bar;', '}', '']
++  let result = phpcomplete#GetClassContentsStructure('Foo.php', lines, 'Foo')
++
++  call assert_equal(type([]), type(result),
++        \ 'GetClassContentsStructure did not return a list')
++  call assert_true(len(result) > 0, 'no class structure returned')
++  call assert_match('class Foo', result[0].content,
++        \ 'class body missing from returned content')
++  call assert_match('bar', result[0].content,
++        \ 'class member missing from returned content')
++endfunc
++
++" vim: shiftwidth=2 sts=2 expandtab
+-- 
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 008dbdb8df..b9f8e40a28 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -30,6 +30,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-57454.patch \
            file://CVE-2026-57455.patch \
            file://CVE-2026-57456.patch \
+           file://CVE-2026-59856.patch \
            "
 
 PV .= ".0340"
-- 
2.43.0



^ permalink raw reply related	[flat|nested] 15+ messages in thread

* [OE-core][wrynose][patch 09/10] vim: Fix CVE-2026-59857
  2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
                   ` (6 preceding siblings ...)
  2026-07-22 12:33 ` [OE-core][wrynose][patch 08/10] vim: Fix CVE-2026-59856 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
  2026-07-22 12:33 ` [OE-core][wrynose][patch 10/10] vim: Fix CVE-2026-59858 Vijay Anusuri
  8 siblings, 0 replies; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
  To: openembedded-core; +Cc: Vijay Anusuri

Pick patch per [1].

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-59857
[2] https://security-tracker.debian.org/tracker/CVE-2026-59857

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
 .../vim/files/CVE-2026-59857.patch            | 110 ++++++++++++++++++
 meta/recipes-support/vim/vim.inc              |   1 +
 2 files changed, 111 insertions(+)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-59857.patch

diff --git a/meta/recipes-support/vim/files/CVE-2026-59857.patch b/meta/recipes-support/vim/files/CVE-2026-59857.patch
new file mode 100644
index 0000000000..aa1f0725b5
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-59857.patch
@@ -0,0 +1,110 @@
+From d22ff1c955ff87e8273210eae125aab0e85b6c30 Mon Sep 17 00:00:00 2001
+From: Hirohito Higashi <h.east.727@gmail.com>
+Date: Mon, 22 Jun 2026 13:00:36 +0900
+Subject: [PATCH] patch 9.2.0725: [security]: Stack out-of-bounds write in
+ spell_soundfold_sal()
+
+Problem:  [security]: A crafted spell file with non-collapsing SAL rules
+          can make soundfold() write one byte past the end of the
+          MAXWLEN result buffer.  This is the same class of
+          out-of-bounds write as GHSA-q8mh-6qm3-25g4 (fixed in 9.2.0698
+          for the SOFO branch), found while auditing the surrounding
+          code.
+Solution: Bound the single-byte SAL result writes and the terminating
+          NUL to MAXWLEN - 1, matching the SOFO branch.
+
+The single-byte branch of spell_soundfold_sal() guarded its writes with
+"reslen < MAXWLEN", allowing reslen to reach MAXWLEN (254).  The trailing
+"res[reslen] = NUL" then wrote at index 254 of the 254-byte stack buffer
+res[MAXWLEN], an off-by-one out-of-bounds write.  Input is case-folded to
+about 253 characters, so a 253-character argument together with a SAL map
+that does not collapse (collapse_result false) reaches the boundary.
+
+Related to previous issue
+[GHSA-q8mh-6qm3-25g4](https://github.com/vim/vim/security/advisories/GHSA-q8mh-6qm3-25g4)
+(9.2.0698)
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-m3hf-xcm3-xhm2
+
+Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
+Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/d22ff1c955ff87e8273210eae125aab0e85b6c30]
+CVE: CVE-2026-59857
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/spell.c                    |  6 +++---
+ src/testdir/test_spellfile.vim | 24 ++++++++++++++++++++++++
+ 2 files changed, 27 insertions(+), 3 deletions(-)
+
+diff --git a/src/spell.c b/src/spell.c
+index 060a2251a4..43a83ce7dc 100644
+--- a/src/spell.c
++++ b/src/spell.c
+@@ -3513,7 +3513,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res)
+ 			// no '<' rule used
+ 			i += k - 1;
+ 			z = 0;
+-			while (*s != NUL && s[1] != NUL && reslen < MAXWLEN)
++			while (*s != NUL && s[1] != NUL && reslen < MAXWLEN - 1)
+ 			{
+ 			    if (reslen == 0 || res[reslen - 1] != *s)
+ 				res[reslen++] = *s;
+@@ -3523,7 +3523,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res)
+ 			c = *s;
+ 			if (strstr((char *)pf, "^^") != NULL)
+ 			{
+-			    if (c != NUL)
++			    if (c != NUL && reslen < MAXWLEN - 1)
+ 				res[reslen++] = c;
+ 			    STRMOVE(word, word + i + 1);
+ 			    i = 0;
+@@ -3542,7 +3542,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res)
+ 
+ 	if (z0 == 0)
+ 	{
+-	    if (k && !p0 && reslen < MAXWLEN && c != NUL
++	    if (k && !p0 && reslen < MAXWLEN - 1 && c != NUL
+ 		    && (!slang->sl_collapse || reslen == 0
+ 						     || res[reslen - 1] != c))
+ 		// condense only double letters
+diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim
+index c0c46a32d2..a9bccc6491 100644
+--- a/src/testdir/test_spellfile.vim
++++ b/src/testdir/test_spellfile.vim
+@@ -387,6 +387,30 @@ func Test_spellfile_format_error()
+   let &rtp = save_rtp
+ endfunc
+ 
++" An over-length soundfold() argument must not overflow the MAXWLEN result
++" buffer in the single-byte branch of spell_soundfold_sal().
++func Test_spellfile_soundfold_sal_overflow()
++  let save_enc = &encoding
++  set encoding=latin1
++  " A SAL map that appends without collapsing, so the result is not shorter
++  " than the input.
++  call writefile(['SET ISO8859-1', 'SAL collapse_result false',
++	\ 'SAL a aaaa', 'SAL b bbbb'], 'Xsal.aff')
++  call writefile(['2', 'hello', 'world'], 'Xsal.dic')
++  mkspell! Xsal Xsal
++  set spl=Xsal.latin1.spl spell
++
++  " 253 input characters hit the buffer boundary; the result must not exceed
++  " MAXWLEN - 1.
++  call assert_true(strlen(soundfold(repeat('a', 253))) <= 253)
++
++  set nospell spl& spelllang&
++  call delete('Xsal.aff')
++  call delete('Xsal.dic')
++  call delete('Xsal.latin1.spl')
++  let &encoding = save_enc
++endfunc
++
+ " Test for format errors in suggest file
+ func Test_sugfile_format_error()
+   let save_rtp = &rtp
+-- 
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index b9f8e40a28..ab7564c3b6 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -31,6 +31,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-57455.patch \
            file://CVE-2026-57456.patch \
            file://CVE-2026-59856.patch \
+           file://CVE-2026-59857.patch \
            "
 
 PV .= ".0340"
-- 
2.43.0



^ permalink raw reply related	[flat|nested] 15+ messages in thread

* [OE-core][wrynose][patch 10/10] vim: Fix CVE-2026-59858
  2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
                   ` (7 preceding siblings ...)
  2026-07-22 12:33 ` [OE-core][wrynose][patch 09/10] vim: Fix CVE-2026-59857 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
  2026-08-26 14:55   ` Vijay Anusuri
  8 siblings, 1 reply; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
  To: openembedded-core; +Cc: Vijay Anusuri

Pick patch per [1].

[1] https://nvd.nist.gov/vuln/detail/CVE-2026-59858
[2] https://security-tracker.debian.org/tracker/CVE-2026-59858

Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
 .../vim/files/CVE-2026-59858.patch            | 134 ++++++++++++++++++
 meta/recipes-support/vim/vim.inc              |   1 +
 2 files changed, 135 insertions(+)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-59858.patch

diff --git a/meta/recipes-support/vim/files/CVE-2026-59858.patch b/meta/recipes-support/vim/files/CVE-2026-59858.patch
new file mode 100644
index 0000000000..a2b903be04
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-59858.patch
@@ -0,0 +1,134 @@
+From 6b611b0d15603c52ebdad17172b0232b4f65704e Mon Sep 17 00:00:00 2001
+From: Hirohito Higashi <h.east.727@gmail.com>
+Date: Fri, 26 Jun 2026 15:41:24 +0900
+Subject: [PATCH] patch 9.2.0735: [security]: arbitrary Ex command execution
+ during C omni-completion
+
+Problem:  [security]: With C omni-completion, a crafted tags file can execute
+          arbitrary Ex commands when completing a struct/union member
+          (cipher-creator)
+Solution: Escape the type field before inserting it into the :vimgrep
+          pattern so it cannot close the pattern and start a new command
+          (Hirohito Higashi).
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-mf92-v4xw-j45x
+
+Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>"
+Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/6b611b0d15603c52ebdad17172b0232b4f65704e]
+CVE: CVE-2026-59858
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ runtime/autoload/ccomplete.vim        |  2 +-
+ src/testdir/Make_all.mak              |  2 +
+ src/testdir/test_plugin_ccomplete.vim | 62 +++++++++++++++++++++++++++
+ 3 files changed, 65 insertions(+), 1 deletion(-)
+ create mode 100644 src/testdir/test_plugin_ccomplete.vim
+
+diff --git a/runtime/autoload/ccomplete.vim b/runtime/autoload/ccomplete.vim
+index 51237be98b..dc3388b524 100644
+--- a/runtime/autoload/ccomplete.vim
++++ b/runtime/autoload/ccomplete.vim
+@@ -600,7 +600,7 @@ def StructMembers( # {{{1
+         return []
+       endif
+       execute 'silent! keepjumps noautocmd '
+-        .. n .. 'vimgrep ' .. '/\t' .. typename .. '\(\t\|$\)/j '
++        .. n .. 'vimgrep ' .. '/\t' .. escape(typename, '/\') .. '\(\t\|$\)/j '
+         .. fnames
+ 
+       qflist = getqflist()
+diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak
+index b5735b6c3c..0cf2c41102 100644
+--- a/src/testdir/Make_all.mak
++++ b/src/testdir/Make_all.mak
+@@ -243,6 +243,7 @@ NEW_TESTS = \
+ 	test_partial \
+ 	test_paste \
+ 	test_perl \
++	test_plugin_ccomplete \
+ 	test_plugin_comment \
+ 	test_plugin_glvs \
+ 	test_plugin_helpcurwin \
+@@ -523,6 +524,7 @@ NEW_TESTS_RES = \
+ 	test_partial.res \
+ 	test_paste.res \
+ 	test_perl.res \
++	test_plugin_ccomplete.res \
+ 	test_plugin_comment.res \
+ 	test_plugin_glvs.res \
+ 	test_plugin_helpcurwin.res \
+diff --git a/src/testdir/test_plugin_ccomplete.vim b/src/testdir/test_plugin_ccomplete.vim
+new file mode 100644
+index 0000000000..a635bd50bd
+--- /dev/null
++++ b/src/testdir/test_plugin_ccomplete.vim
+@@ -0,0 +1,62 @@
++" Tests for the C omni-completion plugin (runtime/autoload/ccomplete.vim).
++
++func s:WriteTags(lines)
++  " Mark unsorted so lookup is a linear scan regardless of entry order.
++  let tagsfile = tempname()
++  call writefile(["!_TAG_FILE_SORTED\t0\t/0/"] + a:lines, tagsfile)
++  return tagsfile
++endfunc
++
++" A crafted typeref field is interpolated into the :vimgrep pattern in
++" StructMembers().  Without escaping, "/" closes the pattern and "|" starts a
++" new Ex command, so the field runs as an Ex command during completion.
++func Test_ccomplete_no_exec_via_typeref()
++  unlet! g:ccomplete_injected
++  let tagsfile = s:WriteTags([
++        \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:x/|let g:ccomplete_injected = 1|\"",
++        \ ])
++
++  let save_tags = &tags
++  let &tags = tagsfile
++
++  new
++  call ccomplete#Complete(1, '')
++  call ccomplete#Complete(0, 'myvar.x')
++
++  call assert_false(exists('g:ccomplete_injected'),
++        \ 'typeref field was executed as an Ex command during omni-completion')
++
++  bwipe!
++  let &tags = save_tags
++  unlet! g:ccomplete_injected
++endfunc
++
++" A legitimate typeref must still drive struct-member completion: escaping the
++" field value must not break the normal path.
++func Test_ccomplete_typeref_completion_still_works()
++  let tagsfile = s:WriteTags([
++        \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:struct:mystruct",
++        \ "alpha\tmain.c\t/^x$/;\"\tm\tstruct:mystruct",
++        \ "beta\tmain.c\t/^x$/;\"\tm\tstruct:mystruct",
++        \ ])
++
++  let save_tags = &tags
++  let &tags = tagsfile
++
++  new
++  call ccomplete#Complete(1, '')
++  let items = ccomplete#Complete(0, 'myvar.')
++
++  call assert_equal(type([]), type(items),
++        \ 'ccomplete#Complete did not return a list')
++  let names = map(copy(items), 'v:val.word')
++  call assert_true(index(names, 'alpha') >= 0,
++        \ 'struct member "alpha" missing from completion: ' . string(names))
++  call assert_true(index(names, 'beta') >= 0,
++        \ 'struct member "beta" missing from completion: ' . string(names))
++
++  bwipe!
++  let &tags = save_tags
++endfunc
++
++" vim: shiftwidth=2 sts=2 expandtab
+-- 
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index ab7564c3b6..0642393db3 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -32,6 +32,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-57456.patch \
            file://CVE-2026-59856.patch \
            file://CVE-2026-59857.patch \
+           file://CVE-2026-59858.patch \
            "
 
 PV .= ".0340"
-- 
2.43.0



^ permalink raw reply related	[flat|nested] 15+ messages in thread

* Re: [OE-core][wrynose][patch 03/10] vim: Fix CVE-2026-57453
  2026-07-22 12:33 ` [OE-core][wrynose][patch 03/10] vim: Fix CVE-2026-57453 Vijay Anusuri
@ 2026-07-26 21:45   ` Yoann Congal
  0 siblings, 0 replies; 15+ messages in thread
From: Yoann Congal @ 2026-07-26 21:45 UTC (permalink / raw)
  To: vanusuri, openembedded-core

On Wed Jul 22, 2026 at 2:33 PM CEST, Vijay Anusuri via lists.openembedded.org wrote:
> Pick patch per [1].
>
> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57453
> [2] https://github.com/vim/vim/security/advisories/GHSA-x5fg-h5w9-9frf
>
> Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> ---
>  .../vim/files/CVE-2026-57453.patch            | 248 ++++++++++++++++++
>  meta/recipes-support/vim/vim.inc              |   1 +
>  2 files changed, 249 insertions(+)
>  create mode 100644 meta/recipes-support/vim/files/CVE-2026-57453.patch
>
> diff --git a/meta/recipes-support/vim/files/CVE-2026-57453.patch b/meta/recipes-support/vim/files/CVE-2026-57453.patch
> new file mode 100644
> index 0000000000..d1ad6d6f54
> --- /dev/null
> +++ b/meta/recipes-support/vim/files/CVE-2026-57453.patch
> @@ -0,0 +1,248 @@
> +From b2cc9be119d51212bf0d3f2a994c7e517c73f4a9 Mon Sep 17 00:00:00 2001
> +From: Christian Brabandt <cb@256bit.org>
> +Date: Sat, 20 Jun 2026 15:35:58 +0000
> +Subject: [PATCH] patch 9.2.0678: [security]: potential powershell code
> + execution in zip.vim
> +
> +Problem:  [security]: potential powershell code execution in zip.vim
> +          (DDugs)
> +Solution: Cleanup zip.vim, introduce PSEscape() to escape() potential powershell code,
> +          use consistent s:Escape() in the various PowerShell functions
> +
> +Github Security Advisory:
> +https://github.com/vim/vim/security/advisories/GHSA-x5fg-h5w9-9frf
> +
> +Signed-off-by: Christian Brabandt <cb@256bit.org>
> +
> +Upstream-Status: Backport [https://github.com/vim/vim/commit/b2cc9be119d51212bf0d3f2a994c7e517c73f4a9]
> +CVE: CVE-2026-57453
> +Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> +---
> + runtime/autoload/zip.vim | 78 +++++++++++++++++++---------------------
> + runtime/doc/pi_zip.txt   | 10 ------
> + 2 files changed, 36 insertions(+), 52 deletions(-)
> +
> +diff --git a/runtime/autoload/zip.vim b/runtime/autoload/zip.vim
> +index f4482fd7fc..752503a626 100644
> +--- a/runtime/autoload/zip.vim
> ++++ b/runtime/autoload/zip.vim
> [...]
> +@@ -339,9 +331,9 @@ fun! zip#Read(fname,mode)
> +   let temp = tempname()
> +   let fn   = expand('%:p')
> + 
> +-  let gnu_cmd = g:zip_unzipcmd . ' -p -- ' . s:Escape(zipfile, 0) . ' ' . s:Escape(fname, 0) . ' > ' . s:Escape(temp, 0)
> +-  let gnu_cmd = 'call system(''' . substitute(gnu_cmd, "'", "''", 'g') . ''')'
> +-  let ps_cmd = 'sil !' . s:ZipReadPS(zipfile, fname, temp)
> ++  let gnu_cmd = g:zip_unzipcmd . ' -p -- ' . s:Escape(zipfile) . ' ' . s:Escape(fname) . ' > ' . s:Escape(temp)
> ++  let gnu_cmd = 'call system(' . string(gnu_cmd) . ')'
> ++  let ps_cmd = $"call system({string(s:ZipDeleteFilePS(zipfile, fname))})"
The above line changed from the upstream commit? Can you explain why?

The change is:
-+  let ps_cmd = 'call system(' . string(s:ZipReadPS(zipfile, fname, temp)) . ')'
++  let ps_cmd = $"call system({string(s:ZipDeleteFilePS(zipfile, fname))})"

In the meantime, I'll hold this patch but continue to review the
reminder of the series (hoping those CVE fixes are independant enought
to avoid a conflict).
-- 
Yoann Congal
Smile ECS



^ permalink raw reply	[flat|nested] 15+ messages in thread

* Re: [OE-core][wrynose][patch 04/10] vim: Fix CVE-2026-57451
  2026-07-22 12:33 ` [OE-core][wrynose][patch 04/10] vim: Fix CVE-2026-57451 Vijay Anusuri
@ 2026-07-26 21:53   ` Yoann Congal
  0 siblings, 0 replies; 15+ messages in thread
From: Yoann Congal @ 2026-07-26 21:53 UTC (permalink / raw)
  To: vanusuri, openembedded-core

On Wed Jul 22, 2026 at 2:33 PM CEST, Vijay Anusuri via lists.openembedded.org wrote:
> Pick patch per [1].
>
> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57451
> [2] https://github.com/vim/vim/security/advisories/GHSA-f36c-2qcp-7gpw
>
> Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> ---
>  .../vim/files/CVE-2026-57451.patch            | 177 ++++++++++++++++++
>  meta/recipes-support/vim/vim.inc              |   1 +
>  2 files changed, 178 insertions(+)
>  create mode 100644 meta/recipes-support/vim/files/CVE-2026-57451.patch
>
> diff --git a/meta/recipes-support/vim/files/CVE-2026-57451.patch b/meta/recipes-support/vim/files/CVE-2026-57451.patch
> new file mode 100644
> index 0000000000..22a0cfc03e
> --- /dev/null
> +++ b/meta/recipes-support/vim/files/CVE-2026-57451.patch
> @@ -0,0 +1,177 @@
> +From b2338ca90643e2f01ecb6547c1172716aaec4f79 Mon Sep 17 00:00:00 2001
> +From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
> +Date: Wed, 17 Jun 2026 21:06:59 +0000
> +Subject: [PATCH] patch 9.2.0670: [security]: Out-of-bounds read with text
> + properties
> +
> +Problem:  [security]: Out-of-bounds read with text properties
> +          (cipher-creator)
> +Solution: Add out-of-bound checks (Yasuhiro Matsumoto)
> +
> +Github Security Advisory:
> +https://github.com/vim/vim/security/advisories/GHSA-f36c-2qcp-7gpw
> +
> +Supported by AI
> +
> +Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
> +Signed-off-by: Christian Brabandt <cb@256bit.org>
> +
> +Upstream-Status: Backport [https://github.com/vim/vim/commit/b2338ca90643e2f01ecb6547c1172716aaec4f79]
> +CVE: CVE-2026-57451
> +Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> +---
> + src/memline.c                  |  7 ++++
> + src/proto/textprop.pro         |  1 +
> + src/testdir/test_textprop2.vim | 59 ++++++++++++++++++++++++++++++++++
> + src/textprop.c                 | 20 ++++++++++++
> + 4 files changed, 87 insertions(+)

Indentation was changed between upstream patch and this patch.
Don't keep the upstream indentation. (Even if unfortunate I admit...)

Regards,
-- 
Yoann Congal
Smile ECS



^ permalink raw reply	[flat|nested] 15+ messages in thread

* Re: [OE-core][wrynose][patch 05/10] vim: Fix CVE-2026-57454
  2026-07-22 12:33 ` [OE-core][wrynose][patch 05/10] vim: Fix CVE-2026-57454 Vijay Anusuri
@ 2026-07-26 22:05   ` Yoann Congal
  0 siblings, 0 replies; 15+ messages in thread
From: Yoann Congal @ 2026-07-26 22:05 UTC (permalink / raw)
  To: vanusuri, openembedded-core

On Wed Jul 22, 2026 at 2:33 PM CEST, Vijay Anusuri via lists.openembedded.org wrote:
> Pick patch per [1].
>
> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57454
> [2] https://security-tracker.debian.org/tracker/CVE-2026-57454
>
> Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> ---
>  .../vim/files/CVE-2026-57454.patch            | 188 ++++++++++++++++++
>  meta/recipes-support/vim/vim.inc              |   1 +
>  2 files changed, 189 insertions(+)
>  create mode 100644 meta/recipes-support/vim/files/CVE-2026-57454.patch
>
> diff --git a/meta/recipes-support/vim/files/CVE-2026-57454.patch b/meta/recipes-support/vim/files/CVE-2026-57454.patch
> new file mode 100644
> index 0000000000..579ffbf11b
> --- /dev/null
> +++ b/meta/recipes-support/vim/files/CVE-2026-57454.patch
> @@ -0,0 +1,188 @@
> +From b3faeecc976d3031d7c0675623516ec60c30f949 Mon Sep 17 00:00:00 2001
> +From: Hirohito Higashi <h.east.727@gmail.com>
> +Date: Sat, 20 Jun 2026 16:06:58 +0000
> +Subject: [PATCH] patch 9.2.0679: [security]: Out-of-bounds read with text
> + property virtual text
> +
> +Problem:  [security]: Out-of-bounds read with text property virtual text.
> +          A crafted undo file can declare a virtual-text property whose
> +          offset points outside the line's property data, so reading the
> +          virtual text reads out of bounds.  This completes the count-only
> +          check added in 9.2.0670.
> +Solution: Validate the virtual-text offset and length of each property
> +          against the available property data before turning the offset
> +          into a pointer.
> +
> +Github Security Advisory:
> +https://github.com/vim/vim/security/advisories/GHSA-ww8h-47xp-hp4w
> +
> +Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
> +Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
> +Signed-off-by: Christian Brabandt <cb@256bit.org>
> +
> +Upstream-Status: Backport [https://github.com/vim/vim/commit/b3faeecc976d3031d7c0675623516ec60c30f949]
> +CVE: CVE-2026-57454
> +Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> +---
> + src/proto/textprop.pro         |  1 +
> + src/testdir/test_textprop2.vim | 60 ++++++++++++++++++++++++++++++----
> + src/textprop.c                 | 36 ++++++++++++++++++++
> + 3 files changed, 90 insertions(+), 7 deletions(-)

This patch also has indentation changes between upstream patch and this
patch.

I'll hold the whole series and let you check and correct the patches.

Please send a v2 of the whole series.

Thanks!
-- 
Yoann Congal
Smile ECS



^ permalink raw reply	[flat|nested] 15+ messages in thread

* Re: [OE-core][wrynose][patch 10/10] vim: Fix CVE-2026-59858
  2026-07-22 12:33 ` [OE-core][wrynose][patch 10/10] vim: Fix CVE-2026-59858 Vijay Anusuri
@ 2026-08-26 14:55   ` Vijay Anusuri
  2026-08-26 17:00     ` Yoann Congal
  0 siblings, 1 reply; 15+ messages in thread
From: Vijay Anusuri @ 2026-08-26 14:55 UTC (permalink / raw)
  To: openembedded-core, Yoann Congal, Fabien Thomas

[-- Attachment #1: Type: text/plain, Size: 6896 bytes --]

Hi Team,

Any update on this?

Thanks & Regards,
Vijay

On Wed, Jul 22, 2026 at 6:04 PM Vijay Anusuri <vanusuri@mvista.com> wrote:

> Pick patch per [1].
>
> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-59858
> [2] https://security-tracker.debian.org/tracker/CVE-2026-59858
>
> Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> ---
>  .../vim/files/CVE-2026-59858.patch            | 134 ++++++++++++++++++
>  meta/recipes-support/vim/vim.inc              |   1 +
>  2 files changed, 135 insertions(+)
>  create mode 100644 meta/recipes-support/vim/files/CVE-2026-59858.patch
>
> diff --git a/meta/recipes-support/vim/files/CVE-2026-59858.patch
> b/meta/recipes-support/vim/files/CVE-2026-59858.patch
> new file mode 100644
> index 0000000000..a2b903be04
> --- /dev/null
> +++ b/meta/recipes-support/vim/files/CVE-2026-59858.patch
> @@ -0,0 +1,134 @@
> +From 6b611b0d15603c52ebdad17172b0232b4f65704e Mon Sep 17 00:00:00 2001
> +From: Hirohito Higashi <h.east.727@gmail.com>
> +Date: Fri, 26 Jun 2026 15:41:24 +0900
> +Subject: [PATCH] patch 9.2.0735: [security]: arbitrary Ex command
> execution
> + during C omni-completion
> +
> +Problem:  [security]: With C omni-completion, a crafted tags file can
> execute
> +          arbitrary Ex commands when completing a struct/union member
> +          (cipher-creator)
> +Solution: Escape the type field before inserting it into the :vimgrep
> +          pattern so it cannot close the pattern and start a new command
> +          (Hirohito Higashi).
> +
> +Github Security Advisory:
> +https://github.com/vim/vim/security/advisories/GHSA-mf92-v4xw-j45x
> +
> +Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>"
> +Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
> +Signed-off-by: Christian Brabandt <cb@256bit.org>
> +
> +Upstream-Status: Backport [
> https://github.com/vim/vim/commit/6b611b0d15603c52ebdad17172b0232b4f65704e
> ]
> +CVE: CVE-2026-59858
> +Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> +---
> + runtime/autoload/ccomplete.vim        |  2 +-
> + src/testdir/Make_all.mak              |  2 +
> + src/testdir/test_plugin_ccomplete.vim | 62 +++++++++++++++++++++++++++
> + 3 files changed, 65 insertions(+), 1 deletion(-)
> + create mode 100644 src/testdir/test_plugin_ccomplete.vim
> +
> +diff --git a/runtime/autoload/ccomplete.vim
> b/runtime/autoload/ccomplete.vim
> +index 51237be98b..dc3388b524 100644
> +--- a/runtime/autoload/ccomplete.vim
> ++++ b/runtime/autoload/ccomplete.vim
> +@@ -600,7 +600,7 @@ def StructMembers( # {{{1
> +         return []
> +       endif
> +       execute 'silent! keepjumps noautocmd '
> +-        .. n .. 'vimgrep ' .. '/\t' .. typename .. '\(\t\|$\)/j '
> ++        .. n .. 'vimgrep ' .. '/\t' .. escape(typename, '/\') ..
> '\(\t\|$\)/j '
> +         .. fnames
> +
> +       qflist = getqflist()
> +diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak
> +index b5735b6c3c..0cf2c41102 100644
> +--- a/src/testdir/Make_all.mak
> ++++ b/src/testdir/Make_all.mak
> +@@ -243,6 +243,7 @@ NEW_TESTS = \
> +       test_partial \
> +       test_paste \
> +       test_perl \
> ++      test_plugin_ccomplete \
> +       test_plugin_comment \
> +       test_plugin_glvs \
> +       test_plugin_helpcurwin \
> +@@ -523,6 +524,7 @@ NEW_TESTS_RES = \
> +       test_partial.res \
> +       test_paste.res \
> +       test_perl.res \
> ++      test_plugin_ccomplete.res \
> +       test_plugin_comment.res \
> +       test_plugin_glvs.res \
> +       test_plugin_helpcurwin.res \
> +diff --git a/src/testdir/test_plugin_ccomplete.vim
> b/src/testdir/test_plugin_ccomplete.vim
> +new file mode 100644
> +index 0000000000..a635bd50bd
> +--- /dev/null
> ++++ b/src/testdir/test_plugin_ccomplete.vim
> +@@ -0,0 +1,62 @@
> ++" Tests for the C omni-completion plugin
> (runtime/autoload/ccomplete.vim).
> ++
> ++func s:WriteTags(lines)
> ++  " Mark unsorted so lookup is a linear scan regardless of entry order.
> ++  let tagsfile = tempname()
> ++  call writefile(["!_TAG_FILE_SORTED\t0\t/0/"] + a:lines, tagsfile)
> ++  return tagsfile
> ++endfunc
> ++
> ++" A crafted typeref field is interpolated into the :vimgrep pattern in
> ++" StructMembers().  Without escaping, "/" closes the pattern and "|"
> starts a
> ++" new Ex command, so the field runs as an Ex command during completion.
> ++func Test_ccomplete_no_exec_via_typeref()
> ++  unlet! g:ccomplete_injected
> ++  let tagsfile = s:WriteTags([
> ++        \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:x/|let
> g:ccomplete_injected = 1|\"",
> ++        \ ])
> ++
> ++  let save_tags = &tags
> ++  let &tags = tagsfile
> ++
> ++  new
> ++  call ccomplete#Complete(1, '')
> ++  call ccomplete#Complete(0, 'myvar.x')
> ++
> ++  call assert_false(exists('g:ccomplete_injected'),
> ++        \ 'typeref field was executed as an Ex command during
> omni-completion')
> ++
> ++  bwipe!
> ++  let &tags = save_tags
> ++  unlet! g:ccomplete_injected
> ++endfunc
> ++
> ++" A legitimate typeref must still drive struct-member completion:
> escaping the
> ++" field value must not break the normal path.
> ++func Test_ccomplete_typeref_completion_still_works()
> ++  let tagsfile = s:WriteTags([
> ++        \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:struct:mystruct",
> ++        \ "alpha\tmain.c\t/^x$/;\"\tm\tstruct:mystruct",
> ++        \ "beta\tmain.c\t/^x$/;\"\tm\tstruct:mystruct",
> ++        \ ])
> ++
> ++  let save_tags = &tags
> ++  let &tags = tagsfile
> ++
> ++  new
> ++  call ccomplete#Complete(1, '')
> ++  let items = ccomplete#Complete(0, 'myvar.')
> ++
> ++  call assert_equal(type([]), type(items),
> ++        \ 'ccomplete#Complete did not return a list')
> ++  let names = map(copy(items), 'v:val.word')
> ++  call assert_true(index(names, 'alpha') >= 0,
> ++        \ 'struct member "alpha" missing from completion: ' .
> string(names))
> ++  call assert_true(index(names, 'beta') >= 0,
> ++        \ 'struct member "beta" missing from completion: ' .
> string(names))
> ++
> ++  bwipe!
> ++  let &tags = save_tags
> ++endfunc
> ++
> ++" vim: shiftwidth=2 sts=2 expandtab
> +--
> +2.43.0
> +
> diff --git a/meta/recipes-support/vim/vim.inc
> b/meta/recipes-support/vim/vim.inc
> index ab7564c3b6..0642393db3 100644
> --- a/meta/recipes-support/vim/vim.inc
> +++ b/meta/recipes-support/vim/vim.inc
> @@ -32,6 +32,7 @@ SRC_URI = "git://
> github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
> <http://github.com/vim/vim.git;branch=master;protocol=https;tag=v$%7BPV%7D>
>             file://CVE-2026-57456.patch \
>             file://CVE-2026-59856.patch \
>             file://CVE-2026-59857.patch \
> +           file://CVE-2026-59858.patch \
>             "
>
>  PV .= ".0340"
> --
> 2.43.0
>
>

[-- Attachment #2: Type: text/html, Size: 8988 bytes --]

^ permalink raw reply	[flat|nested] 15+ messages in thread

* Re: [OE-core][wrynose][patch 10/10] vim: Fix CVE-2026-59858
  2026-08-26 14:55   ` Vijay Anusuri
@ 2026-08-26 17:00     ` Yoann Congal
  0 siblings, 0 replies; 15+ messages in thread
From: Yoann Congal @ 2026-08-26 17:00 UTC (permalink / raw)
  To: Vijay Anusuri, openembedded-core, Fabien Thomas

On Wed Aug 26, 2026 at 4:55 PM CEST, Vijay Anusuri wrote:
> Hi Team,
>
> Any update on this?

I've answered here: https://lore.kernel.org/all/DK8UE7TFOQNN.2W9IFP8L1S2MF@smile.fr/ :
> This patch also has indentation changes between upstream patch and this
> patch.
> 
> I'll hold the whole series and let you check and correct the patches.
> 
> Please send a v2 of the whole series.

Please note that in the meantime I've added another vim series to my
-nut branch (not reviewed yet)

Regards,

>
> Thanks & Regards,
> Vijay
>
> On Wed, Jul 22, 2026 at 6:04 PM Vijay Anusuri <vanusuri@mvista.com> wrote:
>
>> Pick patch per [1].
>>
>> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-59858
>> [2] https://security-tracker.debian.org/tracker/CVE-2026-59858
>>
>> Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
>> ---
>>  .../vim/files/CVE-2026-59858.patch            | 134 ++++++++++++++++++
>>  meta/recipes-support/vim/vim.inc              |   1 +
>>  2 files changed, 135 insertions(+)
>>  create mode 100644 meta/recipes-support/vim/files/CVE-2026-59858.patch
[...]

-- 
Yoann Congal
Smile ECS



^ permalink raw reply	[flat|nested] 15+ messages in thread

end of thread, other threads:[~2026-08-26 17:01 UTC | newest]

Thread overview: 15+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
2026-07-22 12:33 ` [OE-core][wrynose][patch 02/10] vim: Fix CVE-2026-55895 Vijay Anusuri
2026-07-22 12:33 ` [OE-core][wrynose][patch 03/10] vim: Fix CVE-2026-57453 Vijay Anusuri
2026-07-26 21:45   ` Yoann Congal
2026-07-22 12:33 ` [OE-core][wrynose][patch 04/10] vim: Fix CVE-2026-57451 Vijay Anusuri
2026-07-26 21:53   ` Yoann Congal
2026-07-22 12:33 ` [OE-core][wrynose][patch 05/10] vim: Fix CVE-2026-57454 Vijay Anusuri
2026-07-26 22:05   ` Yoann Congal
2026-07-22 12:33 ` [OE-core][wrynose][patch 06/10] vim: Fix CVE-2026-57455 Vijay Anusuri
2026-07-22 12:33 ` [OE-core][wrynose][patch 07/10] vim: Fix CVE-2026-57456 Vijay Anusuri
2026-07-22 12:33 ` [OE-core][wrynose][patch 08/10] vim: Fix CVE-2026-59856 Vijay Anusuri
2026-07-22 12:33 ` [OE-core][wrynose][patch 09/10] vim: Fix CVE-2026-59857 Vijay Anusuri
2026-07-22 12:33 ` [OE-core][wrynose][patch 10/10] vim: Fix CVE-2026-59858 Vijay Anusuri
2026-08-26 14:55   ` Vijay Anusuri
2026-08-26 17:00     ` Yoann Congal

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox