* [OE-core][wrynose][patch 02/10] vim: Fix CVE-2026-55895
2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
2026-07-22 12:33 ` [OE-core][wrynose][patch 03/10] vim: Fix CVE-2026-57453 Vijay Anusuri
` (7 subsequent siblings)
8 siblings, 0 replies; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
To: openembedded-core; +Cc: Vijay Anusuri
Pick patch per [1].
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-55895
[2] https://github.com/vim/vim/security/advisories/GHSA-vhh8-v6wx-hjjh
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
.../vim/files/CVE-2026-55895.patch | 83 +++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 84 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-55895.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-55895.patch b/meta/recipes-support/vim/files/CVE-2026-55895.patch
new file mode 100644
index 0000000000..cc335ea2a6
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-55895.patch
@@ -0,0 +1,83 @@
+From 55bc757a5d436e59d50fe43f7cda94b118f86cb2 Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Tue, 16 Jun 2026 21:00:28 +0000
+Subject: [PATCH] patch 9.2.0663: [security]: runtime(netrw): code injection in
+ local file deletion
+
+Problem: [security]: s:NetrwLocalRmFile() escapes only the backslash in
+ the file name before passing it to :execute, so a name
+ containing "|" injects arbitrary Ex commands when the file is
+ deleted (cipher-creator)
+Solution: Use fnameescape() to correctly escape the file name
+ (Yasuhiro Matsumoto).
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-vhh8-v6wx-hjjh
+
+Supported by AI
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/55bc757a5d436e59d50fe43f7cda94b118f86cb2]
+CVE: CVE-2026-55895
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ .../pack/dist/opt/netrw/autoload/netrw.vim | 4 ++--
+ src/testdir/test_plugin_netrw.vim | 20 +++++++++++++++++++
+ 2 files changed, 22 insertions(+), 2 deletions(-)
+
+diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim
+index 8e5fdb5397..ebb856800c 100644
+--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim
++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim
+@@ -3062,7 +3062,7 @@ function s:NetrwBrowse(islocal,dirname)
+ elseif !a:islocal && dirname !~ '[\/]$' && dirname !~ '^"'
+ " s:NetrwBrowse : remote regular file handler {{{3
+ if bufname(dirname) != ""
+- exe "NetrwKeepj b ".bufname(dirname)
++ exe "NetrwKeepj b ".fnameescape(bufname(dirname))
+ else
+ " attempt transfer of remote regular file
+
+@@ -8772,7 +8772,7 @@ function s:NetrwLocalRmFile(path, fname, all)
+ call netrw#msg#Notify('ERROR', printf("unable to delete <%s>!", rmfile))
+ else
+ " Remove file only if there are no pending changes
+- execute printf('silent! bwipeout %s', rmfile)
++ execute printf('silent! bwipeout %s', fnameescape(rmfile))
+ endif
+
+ elseif dir && (all || empty(ok))
+diff --git a/src/testdir/test_plugin_netrw.vim b/src/testdir/test_plugin_netrw.vim
+index b234670928..4d5fc9a065 100644
+--- a/src/testdir/test_plugin_netrw.vim
++++ b/src/testdir/test_plugin_netrw.vim
+@@ -609,4 +609,24 @@ func Test_netrw_RFC2396()
+ call assert_equal('a b', netrw#RFC2396(fname))
+ endfunc
+
++" Deleting a file whose name contains an Ex command separator must not let the
++" name inject commands into the :execute in s:NetrwLocalRmFile().
++func Test_netrw_local_rm_injection()
++ CheckUnix
++ let dir = getcwd() . '/Xnetrwrm'
++ let fname = "x|let g:injected = 1"
++ call mkdir(dir, 'pR')
++ call writefile([], dir . '/' . fname)
++ try
++ call netrw#Call('NetrwLocalRmFile', dir, fname, 1)
++ call assert_false(exists('g:injected'), 'filename must not inject Ex commands')
++ " The file is removed before the sink, so its absence also confirms the
++ " vulnerable code path was actually exercised (not skipped on an error).
++ call assert_false(filereadable(dir . '/' . fname), 'crafted file must be deleted')
++ finally
++ call delete(dir . '/' . fname)
++ unlet! g:injected
++ endtry
++endfunc
++
+ " vim:ts=8 sts=2 sw=2 et
+--
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index c0315dfed6..b9f6ef987c 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -24,6 +24,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
file://CVE-2026-52859.patch \
file://CVE-2026-52860.patch \
file://CVE-2026-55693.patch \
+ file://CVE-2026-55895.patch \
"
PV .= ".0340"
--
2.43.0
^ permalink raw reply related [flat|nested] 15+ messages in thread* [OE-core][wrynose][patch 03/10] vim: Fix CVE-2026-57453
2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
2026-07-22 12:33 ` [OE-core][wrynose][patch 02/10] vim: Fix CVE-2026-55895 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
2026-07-26 21:45 ` Yoann Congal
2026-07-22 12:33 ` [OE-core][wrynose][patch 04/10] vim: Fix CVE-2026-57451 Vijay Anusuri
` (6 subsequent siblings)
8 siblings, 1 reply; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
To: openembedded-core; +Cc: Vijay Anusuri
Pick patch per [1].
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57453
[2] https://github.com/vim/vim/security/advisories/GHSA-x5fg-h5w9-9frf
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
.../vim/files/CVE-2026-57453.patch | 248 ++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 249 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57453.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-57453.patch b/meta/recipes-support/vim/files/CVE-2026-57453.patch
new file mode 100644
index 0000000000..d1ad6d6f54
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-57453.patch
@@ -0,0 +1,248 @@
+From b2cc9be119d51212bf0d3f2a994c7e517c73f4a9 Mon Sep 17 00:00:00 2001
+From: Christian Brabandt <cb@256bit.org>
+Date: Sat, 20 Jun 2026 15:35:58 +0000
+Subject: [PATCH] patch 9.2.0678: [security]: potential powershell code
+ execution in zip.vim
+
+Problem: [security]: potential powershell code execution in zip.vim
+ (DDugs)
+Solution: Cleanup zip.vim, introduce PSEscape() to escape() potential powershell code,
+ use consistent s:Escape() in the various PowerShell functions
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-x5fg-h5w9-9frf
+
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/b2cc9be119d51212bf0d3f2a994c7e517c73f4a9]
+CVE: CVE-2026-57453
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ runtime/autoload/zip.vim | 78 +++++++++++++++++++---------------------
+ runtime/doc/pi_zip.txt | 10 ------
+ 2 files changed, 36 insertions(+), 52 deletions(-)
+
+diff --git a/runtime/autoload/zip.vim b/runtime/autoload/zip.vim
+index f4482fd7fc..752503a626 100644
+--- a/runtime/autoload/zip.vim
++++ b/runtime/autoload/zip.vim
+@@ -22,6 +22,7 @@
+ " 2026 Mar 08 by Vim Project: Make ZipUpdatePS() check for powershell
+ " 2026 Apr 01 by Vim Project: Detect more path traversal attacks
+ " 2026 Apr 05 by Vim Project: Detect more path traversal attacks
++" 2026 Jun 20 by Vim Project: Fix wrong escaping for the powershell calls
+ " License: Vim License (see vim's :help license)
+ " Copyright: Copyright (C) 2005-2019 Charles E. Campbell {{{1
+ " Permission is hereby granted to use and distribute this code,
+@@ -49,15 +50,6 @@ let s:NOTE = 0
+
+ " ---------------------------------------------------------------------
+ " Global Values: {{{1
+-if !exists("g:zip_shq")
+- if &shq != ""
+- let g:zip_shq= &shq
+- elseif has("unix")
+- let g:zip_shq= "'"
+- else
+- let g:zip_shq= '"'
+- endif
+-endif
+ if !exists("g:zip_zipcmd")
+ let g:zip_zipcmd= "zip"
+ endif
+@@ -133,7 +125,7 @@ function! s:ZipBrowsePS(zipfile)
+ " Browse the contents of a zip file using PowerShell's
+ " Equivalent `unzip -Z1 -- zipfile`
+ let cmds = [
+- \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:Escape(a:zipfile, 1) . ');',
++ \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:PSEscape(a:zipfile) . ');',
+ \ '$zip.Entries | ForEach-Object { $_.FullName };',
+ \ '$zip.Dispose()'
+ \ ]
+@@ -147,16 +139,16 @@ function! s:ZipReadPS(zipfile, fname, tempfile)
+ call s:Mess('WarningMsg', "***warning*** PowerShell can display, but cannot update, files in archive subfolders")
+ endif
+ let cmds = [
+- \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:Escape(a:zipfile, 1) . ');',
+- \ '$fileEntry = $zip.Entries | Where-Object { $_.FullName -eq ' . s:Escape(a:fname, 1) . ' };',
++ \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:PSEscape(a:zipfile) . ');',
++ \ '$fileEntry = $zip.Entries | Where-Object { $_.FullName -eq ' . s:PSEscape(a:fname) . ' };',
+ \ '$stream = $fileEntry.Open();',
+- \ '$fileStream = [System.IO.File]::Create(' . s:Escape(a:tempfile, 1) . ');',
++ \ '$fileStream = [System.IO.File]::Create(' . s:PSEscape(a:tempfile) . ');',
+ \ '$stream.CopyTo($fileStream);',
+ \ '$fileStream.Close();',
+ \ '$stream.Close();',
+ \ '$zip.Dispose()'
+ \ ]
+- return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' '), 1)
++ return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' '))
+ endfunction
+
+ function! s:ZipUpdatePS(zipfile, fname)
+@@ -166,7 +158,7 @@ function! s:ZipUpdatePS(zipfile, fname)
+ call s:Mess('Error', "***error*** PowerShell cannot update files in archive subfolders")
+ return ':'
+ endif
+- return 'Compress-Archive -Path ' . a:fname . ' -Update -DestinationPath ' . a:zipfile
++ return 'Compress-Archive -Path ' . s:PSEscape(a:fname) . ' -Update -DestinationPath ' . s:PSEscape(a:zipfile)
+ endfunction
+
+ function! s:ZipExtractFilePS(zipfile, fname)
+@@ -177,16 +169,16 @@ function! s:ZipExtractFilePS(zipfile, fname)
+ return ':'
+ endif
+ let cmds = [
+- \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:Escape(a:zipfile, 1) . ');',
+- \ '$fileEntry = $zip.Entries | Where-Object { $_.FullName -eq ' . a:fname . ' };',
++ \ '$zip = [System.IO.Compression.ZipFile]::OpenRead(' . s:PSEscape(a:zipfile) . ');',
++ \ '$fileEntry = $zip.Entries | Where-Object { $_.FullName -eq ' . s:PSEscape(a:fname) . ' };',
+ \ '$stream = $fileEntry.Open();',
+- \ '$fileStream = [System.IO.File]::Create(' . a:fname . ');',
++ \ '$fileStream = [System.IO.File]::Create(' . s:PSEscape(a:fname) . ');',
+ \ '$stream.CopyTo($fileStream);',
+ \ '$fileStream.Close();',
+ \ '$stream.Close();',
+ \ '$zip.Dispose()'
+ \ ]
+- return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' '), 1)
++ return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' '))
+ endfunction
+
+ function! s:ZipDeleteFilePS(zipfile, fname)
+@@ -194,12 +186,12 @@ function! s:ZipDeleteFilePS(zipfile, fname)
+ " Equivalent to `zip -d zipfile fname`
+ let cmds = [
+ \ 'Add-Type -AssemblyName System.IO.Compression.FileSystem;',
+- \ '$zip = [System.IO.Compression.ZipFile]::Open(' . s:Escape(a:zipfile, 1) . ', ''Update'');',
+- \ '$entry = $zip.Entries | Where-Object { $_.Name -eq ' . s:Escape(a:fname, 1) . ' };',
++ \ '$zip = [System.IO.Compression.ZipFile]::Open(' . s:PSEscape(a:zipfile) . ', ''Update'');',
++ \ '$entry = $zip.Entries | Where-Object { $_.Name -eq ' . s:PSEscape(a:fname) . ' };',
+ \ 'if ($entry) { $entry.Delete(); $zip.Dispose() }',
+ \ 'else { $zip.Dispose() }'
+ \ ]
+- return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' '), 1)
++ return 'pwsh -NoProfile -Command ' . s:Escape(join(cmds, ' '))
+ endfunction
+
+ " ----------------
+@@ -339,9 +331,9 @@ fun! zip#Read(fname,mode)
+ let temp = tempname()
+ let fn = expand('%:p')
+
+- let gnu_cmd = g:zip_unzipcmd . ' -p -- ' . s:Escape(zipfile, 0) . ' ' . s:Escape(fname, 0) . ' > ' . s:Escape(temp, 0)
+- let gnu_cmd = 'call system(''' . substitute(gnu_cmd, "'", "''", 'g') . ''')'
+- let ps_cmd = 'sil !' . s:ZipReadPS(zipfile, fname, temp)
++ let gnu_cmd = g:zip_unzipcmd . ' -p -- ' . s:Escape(zipfile) . ' ' . s:Escape(fname) . ' > ' . s:Escape(temp)
++ let gnu_cmd = 'call system(' . string(gnu_cmd) . ')'
++ let ps_cmd = $"call system({string(s:ZipDeleteFilePS(zipfile, fname))})"
+ call s:TryExecGnuFallBackToPs(g:zip_unzipcmd, gnu_cmd, ps_cmd)
+
+ sil exe 'keepalt file '.temp
+@@ -408,9 +400,9 @@ fun! zip#Write(fname)
+ " TODO: what to check on MS-Windows to avoid writing absolute paths?
+ endif
+ if fname =~ '^[.]\{1,2}/'
+- let gnu_cmd = g:zip_zipcmd . ' -d ' . s:Escape(fnamemodify(zipfile,":p"),0) . ' ' . s:Escape(fname,0)
+- let gnu_cmd = 'call system(''' . substitute(gnu_cmd, "'", "''", 'g') . ''')'
+- let ps_cmd = $"call system({s:Escape(s:ZipDeleteFilePS(zipfile, fname), 1)})"
++ let gnu_cmd = g:zip_zipcmd . ' -d ' . s:Escape(fnamemodify(zipfile,":p")) . ' ' . s:Escape(fname)
++ let gnu_cmd = 'call system(' . string(gnu_cmd) . ')'
++ let ps_cmd = $"call system({string(s:ZipDeleteFilePS(zipfile, fname))})"
+ call s:TryExecGnuFallBackToPs(g:zip_zipcmd, gnu_cmd, ps_cmd)
+ let fname = fname->substitute('^\([.]\{1,2}/\)\+', '', 'g')
+ let need_rename = 1
+@@ -419,7 +411,7 @@ fun! zip#Write(fname)
+ if fname =~ '/'
+ let dirpath = substitute(fname,'/[^/]\+$','','e')
+ if has("win32unix") && executable("cygpath")
+- let dirpath = substitute(system("cygpath ".s:Escape(dirpath,0)),'\n','','e')
++ let dirpath = substitute(system("cygpath ".s:Escape(dirpath)),'\n','','e')
+ endif
+ call mkdir(dirpath,"p")
+ endif
+@@ -430,16 +422,17 @@ fun! zip#Write(fname)
+ " don't overwrite files forcefully
+ exe "w ".fnameescape(fname)
+ if has("win32unix") && executable("cygpath")
+- let zipfile = substitute(system("cygpath ".s:Escape(zipfile,0)),'\n','','e')
++ let zipfile = substitute(system("cygpath ".s:Escape(zipfile)),'\n','','e')
+ endif
+
+ if (has("win32") || has("win95") || has("win64") || has("win16")) && &shell !~? 'sh$'
+ let fname = substitute(fname, '[', '[[]', 'g')
+ endif
+
+- let gnu_cmd = g:zip_zipcmd . ' -u '. s:Escape(fnamemodify(zipfile,":p"),0) . ' ' . s:Escape(fname,0)
++ let gnu_cmd = g:zip_zipcmd . ' -u '. s:Escape(fnamemodify(zipfile,":p")) . ' ' . s:Escape(fname)
+ let gnu_cmd = 'call system(''' . substitute(gnu_cmd, "'", "''", 'g') . ''')'
+- let ps_cmd = s:ZipUpdatePS(s:Escape(fnamemodify(zipfile, ':p'), 0), s:Escape(fname, 0))
++ let zip = fnamemodify(zipfile, ':p')
++ let ps_cmd = s:ZipUpdatePS(zip, fname)
+ let ps_cmd = 'call system(''' . substitute(ps_cmd, "'", "''", 'g') . ''')'
+ call s:TryExecGnuFallBackToPs(g:zip_zipcmd, gnu_cmd, ps_cmd)
+ if &shell =~ 'pwsh'
+@@ -522,8 +515,8 @@ fun! zip#Extract()
+
+ " extract the file mentioned under the cursor
+ let gnu_cmd = g:zip_extractcmd . ' -o '. shellescape(b:zipfile) . ' ' . target
+- let gnu_cmd = 'call system(''' . substitute(gnu_cmd, "'", "''", 'g') . ''')'
+- let ps_cmd = $"call system({s:Escape(s:ZipExtractFilePS(b:zipfile, target), 1)})"
++ let gnu_cmd = 'call system(' . string(gnu_cmd) . ')'
++ let ps_cmd = 'call system(' . string(s:ZipExtractFilePS(b:zipfile, fname)) . ')'
+ call s:TryExecGnuFallBackToPs(g:zip_extractcmd, gnu_cmd, ps_cmd)
+
+ if v:shell_error != 0
+@@ -537,19 +530,20 @@ endfun
+
+ " ---------------------------------------------------------------------
+ " s:Escape: {{{2
+-fun! s:Escape(fname,isfilt)
+- if exists("*shellescape")
+- if a:isfilt
+- let qnameq= shellescape(a:fname,1)
+- else
+- let qnameq= shellescape(a:fname)
+- endif
++fun! s:Escape(fname, isfilt = 0)
++ if a:isfilt
++ let qnameq = shellescape(a:fname, 1)
+ else
+- let qnameq= g:zip_shq.escape(a:fname,g:zip_shq).g:zip_shq
++ let qnameq = shellescape(a:fname)
+ endif
+ return qnameq
+ endfun
+
++" s:PSEscape: Escape a string for Powershell, shellescape() does not work here {{{2
++fun! s:PSEscape(str)
++ return "'" .. substitute(a:str, "'", "''", 'g') .. "'"
++endfun
++
+ " ---------------------------------------------------------------------
+ " s:ChgDir: {{{2
+ fun! s:ChgDir(newdir,errlvl,errmsg)
+diff --git a/runtime/doc/pi_zip.txt b/runtime/doc/pi_zip.txt
+index e9294b4059..b1800dfcc5 100644
+--- a/runtime/doc/pi_zip.txt
++++ b/runtime/doc/pi_zip.txt
+@@ -48,16 +48,6 @@ Copyright: Copyright (C) 2005-2015 Charles E Campbell *zip-copyright*
+ If this variable exists and is true, the file window will not be
+ automatically maximized when opened.
+
+- *g:zip_shq*
+- Different operating systems may use one or more shells to execute
+- commands. Zip will try to guess the correct quoting mechanism to
+- allow spaces and whatnot in filenames; however, if it is incorrectly
+- guessing the quote to use for your setup, you may use >
+- g:zip_shq
+-< which by default is a single quote under Unix (') and a double quote
+- under Windows ("). If you'd rather have no quotes, simply set
+- g:zip_shq to the empty string (let g:zip_shq= "") in your <.vimrc>.
+-
+ *g:zip_unzipcmd*
+ Use this option to specify the program which does the duty of "unzip".
+ It's used during browsing. By default: >
+--
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index b9f6ef987c..ecdf7cb5b9 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -25,6 +25,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
file://CVE-2026-52860.patch \
file://CVE-2026-55693.patch \
file://CVE-2026-55895.patch \
+ file://CVE-2026-57453.patch \
"
PV .= ".0340"
--
2.43.0
^ permalink raw reply related [flat|nested] 15+ messages in thread* Re: [OE-core][wrynose][patch 03/10] vim: Fix CVE-2026-57453
2026-07-22 12:33 ` [OE-core][wrynose][patch 03/10] vim: Fix CVE-2026-57453 Vijay Anusuri
@ 2026-07-26 21:45 ` Yoann Congal
0 siblings, 0 replies; 15+ messages in thread
From: Yoann Congal @ 2026-07-26 21:45 UTC (permalink / raw)
To: vanusuri, openembedded-core
On Wed Jul 22, 2026 at 2:33 PM CEST, Vijay Anusuri via lists.openembedded.org wrote:
> Pick patch per [1].
>
> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57453
> [2] https://github.com/vim/vim/security/advisories/GHSA-x5fg-h5w9-9frf
>
> Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> ---
> .../vim/files/CVE-2026-57453.patch | 248 ++++++++++++++++++
> meta/recipes-support/vim/vim.inc | 1 +
> 2 files changed, 249 insertions(+)
> create mode 100644 meta/recipes-support/vim/files/CVE-2026-57453.patch
>
> diff --git a/meta/recipes-support/vim/files/CVE-2026-57453.patch b/meta/recipes-support/vim/files/CVE-2026-57453.patch
> new file mode 100644
> index 0000000000..d1ad6d6f54
> --- /dev/null
> +++ b/meta/recipes-support/vim/files/CVE-2026-57453.patch
> @@ -0,0 +1,248 @@
> +From b2cc9be119d51212bf0d3f2a994c7e517c73f4a9 Mon Sep 17 00:00:00 2001
> +From: Christian Brabandt <cb@256bit.org>
> +Date: Sat, 20 Jun 2026 15:35:58 +0000
> +Subject: [PATCH] patch 9.2.0678: [security]: potential powershell code
> + execution in zip.vim
> +
> +Problem: [security]: potential powershell code execution in zip.vim
> + (DDugs)
> +Solution: Cleanup zip.vim, introduce PSEscape() to escape() potential powershell code,
> + use consistent s:Escape() in the various PowerShell functions
> +
> +Github Security Advisory:
> +https://github.com/vim/vim/security/advisories/GHSA-x5fg-h5w9-9frf
> +
> +Signed-off-by: Christian Brabandt <cb@256bit.org>
> +
> +Upstream-Status: Backport [https://github.com/vim/vim/commit/b2cc9be119d51212bf0d3f2a994c7e517c73f4a9]
> +CVE: CVE-2026-57453
> +Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> +---
> + runtime/autoload/zip.vim | 78 +++++++++++++++++++---------------------
> + runtime/doc/pi_zip.txt | 10 ------
> + 2 files changed, 36 insertions(+), 52 deletions(-)
> +
> +diff --git a/runtime/autoload/zip.vim b/runtime/autoload/zip.vim
> +index f4482fd7fc..752503a626 100644
> +--- a/runtime/autoload/zip.vim
> ++++ b/runtime/autoload/zip.vim
> [...]
> +@@ -339,9 +331,9 @@ fun! zip#Read(fname,mode)
> + let temp = tempname()
> + let fn = expand('%:p')
> +
> +- let gnu_cmd = g:zip_unzipcmd . ' -p -- ' . s:Escape(zipfile, 0) . ' ' . s:Escape(fname, 0) . ' > ' . s:Escape(temp, 0)
> +- let gnu_cmd = 'call system(''' . substitute(gnu_cmd, "'", "''", 'g') . ''')'
> +- let ps_cmd = 'sil !' . s:ZipReadPS(zipfile, fname, temp)
> ++ let gnu_cmd = g:zip_unzipcmd . ' -p -- ' . s:Escape(zipfile) . ' ' . s:Escape(fname) . ' > ' . s:Escape(temp)
> ++ let gnu_cmd = 'call system(' . string(gnu_cmd) . ')'
> ++ let ps_cmd = $"call system({string(s:ZipDeleteFilePS(zipfile, fname))})"
The above line changed from the upstream commit? Can you explain why?
The change is:
-+ let ps_cmd = 'call system(' . string(s:ZipReadPS(zipfile, fname, temp)) . ')'
++ let ps_cmd = $"call system({string(s:ZipDeleteFilePS(zipfile, fname))})"
In the meantime, I'll hold this patch but continue to review the
reminder of the series (hoping those CVE fixes are independant enought
to avoid a conflict).
--
Yoann Congal
Smile ECS
^ permalink raw reply [flat|nested] 15+ messages in thread
* [OE-core][wrynose][patch 04/10] vim: Fix CVE-2026-57451
2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
2026-07-22 12:33 ` [OE-core][wrynose][patch 02/10] vim: Fix CVE-2026-55895 Vijay Anusuri
2026-07-22 12:33 ` [OE-core][wrynose][patch 03/10] vim: Fix CVE-2026-57453 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
2026-07-26 21:53 ` Yoann Congal
2026-07-22 12:33 ` [OE-core][wrynose][patch 05/10] vim: Fix CVE-2026-57454 Vijay Anusuri
` (5 subsequent siblings)
8 siblings, 1 reply; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
To: openembedded-core; +Cc: Vijay Anusuri
Pick patch per [1].
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57451
[2] https://github.com/vim/vim/security/advisories/GHSA-f36c-2qcp-7gpw
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
.../vim/files/CVE-2026-57451.patch | 177 ++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 178 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57451.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-57451.patch b/meta/recipes-support/vim/files/CVE-2026-57451.patch
new file mode 100644
index 0000000000..22a0cfc03e
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-57451.patch
@@ -0,0 +1,177 @@
+From b2338ca90643e2f01ecb6547c1172716aaec4f79 Mon Sep 17 00:00:00 2001
+From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Date: Wed, 17 Jun 2026 21:06:59 +0000
+Subject: [PATCH] patch 9.2.0670: [security]: Out-of-bounds read with text
+ properties
+
+Problem: [security]: Out-of-bounds read with text properties
+ (cipher-creator)
+Solution: Add out-of-bound checks (Yasuhiro Matsumoto)
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-f36c-2qcp-7gpw
+
+Supported by AI
+
+Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/b2338ca90643e2f01ecb6547c1172716aaec4f79]
+CVE: CVE-2026-57451
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/memline.c | 7 ++++
+ src/proto/textprop.pro | 1 +
+ src/testdir/test_textprop2.vim | 59 ++++++++++++++++++++++++++++++++++
+ src/textprop.c | 20 ++++++++++++
+ 4 files changed, 87 insertions(+)
+
+diff --git a/src/memline.c b/src/memline.c
+index c15946a6eb..07c7a07d38 100644
+--- a/src/memline.c
++++ b/src/memline.c
+@@ -3796,6 +3796,11 @@ adjust_text_props_for_delete(
+ uint16_t pc;
+
+ mch_memmove(&pc, text + textlen, PROP_COUNT_SIZE);
++ if (!text_prop_count_valid(pc, (size_t)(line_size - (long)textlen)))
++ {
++ internal_error("text property count too large");
++ return;
++ }
+ this_props_len = pc * (int)sizeof(textprop_T);
+ }
+
+@@ -4034,6 +4039,8 @@ theend:
+ mch_memmove(&pc, textprop_save, PROP_COUNT_SIZE);
+ props_data = textprop_save + PROP_COUNT_SIZE;
+ props_bytes = pc * (int)sizeof(textprop_T);
++ if (!text_prop_count_valid(pc, (size_t)textprop_len))
++ props_bytes = 0;
+
+ // Adjust text properties in the line above and below.
+ if (lnum > 1)
+diff --git a/src/proto/textprop.pro b/src/proto/textprop.pro
+index d3ecf6d14c..a01c2f3b2d 100644
+--- a/src/proto/textprop.pro
++++ b/src/proto/textprop.pro
+@@ -35,4 +35,5 @@ void clear_buf_prop_types(buf_T *buf);
+ int adjust_prop_columns(linenr_T lnum, colnr_T col, int bytes_added, int flags);
+ void adjust_props_for_split(linenr_T lnum_props, linenr_T lnum_top, int kept, int deleted, int at_eol);
+ void prepend_joined_props(unpacked_memline_T *um, linenr_T lnum, int last_line, long col, int removed);
++bool text_prop_count_valid(int prop_count, size_t propdata_len);
+ /* vim: set ft=c : */
+diff --git a/src/testdir/test_textprop2.vim b/src/testdir/test_textprop2.vim
+index 193a808415..48387d1c04 100644
+--- a/src/testdir/test_textprop2.vim
++++ b/src/testdir/test_textprop2.vim
+@@ -428,4 +428,63 @@ func Test_multiline_prop_delete_penultimate_line()
+ call s:CleanupPropTypes(['1', '2', '3'])
+ endfunc
+
++func s:ManipulateUndoBlob(name)
++ " Patch the saved old line in the undo file:
++ " 00 00 00 08 'QQQQQQQQ' -> 00 00 00 27 'AAAA' NUL count=0xFFFF <32x00>
++ " i.e. textlen 8 text-only -> 39-byte blob: text "AAAA", NUL, prop_count
++ " 0xFFFF, one zeroed textprop_T(32). propdata_len becomes 34, count 65535.
++ let blob = readfile(a:name, 'B')
++ let marker = 0z000000085151515151515151
++ let repl = 0z000000274141414100FFFF + repeat(0z00, 32)
++ let mlen = len(marker)
++ let idx = -1
++ let i = 0
++ while i <= len(blob) - mlen
++ if blob[i : i + mlen - 1] ==# marker
++ let idx = i
++ break
++ endif
++ let i += 1
++ endwhile
++ call assert_true(idx >= 0, 'saved-line marker not found in undo file')
++
++ let head = idx > 0 ? blob[0 : idx - 1] : 0z
++ call writefile(head + repl + blob[idx + mlen :], a:name)
++
++ exe "rundo" a:name
++endfunc
++
++" A crafted undo file can restore a line whose declared text-property count is
++" far larger than the data, making get_text_props() / consumers read past the
++" line buffer. Restore such a line and force a consumer; reaching the asserts
++" (no ASan abort / crash) means the count is bounded.
++func Test_textprop_undo_bad_prop_count()
++ CheckFeature persistent_undo
++
++ new
++ call setline(1, ['QQQQQQQQ', 'DECOYLINE'])
++ let &ul = &ul
++ call setline(1, 'BBBB') " undo step saves old line 1 = "QQQQQQQQ"
++ wundo Xtpundo
++ call s:ManipulateUndoBlob('Xtpundo')
++
++ undo
++
++ " Safety: prove the malicious line was actually restored before the consumer
++ " runs, so the test can't pass vacuously if the patch missed.
++ call assert_equal('AAAA', getline(1))
++
++ " Adding a property anywhere sets b_has_textprop, so get_text_props() will
++ " actually inspect line 1 instead of returning early.
++ call prop_type_add('Xtp', {})
++ call prop_add(2, 1, {'type': 'Xtp', 'length': 1})
++
++ " this caused OOB read, now it triggers internal error
++ call assert_fails('call prop_list(1)', ['E340:', 'corrupted'])
++
++ call prop_type_delete('Xtp')
++ bwipe!
++ call delete('Xtpundo')
++endfunc
++
+ " vim: shiftwidth=2 sts=2 expandtab
+diff --git a/src/textprop.c b/src/textprop.c
+index 33165a8e43..931fb78d25 100644
+--- a/src/textprop.c
++++ b/src/textprop.c
+@@ -109,6 +109,12 @@ um_goto_line(unpacked_memline_T *um, linenr_T lnum, int extra_props)
+ char_u *props_start;
+
+ mch_memmove(&prop_count, count_ptr, PROP_COUNT_SIZE);
++ if (!text_prop_count_valid(prop_count, propdata_len))
++ {
++ iemsg(e_text_property_info_corrupted);
++ um->buf = NULL;
++ return false;
++ }
+ proplen = (int)prop_count;
+ props_start = count_ptr + PROP_COUNT_SIZE;
+
+@@ -1235,6 +1241,11 @@ get_text_props(buf_T *buf, linenr_T lnum, char_u **props, int will_change)
+ return 0;
+ }
+ mch_memmove(&prop_count, text + textlen, PROP_COUNT_SIZE);
++ if (!text_prop_count_valid(prop_count, propdata_len))
++ {
++ iemsg(e_text_property_info_corrupted);
++ return 0;
++ }
+ *props = text + textlen + PROP_COUNT_SIZE;
+ return (int)prop_count;
+ }
+@@ -3219,4 +3230,13 @@ prepend_joined_props(
+ um_abort(&r_um);
+ }
+
++ bool
++text_prop_count_valid(int prop_count, size_t propdata_len)
++{
++ if (propdata_len < PROP_COUNT_SIZE)
++ return false;
++ return (size_t)prop_count * sizeof(textprop_T)
++ <= propdata_len - PROP_COUNT_SIZE;
++}
++
+ #endif // FEAT_PROP_POPUP
+--
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index ecdf7cb5b9..b9acb4665a 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -26,6 +26,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
file://CVE-2026-55693.patch \
file://CVE-2026-55895.patch \
file://CVE-2026-57453.patch \
+ file://CVE-2026-57451.patch \
"
PV .= ".0340"
--
2.43.0
^ permalink raw reply related [flat|nested] 15+ messages in thread* Re: [OE-core][wrynose][patch 04/10] vim: Fix CVE-2026-57451
2026-07-22 12:33 ` [OE-core][wrynose][patch 04/10] vim: Fix CVE-2026-57451 Vijay Anusuri
@ 2026-07-26 21:53 ` Yoann Congal
0 siblings, 0 replies; 15+ messages in thread
From: Yoann Congal @ 2026-07-26 21:53 UTC (permalink / raw)
To: vanusuri, openembedded-core
On Wed Jul 22, 2026 at 2:33 PM CEST, Vijay Anusuri via lists.openembedded.org wrote:
> Pick patch per [1].
>
> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57451
> [2] https://github.com/vim/vim/security/advisories/GHSA-f36c-2qcp-7gpw
>
> Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> ---
> .../vim/files/CVE-2026-57451.patch | 177 ++++++++++++++++++
> meta/recipes-support/vim/vim.inc | 1 +
> 2 files changed, 178 insertions(+)
> create mode 100644 meta/recipes-support/vim/files/CVE-2026-57451.patch
>
> diff --git a/meta/recipes-support/vim/files/CVE-2026-57451.patch b/meta/recipes-support/vim/files/CVE-2026-57451.patch
> new file mode 100644
> index 0000000000..22a0cfc03e
> --- /dev/null
> +++ b/meta/recipes-support/vim/files/CVE-2026-57451.patch
> @@ -0,0 +1,177 @@
> +From b2338ca90643e2f01ecb6547c1172716aaec4f79 Mon Sep 17 00:00:00 2001
> +From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
> +Date: Wed, 17 Jun 2026 21:06:59 +0000
> +Subject: [PATCH] patch 9.2.0670: [security]: Out-of-bounds read with text
> + properties
> +
> +Problem: [security]: Out-of-bounds read with text properties
> + (cipher-creator)
> +Solution: Add out-of-bound checks (Yasuhiro Matsumoto)
> +
> +Github Security Advisory:
> +https://github.com/vim/vim/security/advisories/GHSA-f36c-2qcp-7gpw
> +
> +Supported by AI
> +
> +Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
> +Signed-off-by: Christian Brabandt <cb@256bit.org>
> +
> +Upstream-Status: Backport [https://github.com/vim/vim/commit/b2338ca90643e2f01ecb6547c1172716aaec4f79]
> +CVE: CVE-2026-57451
> +Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> +---
> + src/memline.c | 7 ++++
> + src/proto/textprop.pro | 1 +
> + src/testdir/test_textprop2.vim | 59 ++++++++++++++++++++++++++++++++++
> + src/textprop.c | 20 ++++++++++++
> + 4 files changed, 87 insertions(+)
Indentation was changed between upstream patch and this patch.
Don't keep the upstream indentation. (Even if unfortunate I admit...)
Regards,
--
Yoann Congal
Smile ECS
^ permalink raw reply [flat|nested] 15+ messages in thread
* [OE-core][wrynose][patch 05/10] vim: Fix CVE-2026-57454
2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
` (2 preceding siblings ...)
2026-07-22 12:33 ` [OE-core][wrynose][patch 04/10] vim: Fix CVE-2026-57451 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
2026-07-26 22:05 ` Yoann Congal
2026-07-22 12:33 ` [OE-core][wrynose][patch 06/10] vim: Fix CVE-2026-57455 Vijay Anusuri
` (4 subsequent siblings)
8 siblings, 1 reply; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
To: openembedded-core; +Cc: Vijay Anusuri
Pick patch per [1].
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57454
[2] https://security-tracker.debian.org/tracker/CVE-2026-57454
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
.../vim/files/CVE-2026-57454.patch | 188 ++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 189 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57454.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-57454.patch b/meta/recipes-support/vim/files/CVE-2026-57454.patch
new file mode 100644
index 0000000000..579ffbf11b
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-57454.patch
@@ -0,0 +1,188 @@
+From b3faeecc976d3031d7c0675623516ec60c30f949 Mon Sep 17 00:00:00 2001
+From: Hirohito Higashi <h.east.727@gmail.com>
+Date: Sat, 20 Jun 2026 16:06:58 +0000
+Subject: [PATCH] patch 9.2.0679: [security]: Out-of-bounds read with text
+ property virtual text
+
+Problem: [security]: Out-of-bounds read with text property virtual text.
+ A crafted undo file can declare a virtual-text property whose
+ offset points outside the line's property data, so reading the
+ virtual text reads out of bounds. This completes the count-only
+ check added in 9.2.0670.
+Solution: Validate the virtual-text offset and length of each property
+ against the available property data before turning the offset
+ into a pointer.
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-ww8h-47xp-hp4w
+
+Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
+Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/b3faeecc976d3031d7c0675623516ec60c30f949]
+CVE: CVE-2026-57454
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/proto/textprop.pro | 1 +
+ src/testdir/test_textprop2.vim | 60 ++++++++++++++++++++++++++++++----
+ src/textprop.c | 36 ++++++++++++++++++++
+ 3 files changed, 90 insertions(+), 7 deletions(-)
+
+diff --git a/src/proto/textprop.pro b/src/proto/textprop.pro
+index a01c2f3b2d..4e6fcc89a4 100644
+--- a/src/proto/textprop.pro
++++ b/src/proto/textprop.pro
+@@ -36,4 +36,5 @@ int adjust_prop_columns(linenr_T lnum, colnr_T col, int bytes_added, int flags);
+ void adjust_props_for_split(linenr_T lnum_props, linenr_T lnum_top, int kept, int deleted, int at_eol);
+ void prepend_joined_props(unpacked_memline_T *um, linenr_T lnum, int last_line, long col, int removed);
+ bool text_prop_count_valid(int prop_count, size_t propdata_len);
++bool text_prop_vtext_valid(char_u *props, int prop_count, size_t propdata_len);
+ /* vim: set ft=c : */
+diff --git a/src/testdir/test_textprop2.vim b/src/testdir/test_textprop2.vim
+index 48387d1c04..689096209c 100644
+--- a/src/testdir/test_textprop2.vim
++++ b/src/testdir/test_textprop2.vim
+@@ -428,14 +428,12 @@ func Test_multiline_prop_delete_penultimate_line()
+ call s:CleanupPropTypes(['1', '2', '3'])
+ endfunc
+
+-func s:ManipulateUndoBlob(name)
+- " Patch the saved old line in the undo file:
+- " 00 00 00 08 'QQQQQQQQ' -> 00 00 00 27 'AAAA' NUL count=0xFFFF <32x00>
+- " i.e. textlen 8 text-only -> 39-byte blob: text "AAAA", NUL, prop_count
+- " 0xFFFF, one zeroed textprop_T(32). propdata_len becomes 34, count 65535.
++func s:ManipulateUndoBlob(name, repl)
++ " Replace the saved old line (00 00 00 08 'QQQQQQQQ') in the undo file with
++ " the crafted "repl" blob, then read it back in.
+ let blob = readfile(a:name, 'B')
+ let marker = 0z000000085151515151515151
+- let repl = 0z000000274141414100FFFF + repeat(0z00, 32)
++ let repl = a:repl
+ let mlen = len(marker)
+ let idx = -1
+ let i = 0
+@@ -466,7 +464,10 @@ func Test_textprop_undo_bad_prop_count()
+ let &ul = &ul
+ call setline(1, 'BBBB') " undo step saves old line 1 = "QQQQQQQQ"
+ wundo Xtpundo
+- call s:ManipulateUndoBlob('Xtpundo')
++ " 39-byte blob: "AAAA" NUL count=0xFFFF, one zeroed textprop_T(32).
++ " propdata_len becomes 34 while the count claims 65535 properties.
++ call s:ManipulateUndoBlob('Xtpundo', 0z000000274141414100FFFF
++ \ + repeat(0z00, 32))
+
+ undo
+
+@@ -487,4 +488,49 @@ func Test_textprop_undo_bad_prop_count()
+ call delete('Xtpundo')
+ endfunc
+
++" A crafted undo file can restore a line whose virtual-text property declares an
++" out-of-range tp_text_offset. Turning that offset into a pointer and reading
++" the virtual text would read past the line buffer. Restore such a line and
++" force a consumer; reaching the asserts (no ASan abort / crash) means the
++" offset is bounded.
++func Test_textprop_undo_bad_vtext_offset()
++ CheckFeature persistent_undo
++
++ new
++ call setline(1, ['QQQQQQQQ', 'DECOYLINE'])
++ let &ul = &ul
++ call setline(1, 'BBBB') " undo step saves old line 1 = "QQQQQQQQ"
++ wundo Xtpundo
++
++ " One textprop_T for a virtual text prop (tp_id < 0) whose tp_text_offset
++ " (0x00100000) points far past the 34-byte property data. The count (1) is
++ " valid, so only the offset/length check can reject this.
++ let prop = 0z01000000 " tp_col = 1
++ let prop += 0z04000000 " tp_len = 4
++ let prop += 0zFFFFFFFF " tp_id = -1 (virtual text)
++ let prop += 0z00000000 " tp_type = 0
++ let prop += 0z00000000 " tp_flags = 0
++ let prop += 0z00000000 " tp_padleft = 0
++ let prop += 0z00001000 " u.tp_text_offset = 0x00100000
++ let prop += 0z00000000 " union upper bytes
++ call s:ManipulateUndoBlob('Xtpundo', 0z000000274141414100 + 0z0100 + prop)
++
++ undo
++
++ " Safety: prove the malicious line was actually restored before the consumer
++ " runs, so the test can't pass vacuously if the patch missed.
++ call assert_equal('AAAA', getline(1))
++
++ call prop_type_add('Xtp', {})
++ call prop_add(2, 1, {'type': 'Xtp', 'length': 1})
++
++ " this caused OOB read, now it is rejected as a corrupted (untrusted) undo
++ " file with a catchable error
++ call assert_fails('call prop_list(1)', 'E967:')
++
++ call prop_type_delete('Xtp')
++ bwipe!
++ call delete('Xtpundo')
++endfunc
++
+ " vim: shiftwidth=2 sts=2 expandtab
+diff --git a/src/textprop.c b/src/textprop.c
+index 931fb78d25..463a477e4d 100644
+--- a/src/textprop.c
++++ b/src/textprop.c
+@@ -118,6 +118,13 @@ um_goto_line(unpacked_memline_T *um, linenr_T lnum, int extra_props)
+ proplen = (int)prop_count;
+ props_start = count_ptr + PROP_COUNT_SIZE;
+
++ if (!text_prop_vtext_valid(props_start, proplen, propdata_len))
++ {
++ emsg(e_text_property_info_corrupted);
++ um->buf = NULL;
++ return false;
++ }
++
+ um->props = ALLOC_MULT(textprop_T, proplen + extra_props);
+ if (um->props == NULL)
+ {
+@@ -1246,6 +1253,12 @@ get_text_props(buf_T *buf, linenr_T lnum, char_u **props, int will_change)
+ iemsg(e_text_property_info_corrupted);
+ return 0;
+ }
++ if (!text_prop_vtext_valid(text + textlen + PROP_COUNT_SIZE,
++ (int)prop_count, propdata_len))
++ {
++ emsg(e_text_property_info_corrupted);
++ return 0;
++ }
+ *props = text + textlen + PROP_COUNT_SIZE;
+ return (int)prop_count;
+ }
+@@ -3239,4 +3252,27 @@ text_prop_count_valid(int prop_count, size_t propdata_len)
+ <= propdata_len - PROP_COUNT_SIZE;
+ }
+
++/*
++ * Return true when every virtual text property's offset and length stay within
++ * "propdata_len", so tp_text_offset can be safely turned into a pointer.
++ * "props" may be unaligned.
++ */
++ bool
++text_prop_vtext_valid(char_u *props, int prop_count, size_t propdata_len)
++{
++ for (int i = 0; i < prop_count; ++i)
++ {
++ textprop_T prop;
++
++ mch_memmove(&prop, props + (size_t)i * sizeof(textprop_T),
++ sizeof(textprop_T));
++ if (prop.tp_id >= 0 || prop.u.tp_text_offset <= 0)
++ continue;
++ if (prop.tp_len < 0 || (size_t)prop.u.tp_text_offset
++ + (size_t)prop.tp_len + 1 > propdata_len)
++ return false;
++ }
++ return true;
++}
++
+ #endif // FEAT_PROP_POPUP
+--
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index b9acb4665a..82f63f6067 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -27,6 +27,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
file://CVE-2026-55895.patch \
file://CVE-2026-57453.patch \
file://CVE-2026-57451.patch \
+ file://CVE-2026-57454.patch \
"
PV .= ".0340"
--
2.43.0
^ permalink raw reply related [flat|nested] 15+ messages in thread* Re: [OE-core][wrynose][patch 05/10] vim: Fix CVE-2026-57454
2026-07-22 12:33 ` [OE-core][wrynose][patch 05/10] vim: Fix CVE-2026-57454 Vijay Anusuri
@ 2026-07-26 22:05 ` Yoann Congal
0 siblings, 0 replies; 15+ messages in thread
From: Yoann Congal @ 2026-07-26 22:05 UTC (permalink / raw)
To: vanusuri, openembedded-core
On Wed Jul 22, 2026 at 2:33 PM CEST, Vijay Anusuri via lists.openembedded.org wrote:
> Pick patch per [1].
>
> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-57454
> [2] https://security-tracker.debian.org/tracker/CVE-2026-57454
>
> Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> ---
> .../vim/files/CVE-2026-57454.patch | 188 ++++++++++++++++++
> meta/recipes-support/vim/vim.inc | 1 +
> 2 files changed, 189 insertions(+)
> create mode 100644 meta/recipes-support/vim/files/CVE-2026-57454.patch
>
> diff --git a/meta/recipes-support/vim/files/CVE-2026-57454.patch b/meta/recipes-support/vim/files/CVE-2026-57454.patch
> new file mode 100644
> index 0000000000..579ffbf11b
> --- /dev/null
> +++ b/meta/recipes-support/vim/files/CVE-2026-57454.patch
> @@ -0,0 +1,188 @@
> +From b3faeecc976d3031d7c0675623516ec60c30f949 Mon Sep 17 00:00:00 2001
> +From: Hirohito Higashi <h.east.727@gmail.com>
> +Date: Sat, 20 Jun 2026 16:06:58 +0000
> +Subject: [PATCH] patch 9.2.0679: [security]: Out-of-bounds read with text
> + property virtual text
> +
> +Problem: [security]: Out-of-bounds read with text property virtual text.
> + A crafted undo file can declare a virtual-text property whose
> + offset points outside the line's property data, so reading the
> + virtual text reads out of bounds. This completes the count-only
> + check added in 9.2.0670.
> +Solution: Validate the virtual-text offset and length of each property
> + against the available property data before turning the offset
> + into a pointer.
> +
> +Github Security Advisory:
> +https://github.com/vim/vim/security/advisories/GHSA-ww8h-47xp-hp4w
> +
> +Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
> +Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
> +Signed-off-by: Christian Brabandt <cb@256bit.org>
> +
> +Upstream-Status: Backport [https://github.com/vim/vim/commit/b3faeecc976d3031d7c0675623516ec60c30f949]
> +CVE: CVE-2026-57454
> +Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> +---
> + src/proto/textprop.pro | 1 +
> + src/testdir/test_textprop2.vim | 60 ++++++++++++++++++++++++++++++----
> + src/textprop.c | 36 ++++++++++++++++++++
> + 3 files changed, 90 insertions(+), 7 deletions(-)
This patch also has indentation changes between upstream patch and this
patch.
I'll hold the whole series and let you check and correct the patches.
Please send a v2 of the whole series.
Thanks!
--
Yoann Congal
Smile ECS
^ permalink raw reply [flat|nested] 15+ messages in thread
* [OE-core][wrynose][patch 06/10] vim: Fix CVE-2026-57455
2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
` (3 preceding siblings ...)
2026-07-22 12:33 ` [OE-core][wrynose][patch 05/10] vim: Fix CVE-2026-57454 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
2026-07-22 12:33 ` [OE-core][wrynose][patch 07/10] vim: Fix CVE-2026-57456 Vijay Anusuri
` (3 subsequent siblings)
8 siblings, 0 replies; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
To: openembedded-core; +Cc: Vijay Anusuri
Pick patch per [1].
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57455
[2] https://security-tracker.debian.org/tracker/CVE-2026-57455
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
.../vim/files/CVE-2026-57455.patch | 72 +++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 73 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57455.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-57455.patch b/meta/recipes-support/vim/files/CVE-2026-57455.patch
new file mode 100644
index 0000000000..51f0eb7fe0
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-57455.patch
@@ -0,0 +1,72 @@
+From 497f931f85339d175d7f69588dd249e8ccfed41b Mon Sep 17 00:00:00 2001
+From: Christian Brabandt <cb@256bit.org>
+Date: Sun, 21 Jun 2026 19:20:03 +0000
+Subject: [PATCH] patch 9.2.0698: [security]: Out-of-bounds write with
+ soundfold()
+
+Problem: [security]: Out-of-bounds write with soundfold()
+ (cipher-creator)
+Solution: Add an abort condition to the for loop to validate the buffer
+ size.
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-q8mh-6qm3-25g4
+
+Supported by AI
+
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/497f931f85339d175d7f69588dd249e8ccfed41b]
+CVE: CVE-2026-57455
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/spell.c | 2 +-
+ src/testdir/test_spellfile.vim | 21 +++++++++++++++++++++
+ 2 files changed, 22 insertions(+), 1 deletion(-)
+
+diff --git a/src/spell.c b/src/spell.c
+index 01eb57e3a9..060a2251a4 100644
+--- a/src/spell.c
++++ b/src/spell.c
+@@ -3270,7 +3270,7 @@ spell_soundfold_sofo(slang_T *slang, char_u *inword, char_u *res)
+ else
+ {
+ // The sl_sal_first[] table contains the translation.
+- for (s = inword; (c = *s) != NUL; ++s)
++ for (s = inword; (c = *s) != NUL && ri < MAXWLEN - 1; ++s)
+ {
+ if (VIM_ISWHITE(c))
+ c = ' ';
+diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim
+index 4da270acea..c0c46a32d2 100644
+--- a/src/testdir/test_spellfile.vim
++++ b/src/testdir/test_spellfile.vim
+@@ -1223,4 +1223,25 @@ func Test_spell_sug_tree_count_words_overflow()
+ bwipe!
+ endfunc
+
++" A word longer than MAXWLEN must not overflow the soundfold result buffer in
++" the single-byte SOFO branch of spell_soundfold_sofo().
++func Test_soundfold_overflow()
++ let _enc=&enc
++ set enc=latin1
++ call writefile(['SOFOFROM ab', 'SOFOTO xy'], 'Xtest.aff', 'D')
++ call writefile(['1', 'foo'], 'Xtest.dic', 'D')
++ mkspell! Xtest Xtest
++ defer delete('Xtest.latin1.spl')
++ defer delete('Xtest.latin1.sug')
++ setl spelllang=Xtest.latin1.spl spell
++
++ " Before the fix the copy loop wrote one byte per input byte into a
++ " MAXWLEN (254) stack buffer with no upper bound, smashing the stack.
++ let sound = soundfold(repeat('ab', 300))
++ call assert_true(strlen(sound) < 254, 'soundfold result exceeds MAXWLEN')
++
++ set spell& spelllang&
++ let &enc = _enc
++endfunc
++
+ " vim: shiftwidth=2 sts=2 expandtab
+--
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 82f63f6067..dec5b68324 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -28,6 +28,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
file://CVE-2026-57453.patch \
file://CVE-2026-57451.patch \
file://CVE-2026-57454.patch \
+ file://CVE-2026-57455.patch \
"
PV .= ".0340"
--
2.43.0
^ permalink raw reply related [flat|nested] 15+ messages in thread* [OE-core][wrynose][patch 07/10] vim: Fix CVE-2026-57456
2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
` (4 preceding siblings ...)
2026-07-22 12:33 ` [OE-core][wrynose][patch 06/10] vim: Fix CVE-2026-57455 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
2026-07-22 12:33 ` [OE-core][wrynose][patch 08/10] vim: Fix CVE-2026-59856 Vijay Anusuri
` (2 subsequent siblings)
8 siblings, 0 replies; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
To: openembedded-core; +Cc: Vijay Anusuri
Pick patch per [1].
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-57456
[2] https://security-tracker.debian.org/tracker/CVE-2026-57456
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
.../vim/files/CVE-2026-57456.patch | 149 ++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 150 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-57456.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-57456.patch b/meta/recipes-support/vim/files/CVE-2026-57456.patch
new file mode 100644
index 0000000000..9a4155ef04
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-57456.patch
@@ -0,0 +1,149 @@
+From cce141c42740f122dd8486ae04e21c2a81016ba8 Mon Sep 17 00:00:00 2001
+From: Christian Brabandt <cb@256bit.org>
+Date: Sun, 21 Jun 2026 19:50:56 +0000
+Subject: [PATCH] patch 9.2.0699: [security]: possible code execution with
+ python complete
+
+Problem: [security]: possible code execution with python complete
+ (morningbread)
+Solution: Use repr() to quote the doc strings correctly
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-ppj8-wqjf-6fp3
+
+Supported by AI
+
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/cce141c42740f122dd8486ae04e21c2a81016ba8]
+CVE: CVE-2026-57456
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ runtime/autoload/python3complete.vim | 9 +++++----
+ runtime/autoload/pythoncomplete.vim | 9 +++++----
+ src/testdir/test_plugin_python3complete.vim | 15 +++++++++++++++
+ 3 files changed, 25 insertions(+), 8 deletions(-)
+
+diff --git a/runtime/autoload/python3complete.vim b/runtime/autoload/python3complete.vim
+index c4ef19d82f..f90cca74b3 100644
+--- a/runtime/autoload/python3complete.vim
++++ b/runtime/autoload/python3complete.vim
+@@ -2,7 +2,7 @@
+ " Maintainer: <vacancy>
+ " Previous Maintainer: Aaron Griffin <aaronmgriffin@gmail.com>
+ " Version: 0.10
+-" Last Updated: 2026 Jun 04
++" Last Updated: 2026 Jun 21
+ "
+ " Roland Puntaier: this file contains adaptations for python3 and is parallel to pythoncomplete.vim
+ "
+@@ -22,6 +22,7 @@
+ " previous code passed buffer-supplied expressions to exec() which
+ " Python evaluates at definition time, allowing arbitrary code
+ " execution via crafted def/class headers
++" * use repr() on doc strings to prevent code execution
+ "
+ " v 0.9
+ " * Fixed docstring parsing for classes and functions
+@@ -335,7 +336,7 @@ class Scope(object):
+
+ def get_code(self):
+ str = ""
+- if len(self.docstr) > 0: str += '"""'+self.docstr+'"""\n'
++ if len(self.docstr) > 0: str += repr(self.docstr)+'\n'
+ str += 'class _PyCmplNoType:\n def __getattr__(self,name):\n return None\n'
+ for sub in self.subscopes:
+ str += sub.get_code()
+@@ -378,7 +379,7 @@ class Class(Scope):
+ if _DOTTED_NAME_RE.match(s.strip())]
+ if len(safe_supers) > 0: str += '(%s)' % ','.join(safe_supers)
+ str += ':\n'
+- if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
++ if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n'
+ if len(self.subscopes) > 0:
+ for s in self.subscopes: str += s.get_code()
+ else:
+@@ -401,7 +402,7 @@ class Function(Scope):
+ safe_params = [p for p in safe_params if p]
+ str = "%sdef %s(%s):\n" % \
+ (self.currentindent(),self.name,','.join(safe_params))
+- if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
++ if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n'
+ str += "%spass\n" % self.childindent()
+ return str
+
+diff --git a/runtime/autoload/pythoncomplete.vim b/runtime/autoload/pythoncomplete.vim
+index 39b1efd299..d2f5d57b0c 100644
+--- a/runtime/autoload/pythoncomplete.vim
++++ b/runtime/autoload/pythoncomplete.vim
+@@ -2,7 +2,7 @@
+ " Maintainer: <vacancy>
+ " Previous Maintainer: Aaron Griffin <aaronmgriffin@gmail.com>
+ " Version: 0.10
+-" Last Updated: 2026 Jun 04
++" Last Updated: 2026 Jun 21
+ "
+ " Changes
+ " TODO:
+@@ -20,6 +20,7 @@
+ " previous code passed buffer-supplied expressions to exec() which
+ " Python evaluates at definition time, allowing arbitrary code
+ " execution via crafted def/class headers
++" * use repr() on doc strings to prevent code execution
+ "
+ " v 0.9
+ " * Fixed docstring parsing for classes and functions
+@@ -350,7 +351,7 @@ class Scope(object):
+
+ def get_code(self):
+ str = ""
+- if len(self.docstr) > 0: str += '"""'+self.docstr+'"""\n'
++ if len(self.docstr) > 0: str += repr(self.docstr)+'\n'
+ str += 'class _PyCmplNoType:\n def __getattr__(self,name):\n return None\n'
+ for sub in self.subscopes:
+ str += sub.get_code()
+@@ -393,7 +394,7 @@ class Class(Scope):
+ if _DOTTED_NAME_RE.match(s.strip())]
+ if len(safe_supers) > 0: str += '(%s)' % ','.join(safe_supers)
+ str += ':\n'
+- if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
++ if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n'
+ if len(self.subscopes) > 0:
+ for s in self.subscopes: str += s.get_code()
+ else:
+@@ -416,7 +417,7 @@ class Function(Scope):
+ safe_params = [p for p in safe_params if p]
+ str = "%sdef %s(%s):\n" % \
+ (self.currentindent(),self.name,','.join(safe_params))
+- if len(self.docstr) > 0: str += self.childindent()+'"""'+self.docstr+'"""\n'
++ if len(self.docstr) > 0: str += self.childindent()+repr(self.docstr)+'\n'
+ str += "%spass\n" % self.childindent()
+ return str
+
+diff --git a/src/testdir/test_plugin_python3complete.vim b/src/testdir/test_plugin_python3complete.vim
+index e2b0c6616d..590348ee4a 100644
+--- a/src/testdir/test_plugin_python3complete.vim
++++ b/src/testdir/test_plugin_python3complete.vim
+@@ -221,4 +221,19 @@ func Test_python3complete_allow_import_on_runs_imports()
+ \ 'g:pythoncomplete_allow_import=1 did not run the buffer import')
+ endfunc
+
++func Test_python3complete_no_exec_via_class_docstring()
++ " A class-body docstring is emitted verbatim between triple quotes by
++ " get_code() and runs at class-definition time during exec(). A single-
++ " quoted source docstring lets an embedded """ survive doc()'s leading/
++ " trailing quote strip and break out of the generated literal.
++ let marker = tempname()
++ call s:CompleteAndExpectNoMarker([
++ \ 'class Foo:',
++ \ ' ''x"""+open("' . marker . '", "w").close()+"""y''',
++ \ ' pass',
++ \ 'Foo.',
++ \ ], marker,
++ \ 'class docstring expression was evaluated during omni-completion')
++endfunc
++
+ " vim: shiftwidth=2 sts=2 expandtab
+--
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index dec5b68324..008dbdb8df 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -29,6 +29,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
file://CVE-2026-57451.patch \
file://CVE-2026-57454.patch \
file://CVE-2026-57455.patch \
+ file://CVE-2026-57456.patch \
"
PV .= ".0340"
--
2.43.0
^ permalink raw reply related [flat|nested] 15+ messages in thread* [OE-core][wrynose][patch 08/10] vim: Fix CVE-2026-59856
2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
` (5 preceding siblings ...)
2026-07-22 12:33 ` [OE-core][wrynose][patch 07/10] vim: Fix CVE-2026-57456 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
2026-07-22 12:33 ` [OE-core][wrynose][patch 09/10] vim: Fix CVE-2026-59857 Vijay Anusuri
2026-07-22 12:33 ` [OE-core][wrynose][patch 10/10] vim: Fix CVE-2026-59858 Vijay Anusuri
8 siblings, 0 replies; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
To: openembedded-core; +Cc: Vijay Anusuri
Pick patch per [1].
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-59856
[2] https://security-tracker.debian.org/tracker/CVE-2026-59856
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
.../vim/files/CVE-2026-59856.patch | 103 ++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 104 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-59856.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-59856.patch b/meta/recipes-support/vim/files/CVE-2026-59856.patch
new file mode 100644
index 0000000000..42636161d0
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-59856.patch
@@ -0,0 +1,103 @@
+From 43afc581a37a35762dd0ef292f038b9dc5680a24 Mon Sep 17 00:00:00 2001
+From: Hirohito Higashi <h.east.727@gmail.com>
+Date: Fri, 26 Jun 2026 20:07:01 +0900
+Subject: [PATCH] patch 9.2.0736: potential command execution in PHP
+ omni-completion
+
+Problem: With PHP omni-completion, a crafted file can potentially
+ execute arbitrary commands when completing a class member.
+Solution: Quote the class name before inserting it into the search()
+ pattern run via win_execute().
+
+Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
+Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/43afc581a37a35762dd0ef292f038b9dc5680a24]
+CVE: CVE-2026-59856
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ runtime/autoload/phpcomplete.vim | 3 ++-
+ src/testdir/Make_all.mak | 2 ++
+ src/testdir/test_plugin_phpcomplete.vim | 35 +++++++++++++++++++++++++
+ 3 files changed, 39 insertions(+), 1 deletion(-)
+ create mode 100644 src/testdir/test_plugin_phpcomplete.vim
+
+diff --git a/runtime/autoload/phpcomplete.vim b/runtime/autoload/phpcomplete.vim
+index 5b4263ae45..ec54352586 100644
+--- a/runtime/autoload/phpcomplete.vim
++++ b/runtime/autoload/phpcomplete.vim
+@@ -2082,7 +2082,8 @@ function! phpcomplete#GetClassContentsStructure(file_path, file_lines, class_nam
+ let result = []
+ let popup_id = popup_create(a:file_lines, {'hidden': v:true})
+
+- call win_execute(popup_id, 'call search(''\c\(class\|interface\|trait\)\_s\+'.a:class_name.'\(\>\|$\)'')')
++ call win_execute(popup_id, 'call search('
++ \ . string('\c\(class\|interface\|trait\)\_s\+' . a:class_name . '\(\>\|$\)') . ')')
+ call win_execute(popup_id, "let cfline = line('.')")
+ call win_execute(popup_id, "call search('{')")
+ call win_execute(popup_id, "let endline = line('.')")
+diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak
+index b06d1af431..b5735b6c3c 100644
+--- a/src/testdir/Make_all.mak
++++ b/src/testdir/Make_all.mak
+@@ -250,6 +250,7 @@ NEW_TESTS = \
+ test_plugin_man \
+ test_plugin_matchparen \
+ test_plugin_netrw \
++ test_plugin_phpcomplete \
+ test_plugin_python3complete \
+ test_plugin_osc52 \
+ test_plugin_tar \
+@@ -529,6 +530,7 @@ NEW_TESTS_RES = \
+ test_plugin_man.res \
+ test_plugin_matchparen.res \
+ test_plugin_netrw.res \
++ test_plugin_phpcomplete.res \
+ test_plugin_python3complete.res \
+ test_plugin_osc52.res \
+ test_plugin_tar.res \
+diff --git a/src/testdir/test_plugin_phpcomplete.vim b/src/testdir/test_plugin_phpcomplete.vim
+new file mode 100644
+index 0000000000..7f66be47b7
+--- /dev/null
++++ b/src/testdir/test_plugin_phpcomplete.vim
+@@ -0,0 +1,35 @@
++" Tests for the PHP omni-completion plugin (runtime/autoload/phpcomplete.vim).
++
++" A buffer class name is interpolated into a search() pattern run via
++" win_execute(). Without escaping, "'" closes the string and "|" starts a new
++" Ex command, so the name runs as an Ex command during completion.
++func Test_phpcomplete_no_exec_via_class_name()
++ unlet! g:phpcomplete_injected
++ let lines = ['<?php', 'class x {}', '']
++ let payload = "x')|let g:phpcomplete_injected = 1|call search('"
++
++ try
++ call phpcomplete#GetClassContentsStructure('x.php', lines, payload)
++ catch
++ endtry
++
++ call assert_false(exists('g:phpcomplete_injected'),
++ \ 'class name was executed as an Ex command during completion')
++
++ unlet! g:phpcomplete_injected
++endfunc
++
++func Test_phpcomplete_class_lookup_still_works()
++ let lines = ['<?php', 'class Foo {', ' public $bar;', '}', '']
++ let result = phpcomplete#GetClassContentsStructure('Foo.php', lines, 'Foo')
++
++ call assert_equal(type([]), type(result),
++ \ 'GetClassContentsStructure did not return a list')
++ call assert_true(len(result) > 0, 'no class structure returned')
++ call assert_match('class Foo', result[0].content,
++ \ 'class body missing from returned content')
++ call assert_match('bar', result[0].content,
++ \ 'class member missing from returned content')
++endfunc
++
++" vim: shiftwidth=2 sts=2 expandtab
+--
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index 008dbdb8df..b9f8e40a28 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -30,6 +30,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
file://CVE-2026-57454.patch \
file://CVE-2026-57455.patch \
file://CVE-2026-57456.patch \
+ file://CVE-2026-59856.patch \
"
PV .= ".0340"
--
2.43.0
^ permalink raw reply related [flat|nested] 15+ messages in thread* [OE-core][wrynose][patch 09/10] vim: Fix CVE-2026-59857
2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
` (6 preceding siblings ...)
2026-07-22 12:33 ` [OE-core][wrynose][patch 08/10] vim: Fix CVE-2026-59856 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
2026-07-22 12:33 ` [OE-core][wrynose][patch 10/10] vim: Fix CVE-2026-59858 Vijay Anusuri
8 siblings, 0 replies; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
To: openembedded-core; +Cc: Vijay Anusuri
Pick patch per [1].
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-59857
[2] https://security-tracker.debian.org/tracker/CVE-2026-59857
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
.../vim/files/CVE-2026-59857.patch | 110 ++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 111 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-59857.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-59857.patch b/meta/recipes-support/vim/files/CVE-2026-59857.patch
new file mode 100644
index 0000000000..aa1f0725b5
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-59857.patch
@@ -0,0 +1,110 @@
+From d22ff1c955ff87e8273210eae125aab0e85b6c30 Mon Sep 17 00:00:00 2001
+From: Hirohito Higashi <h.east.727@gmail.com>
+Date: Mon, 22 Jun 2026 13:00:36 +0900
+Subject: [PATCH] patch 9.2.0725: [security]: Stack out-of-bounds write in
+ spell_soundfold_sal()
+
+Problem: [security]: A crafted spell file with non-collapsing SAL rules
+ can make soundfold() write one byte past the end of the
+ MAXWLEN result buffer. This is the same class of
+ out-of-bounds write as GHSA-q8mh-6qm3-25g4 (fixed in 9.2.0698
+ for the SOFO branch), found while auditing the surrounding
+ code.
+Solution: Bound the single-byte SAL result writes and the terminating
+ NUL to MAXWLEN - 1, matching the SOFO branch.
+
+The single-byte branch of spell_soundfold_sal() guarded its writes with
+"reslen < MAXWLEN", allowing reslen to reach MAXWLEN (254). The trailing
+"res[reslen] = NUL" then wrote at index 254 of the 254-byte stack buffer
+res[MAXWLEN], an off-by-one out-of-bounds write. Input is case-folded to
+about 253 characters, so a 253-character argument together with a SAL map
+that does not collapse (collapse_result false) reaches the boundary.
+
+Related to previous issue
+[GHSA-q8mh-6qm3-25g4](https://github.com/vim/vim/security/advisories/GHSA-q8mh-6qm3-25g4)
+(9.2.0698)
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-m3hf-xcm3-xhm2
+
+Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
+Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/d22ff1c955ff87e8273210eae125aab0e85b6c30]
+CVE: CVE-2026-59857
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/spell.c | 6 +++---
+ src/testdir/test_spellfile.vim | 24 ++++++++++++++++++++++++
+ 2 files changed, 27 insertions(+), 3 deletions(-)
+
+diff --git a/src/spell.c b/src/spell.c
+index 060a2251a4..43a83ce7dc 100644
+--- a/src/spell.c
++++ b/src/spell.c
+@@ -3513,7 +3513,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res)
+ // no '<' rule used
+ i += k - 1;
+ z = 0;
+- while (*s != NUL && s[1] != NUL && reslen < MAXWLEN)
++ while (*s != NUL && s[1] != NUL && reslen < MAXWLEN - 1)
+ {
+ if (reslen == 0 || res[reslen - 1] != *s)
+ res[reslen++] = *s;
+@@ -3523,7 +3523,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res)
+ c = *s;
+ if (strstr((char *)pf, "^^") != NULL)
+ {
+- if (c != NUL)
++ if (c != NUL && reslen < MAXWLEN - 1)
+ res[reslen++] = c;
+ STRMOVE(word, word + i + 1);
+ i = 0;
+@@ -3542,7 +3542,7 @@ spell_soundfold_sal(slang_T *slang, char_u *inword, char_u *res)
+
+ if (z0 == 0)
+ {
+- if (k && !p0 && reslen < MAXWLEN && c != NUL
++ if (k && !p0 && reslen < MAXWLEN - 1 && c != NUL
+ && (!slang->sl_collapse || reslen == 0
+ || res[reslen - 1] != c))
+ // condense only double letters
+diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim
+index c0c46a32d2..a9bccc6491 100644
+--- a/src/testdir/test_spellfile.vim
++++ b/src/testdir/test_spellfile.vim
+@@ -387,6 +387,30 @@ func Test_spellfile_format_error()
+ let &rtp = save_rtp
+ endfunc
+
++" An over-length soundfold() argument must not overflow the MAXWLEN result
++" buffer in the single-byte branch of spell_soundfold_sal().
++func Test_spellfile_soundfold_sal_overflow()
++ let save_enc = &encoding
++ set encoding=latin1
++ " A SAL map that appends without collapsing, so the result is not shorter
++ " than the input.
++ call writefile(['SET ISO8859-1', 'SAL collapse_result false',
++ \ 'SAL a aaaa', 'SAL b bbbb'], 'Xsal.aff')
++ call writefile(['2', 'hello', 'world'], 'Xsal.dic')
++ mkspell! Xsal Xsal
++ set spl=Xsal.latin1.spl spell
++
++ " 253 input characters hit the buffer boundary; the result must not exceed
++ " MAXWLEN - 1.
++ call assert_true(strlen(soundfold(repeat('a', 253))) <= 253)
++
++ set nospell spl& spelllang&
++ call delete('Xsal.aff')
++ call delete('Xsal.dic')
++ call delete('Xsal.latin1.spl')
++ let &encoding = save_enc
++endfunc
++
+ " Test for format errors in suggest file
+ func Test_sugfile_format_error()
+ let save_rtp = &rtp
+--
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index b9f8e40a28..ab7564c3b6 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -31,6 +31,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
file://CVE-2026-57455.patch \
file://CVE-2026-57456.patch \
file://CVE-2026-59856.patch \
+ file://CVE-2026-59857.patch \
"
PV .= ".0340"
--
2.43.0
^ permalink raw reply related [flat|nested] 15+ messages in thread* [OE-core][wrynose][patch 10/10] vim: Fix CVE-2026-59858
2026-07-22 12:33 [OE-core][wrynose][patch 01/10] vim: Fix CVE-2026-55693 Vijay Anusuri
` (7 preceding siblings ...)
2026-07-22 12:33 ` [OE-core][wrynose][patch 09/10] vim: Fix CVE-2026-59857 Vijay Anusuri
@ 2026-07-22 12:33 ` Vijay Anusuri
2026-08-26 14:55 ` Vijay Anusuri
8 siblings, 1 reply; 15+ messages in thread
From: Vijay Anusuri @ 2026-07-22 12:33 UTC (permalink / raw)
To: openembedded-core; +Cc: Vijay Anusuri
Pick patch per [1].
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-59858
[2] https://security-tracker.debian.org/tracker/CVE-2026-59858
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
---
.../vim/files/CVE-2026-59858.patch | 134 ++++++++++++++++++
meta/recipes-support/vim/vim.inc | 1 +
2 files changed, 135 insertions(+)
create mode 100644 meta/recipes-support/vim/files/CVE-2026-59858.patch
diff --git a/meta/recipes-support/vim/files/CVE-2026-59858.patch b/meta/recipes-support/vim/files/CVE-2026-59858.patch
new file mode 100644
index 0000000000..a2b903be04
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-59858.patch
@@ -0,0 +1,134 @@
+From 6b611b0d15603c52ebdad17172b0232b4f65704e Mon Sep 17 00:00:00 2001
+From: Hirohito Higashi <h.east.727@gmail.com>
+Date: Fri, 26 Jun 2026 15:41:24 +0900
+Subject: [PATCH] patch 9.2.0735: [security]: arbitrary Ex command execution
+ during C omni-completion
+
+Problem: [security]: With C omni-completion, a crafted tags file can execute
+ arbitrary Ex commands when completing a struct/union member
+ (cipher-creator)
+Solution: Escape the type field before inserting it into the :vimgrep
+ pattern so it cannot close the pattern and start a new command
+ (Hirohito Higashi).
+
+Github Security Advisory:
+https://github.com/vim/vim/security/advisories/GHSA-mf92-v4xw-j45x
+
+Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>"
+Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
+Signed-off-by: Christian Brabandt <cb@256bit.org>
+
+Upstream-Status: Backport [https://github.com/vim/vim/commit/6b611b0d15603c52ebdad17172b0232b4f65704e]
+CVE: CVE-2026-59858
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ runtime/autoload/ccomplete.vim | 2 +-
+ src/testdir/Make_all.mak | 2 +
+ src/testdir/test_plugin_ccomplete.vim | 62 +++++++++++++++++++++++++++
+ 3 files changed, 65 insertions(+), 1 deletion(-)
+ create mode 100644 src/testdir/test_plugin_ccomplete.vim
+
+diff --git a/runtime/autoload/ccomplete.vim b/runtime/autoload/ccomplete.vim
+index 51237be98b..dc3388b524 100644
+--- a/runtime/autoload/ccomplete.vim
++++ b/runtime/autoload/ccomplete.vim
+@@ -600,7 +600,7 @@ def StructMembers( # {{{1
+ return []
+ endif
+ execute 'silent! keepjumps noautocmd '
+- .. n .. 'vimgrep ' .. '/\t' .. typename .. '\(\t\|$\)/j '
++ .. n .. 'vimgrep ' .. '/\t' .. escape(typename, '/\') .. '\(\t\|$\)/j '
+ .. fnames
+
+ qflist = getqflist()
+diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak
+index b5735b6c3c..0cf2c41102 100644
+--- a/src/testdir/Make_all.mak
++++ b/src/testdir/Make_all.mak
+@@ -243,6 +243,7 @@ NEW_TESTS = \
+ test_partial \
+ test_paste \
+ test_perl \
++ test_plugin_ccomplete \
+ test_plugin_comment \
+ test_plugin_glvs \
+ test_plugin_helpcurwin \
+@@ -523,6 +524,7 @@ NEW_TESTS_RES = \
+ test_partial.res \
+ test_paste.res \
+ test_perl.res \
++ test_plugin_ccomplete.res \
+ test_plugin_comment.res \
+ test_plugin_glvs.res \
+ test_plugin_helpcurwin.res \
+diff --git a/src/testdir/test_plugin_ccomplete.vim b/src/testdir/test_plugin_ccomplete.vim
+new file mode 100644
+index 0000000000..a635bd50bd
+--- /dev/null
++++ b/src/testdir/test_plugin_ccomplete.vim
+@@ -0,0 +1,62 @@
++" Tests for the C omni-completion plugin (runtime/autoload/ccomplete.vim).
++
++func s:WriteTags(lines)
++ " Mark unsorted so lookup is a linear scan regardless of entry order.
++ let tagsfile = tempname()
++ call writefile(["!_TAG_FILE_SORTED\t0\t/0/"] + a:lines, tagsfile)
++ return tagsfile
++endfunc
++
++" A crafted typeref field is interpolated into the :vimgrep pattern in
++" StructMembers(). Without escaping, "/" closes the pattern and "|" starts a
++" new Ex command, so the field runs as an Ex command during completion.
++func Test_ccomplete_no_exec_via_typeref()
++ unlet! g:ccomplete_injected
++ let tagsfile = s:WriteTags([
++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:x/|let g:ccomplete_injected = 1|\"",
++ \ ])
++
++ let save_tags = &tags
++ let &tags = tagsfile
++
++ new
++ call ccomplete#Complete(1, '')
++ call ccomplete#Complete(0, 'myvar.x')
++
++ call assert_false(exists('g:ccomplete_injected'),
++ \ 'typeref field was executed as an Ex command during omni-completion')
++
++ bwipe!
++ let &tags = save_tags
++ unlet! g:ccomplete_injected
++endfunc
++
++" A legitimate typeref must still drive struct-member completion: escaping the
++" field value must not break the normal path.
++func Test_ccomplete_typeref_completion_still_works()
++ let tagsfile = s:WriteTags([
++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:struct:mystruct",
++ \ "alpha\tmain.c\t/^x$/;\"\tm\tstruct:mystruct",
++ \ "beta\tmain.c\t/^x$/;\"\tm\tstruct:mystruct",
++ \ ])
++
++ let save_tags = &tags
++ let &tags = tagsfile
++
++ new
++ call ccomplete#Complete(1, '')
++ let items = ccomplete#Complete(0, 'myvar.')
++
++ call assert_equal(type([]), type(items),
++ \ 'ccomplete#Complete did not return a list')
++ let names = map(copy(items), 'v:val.word')
++ call assert_true(index(names, 'alpha') >= 0,
++ \ 'struct member "alpha" missing from completion: ' . string(names))
++ call assert_true(index(names, 'beta') >= 0,
++ \ 'struct member "beta" missing from completion: ' . string(names))
++
++ bwipe!
++ let &tags = save_tags
++endfunc
++
++" vim: shiftwidth=2 sts=2 expandtab
+--
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index ab7564c3b6..0642393db3 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -32,6 +32,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
file://CVE-2026-57456.patch \
file://CVE-2026-59856.patch \
file://CVE-2026-59857.patch \
+ file://CVE-2026-59858.patch \
"
PV .= ".0340"
--
2.43.0
^ permalink raw reply related [flat|nested] 15+ messages in thread* Re: [OE-core][wrynose][patch 10/10] vim: Fix CVE-2026-59858
2026-07-22 12:33 ` [OE-core][wrynose][patch 10/10] vim: Fix CVE-2026-59858 Vijay Anusuri
@ 2026-08-26 14:55 ` Vijay Anusuri
2026-08-26 17:00 ` Yoann Congal
0 siblings, 1 reply; 15+ messages in thread
From: Vijay Anusuri @ 2026-08-26 14:55 UTC (permalink / raw)
To: openembedded-core, Yoann Congal, Fabien Thomas
[-- Attachment #1: Type: text/plain, Size: 6896 bytes --]
Hi Team,
Any update on this?
Thanks & Regards,
Vijay
On Wed, Jul 22, 2026 at 6:04 PM Vijay Anusuri <vanusuri@mvista.com> wrote:
> Pick patch per [1].
>
> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-59858
> [2] https://security-tracker.debian.org/tracker/CVE-2026-59858
>
> Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> ---
> .../vim/files/CVE-2026-59858.patch | 134 ++++++++++++++++++
> meta/recipes-support/vim/vim.inc | 1 +
> 2 files changed, 135 insertions(+)
> create mode 100644 meta/recipes-support/vim/files/CVE-2026-59858.patch
>
> diff --git a/meta/recipes-support/vim/files/CVE-2026-59858.patch
> b/meta/recipes-support/vim/files/CVE-2026-59858.patch
> new file mode 100644
> index 0000000000..a2b903be04
> --- /dev/null
> +++ b/meta/recipes-support/vim/files/CVE-2026-59858.patch
> @@ -0,0 +1,134 @@
> +From 6b611b0d15603c52ebdad17172b0232b4f65704e Mon Sep 17 00:00:00 2001
> +From: Hirohito Higashi <h.east.727@gmail.com>
> +Date: Fri, 26 Jun 2026 15:41:24 +0900
> +Subject: [PATCH] patch 9.2.0735: [security]: arbitrary Ex command
> execution
> + during C omni-completion
> +
> +Problem: [security]: With C omni-completion, a crafted tags file can
> execute
> + arbitrary Ex commands when completing a struct/union member
> + (cipher-creator)
> +Solution: Escape the type field before inserting it into the :vimgrep
> + pattern so it cannot close the pattern and start a new command
> + (Hirohito Higashi).
> +
> +Github Security Advisory:
> +https://github.com/vim/vim/security/advisories/GHSA-mf92-v4xw-j45x
> +
> +Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>"
> +Signed-off-by: Hirohito Higashi <h.east.727@gmail.com>
> +Signed-off-by: Christian Brabandt <cb@256bit.org>
> +
> +Upstream-Status: Backport [
> https://github.com/vim/vim/commit/6b611b0d15603c52ebdad17172b0232b4f65704e
> ]
> +CVE: CVE-2026-59858
> +Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
> +---
> + runtime/autoload/ccomplete.vim | 2 +-
> + src/testdir/Make_all.mak | 2 +
> + src/testdir/test_plugin_ccomplete.vim | 62 +++++++++++++++++++++++++++
> + 3 files changed, 65 insertions(+), 1 deletion(-)
> + create mode 100644 src/testdir/test_plugin_ccomplete.vim
> +
> +diff --git a/runtime/autoload/ccomplete.vim
> b/runtime/autoload/ccomplete.vim
> +index 51237be98b..dc3388b524 100644
> +--- a/runtime/autoload/ccomplete.vim
> ++++ b/runtime/autoload/ccomplete.vim
> +@@ -600,7 +600,7 @@ def StructMembers( # {{{1
> + return []
> + endif
> + execute 'silent! keepjumps noautocmd '
> +- .. n .. 'vimgrep ' .. '/\t' .. typename .. '\(\t\|$\)/j '
> ++ .. n .. 'vimgrep ' .. '/\t' .. escape(typename, '/\') ..
> '\(\t\|$\)/j '
> + .. fnames
> +
> + qflist = getqflist()
> +diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak
> +index b5735b6c3c..0cf2c41102 100644
> +--- a/src/testdir/Make_all.mak
> ++++ b/src/testdir/Make_all.mak
> +@@ -243,6 +243,7 @@ NEW_TESTS = \
> + test_partial \
> + test_paste \
> + test_perl \
> ++ test_plugin_ccomplete \
> + test_plugin_comment \
> + test_plugin_glvs \
> + test_plugin_helpcurwin \
> +@@ -523,6 +524,7 @@ NEW_TESTS_RES = \
> + test_partial.res \
> + test_paste.res \
> + test_perl.res \
> ++ test_plugin_ccomplete.res \
> + test_plugin_comment.res \
> + test_plugin_glvs.res \
> + test_plugin_helpcurwin.res \
> +diff --git a/src/testdir/test_plugin_ccomplete.vim
> b/src/testdir/test_plugin_ccomplete.vim
> +new file mode 100644
> +index 0000000000..a635bd50bd
> +--- /dev/null
> ++++ b/src/testdir/test_plugin_ccomplete.vim
> +@@ -0,0 +1,62 @@
> ++" Tests for the C omni-completion plugin
> (runtime/autoload/ccomplete.vim).
> ++
> ++func s:WriteTags(lines)
> ++ " Mark unsorted so lookup is a linear scan regardless of entry order.
> ++ let tagsfile = tempname()
> ++ call writefile(["!_TAG_FILE_SORTED\t0\t/0/"] + a:lines, tagsfile)
> ++ return tagsfile
> ++endfunc
> ++
> ++" A crafted typeref field is interpolated into the :vimgrep pattern in
> ++" StructMembers(). Without escaping, "/" closes the pattern and "|"
> starts a
> ++" new Ex command, so the field runs as an Ex command during completion.
> ++func Test_ccomplete_no_exec_via_typeref()
> ++ unlet! g:ccomplete_injected
> ++ let tagsfile = s:WriteTags([
> ++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:x/|let
> g:ccomplete_injected = 1|\"",
> ++ \ ])
> ++
> ++ let save_tags = &tags
> ++ let &tags = tagsfile
> ++
> ++ new
> ++ call ccomplete#Complete(1, '')
> ++ call ccomplete#Complete(0, 'myvar.x')
> ++
> ++ call assert_false(exists('g:ccomplete_injected'),
> ++ \ 'typeref field was executed as an Ex command during
> omni-completion')
> ++
> ++ bwipe!
> ++ let &tags = save_tags
> ++ unlet! g:ccomplete_injected
> ++endfunc
> ++
> ++" A legitimate typeref must still drive struct-member completion:
> escaping the
> ++" field value must not break the normal path.
> ++func Test_ccomplete_typeref_completion_still_works()
> ++ let tagsfile = s:WriteTags([
> ++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:struct:mystruct",
> ++ \ "alpha\tmain.c\t/^x$/;\"\tm\tstruct:mystruct",
> ++ \ "beta\tmain.c\t/^x$/;\"\tm\tstruct:mystruct",
> ++ \ ])
> ++
> ++ let save_tags = &tags
> ++ let &tags = tagsfile
> ++
> ++ new
> ++ call ccomplete#Complete(1, '')
> ++ let items = ccomplete#Complete(0, 'myvar.')
> ++
> ++ call assert_equal(type([]), type(items),
> ++ \ 'ccomplete#Complete did not return a list')
> ++ let names = map(copy(items), 'v:val.word')
> ++ call assert_true(index(names, 'alpha') >= 0,
> ++ \ 'struct member "alpha" missing from completion: ' .
> string(names))
> ++ call assert_true(index(names, 'beta') >= 0,
> ++ \ 'struct member "beta" missing from completion: ' .
> string(names))
> ++
> ++ bwipe!
> ++ let &tags = save_tags
> ++endfunc
> ++
> ++" vim: shiftwidth=2 sts=2 expandtab
> +--
> +2.43.0
> +
> diff --git a/meta/recipes-support/vim/vim.inc
> b/meta/recipes-support/vim/vim.inc
> index ab7564c3b6..0642393db3 100644
> --- a/meta/recipes-support/vim/vim.inc
> +++ b/meta/recipes-support/vim/vim.inc
> @@ -32,6 +32,7 @@ SRC_URI = "git://
> github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
> <http://github.com/vim/vim.git;branch=master;protocol=https;tag=v$%7BPV%7D>
> file://CVE-2026-57456.patch \
> file://CVE-2026-59856.patch \
> file://CVE-2026-59857.patch \
> + file://CVE-2026-59858.patch \
> "
>
> PV .= ".0340"
> --
> 2.43.0
>
>
[-- Attachment #2: Type: text/html, Size: 8988 bytes --]
^ permalink raw reply [flat|nested] 15+ messages in thread* Re: [OE-core][wrynose][patch 10/10] vim: Fix CVE-2026-59858
2026-08-26 14:55 ` Vijay Anusuri
@ 2026-08-26 17:00 ` Yoann Congal
0 siblings, 0 replies; 15+ messages in thread
From: Yoann Congal @ 2026-08-26 17:00 UTC (permalink / raw)
To: Vijay Anusuri, openembedded-core, Fabien Thomas
On Wed Aug 26, 2026 at 4:55 PM CEST, Vijay Anusuri wrote:
> Hi Team,
>
> Any update on this?
I've answered here: https://lore.kernel.org/all/DK8UE7TFOQNN.2W9IFP8L1S2MF@smile.fr/ :
> This patch also has indentation changes between upstream patch and this
> patch.
>
> I'll hold the whole series and let you check and correct the patches.
>
> Please send a v2 of the whole series.
Please note that in the meantime I've added another vim series to my
-nut branch (not reviewed yet)
Regards,
>
> Thanks & Regards,
> Vijay
>
> On Wed, Jul 22, 2026 at 6:04 PM Vijay Anusuri <vanusuri@mvista.com> wrote:
>
>> Pick patch per [1].
>>
>> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-59858
>> [2] https://security-tracker.debian.org/tracker/CVE-2026-59858
>>
>> Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
>> ---
>> .../vim/files/CVE-2026-59858.patch | 134 ++++++++++++++++++
>> meta/recipes-support/vim/vim.inc | 1 +
>> 2 files changed, 135 insertions(+)
>> create mode 100644 meta/recipes-support/vim/files/CVE-2026-59858.patch
[...]
--
Yoann Congal
Smile ECS
^ permalink raw reply [flat|nested] 15+ messages in thread