Hi Team,

Any update on this?

Thanks & Regards,
Vijay

On Thu, Jul 23, 2026 at 2:56 PM Siddharth Doshi via lists.openembedded.org
<[email protected]> wrote:

> From: Siddharth Doshi <[email protected]>
>
> Picking patch as per [1], and same patch is mentioned in [2]
>
> References:
> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-59858
> [2] https://security-tracker.debian.org/tracker/CVE-2026-59858
>
> Signed-off-by: Siddharth Doshi <[email protected]>
> ---
>  .../vim/files/CVE-2026-59858.patch            | 134 ++++++++++++++++++
>  meta/recipes-support/vim/vim.inc              |   1 +
>  2 files changed, 135 insertions(+)
>  create mode 100644 meta/recipes-support/vim/files/CVE-2026-59858.patch
>
> diff --git a/meta/recipes-support/vim/files/CVE-2026-59858.patch
> b/meta/recipes-support/vim/files/CVE-2026-59858.patch
> new file mode 100644
> index 0000000000..0b754ec2d3
> --- /dev/null
> +++ b/meta/recipes-support/vim/files/CVE-2026-59858.patch
> @@ -0,0 +1,134 @@
> +From 6b611b0d15603c52ebdad17172b0232b4f65704e Mon Sep 17 00:00:00 2001
> +From: Hirohito Higashi <[email protected]>
> +Date: Fri, 26 Jun 2026 15:41:24 +0900
> +Subject: [PATCH] patch 9.2.0735: [security]: arbitrary Ex command
> execution
> + during C omni-completion
> +
> +Problem:  [security]: With C omni-completion, a crafted tags file can
> execute
> +          arbitrary Ex commands when completing a struct/union member
> +          (cipher-creator)
> +Solution: Escape the type field before inserting it into the :vimgrep
> +          pattern so it cannot close the pattern and start a new command
> +          (Hirohito Higashi).
> +
> +Github Security Advisory:
> +https://github.com/vim/vim/security/advisories/GHSA-mf92-v4xw-j45x
> +
> +Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>"
> +Signed-off-by: Hirohito Higashi <[email protected]>
> +Signed-off-by: Christian Brabandt <[email protected]>
> +
> +Upstream-Status: Backport [
> https://github.com/vim/vim/commit/6b611b0d15603c52ebdad17172b0232b4f65704e
> ]
> +CVE: CVE-2026-59858
> +Signed-off-by: Siddharth Doshi <[email protected]>
> +---
> + runtime/autoload/ccomplete.vim        |  2 +-
> + src/testdir/Make_all.mak              |  2 +
> + src/testdir/test_plugin_ccomplete.vim | 62 +++++++++++++++++++++++++++
> + 3 files changed, 65 insertions(+), 1 deletion(-)
> + create mode 100644 src/testdir/test_plugin_ccomplete.vim
> +
> +diff --git a/runtime/autoload/ccomplete.vim
> b/runtime/autoload/ccomplete.vim
> +index cb4bb2c167..248d6f2e60 100644
> +--- a/runtime/autoload/ccomplete.vim
> ++++ b/runtime/autoload/ccomplete.vim
> +@@ -593,7 +593,7 @@ def StructMembers( # {{{1
> +         return []
> +       endif
> +       execute 'silent! keepjumps noautocmd '
> +-        .. n .. 'vimgrep ' .. '/\t' .. typename .. '\(\t\|$\)/j '
> ++        .. n .. 'vimgrep ' .. '/\t' .. escape(typename, '/\') ..
> '\(\t\|$\)/j '
> +         .. fnames
> +
> +       qflist = getqflist()
> +diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak
> +index 7d57b2e727..681e9b3b2a 100644
> +--- a/src/testdir/Make_all.mak
> ++++ b/src/testdir/Make_all.mak
> +@@ -242,6 +242,7 @@ NEW_TESTS = \
> +       test_partial \
> +       test_paste \
> +       test_perl \
> ++      test_plugin_ccomplete \
> +       test_plugin_comment \
> +       test_plugin_glvs \
> +       test_plugin_helptoc \
> +@@ -516,6 +517,7 @@ NEW_TESTS_RES = \
> +       test_partial.res \
> +       test_paste.res \
> +       test_perl.res \
> ++      test_plugin_ccomplete.res \
> +       test_plugin_comment.res \
> +       test_plugin_glvs.res \
> +       test_plugin_helptoc.res \
> +diff --git a/src/testdir/test_plugin_ccomplete.vim
> b/src/testdir/test_plugin_ccomplete.vim
> +new file mode 100644
> +index 0000000000..a635bd50bd
> +--- /dev/null
> ++++ b/src/testdir/test_plugin_ccomplete.vim
> +@@ -0,0 +1,62 @@
> ++" Tests for the C omni-completion plugin
> (runtime/autoload/ccomplete.vim).
> ++
> ++func s:WriteTags(lines)
> ++  " Mark unsorted so lookup is a linear scan regardless of entry order.
> ++  let tagsfile = tempname()
> ++  call writefile(["!_TAG_FILE_SORTED\t0\t/0/"] + a:lines, tagsfile)
> ++  return tagsfile
> ++endfunc
> ++
> ++" A crafted typeref field is interpolated into the :vimgrep pattern in
> ++" StructMembers().  Without escaping, "/" closes the pattern and "|"
> starts a
> ++" new Ex command, so the field runs as an Ex command during completion.
> ++func Test_ccomplete_no_exec_via_typeref()
> ++  unlet! g:ccomplete_injected
> ++  let tagsfile = s:WriteTags([
> ++        \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:x/|let
> g:ccomplete_injected = 1|\"",
> ++        \ ])
> ++
> ++  let save_tags = &tags
> ++  let &tags = tagsfile
> ++
> ++  new
> ++  call ccomplete#Complete(1, '')
> ++  call ccomplete#Complete(0, 'myvar.x')
> ++
> ++  call assert_false(exists('g:ccomplete_injected'),
> ++        \ 'typeref field was executed as an Ex command during
> omni-completion')
> ++
> ++  bwipe!
> ++  let &tags = save_tags
> ++  unlet! g:ccomplete_injected
> ++endfunc
> ++
> ++" A legitimate typeref must still drive struct-member completion:
> escaping the
> ++" field value must not break the normal path.
> ++func Test_ccomplete_typeref_completion_still_works()
> ++  let tagsfile = s:WriteTags([
> ++        \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:struct:mystruct",
> ++        \ "alpha\tmain.c\t/^x$/;\"\tm\tstruct:mystruct",
> ++        \ "beta\tmain.c\t/^x$/;\"\tm\tstruct:mystruct",
> ++        \ ])
> ++
> ++  let save_tags = &tags
> ++  let &tags = tagsfile
> ++
> ++  new
> ++  call ccomplete#Complete(1, '')
> ++  let items = ccomplete#Complete(0, 'myvar.')
> ++
> ++  call assert_equal(type([]), type(items),
> ++        \ 'ccomplete#Complete did not return a list')
> ++  let names = map(copy(items), 'v:val.word')
> ++  call assert_true(index(names, 'alpha') >= 0,
> ++        \ 'struct member "alpha" missing from completion: ' .
> string(names))
> ++  call assert_true(index(names, 'beta') >= 0,
> ++        \ 'struct member "beta" missing from completion: ' .
> string(names))
> ++
> ++  bwipe!
> ++  let &tags = save_tags
> ++endfunc
> ++
> ++" vim: shiftwidth=2 sts=2 expandtab
> +--
> +2.44.4
> +
> diff --git a/meta/recipes-support/vim/vim.inc
> b/meta/recipes-support/vim/vim.inc
> index a484a5c840..6ef9745b57 100644
> --- a/meta/recipes-support/vim/vim.inc
> +++ b/meta/recipes-support/vim/vim.inc
> @@ -48,6 +48,7 @@ SRC_URI = "git://
> github.com/vim/vim.git;branch=master;protocol=https \
>             file://CVE-2026-57455.patch \
>             file://CVE-2026-59856.patch \
>             file://CVE-2026-59857.patch \
> +           file://CVE-2026-59858.patch \
>             "
>
>  PV .= ".1683"
> --
> 2.34.1
>
>
> 
>
>
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244401): 
https://lists.openembedded.org/g/openembedded-core/message/244401
Mute This Topic: https://lists.openembedded.org/mt/120408052/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to