Hi Team, Any update on this?
Thanks & Regards, Vijay On Thu, Jul 23, 2026 at 2:56 PM Siddharth Doshi via lists.openembedded.org <[email protected]> wrote: > From: Siddharth Doshi <[email protected]> > > Picking patch as per [1], and same patch is mentioned in [2] > > References: > [1] https://nvd.nist.gov/vuln/detail/CVE-2026-59858 > [2] https://security-tracker.debian.org/tracker/CVE-2026-59858 > > Signed-off-by: Siddharth Doshi <[email protected]> > --- > .../vim/files/CVE-2026-59858.patch | 134 ++++++++++++++++++ > meta/recipes-support/vim/vim.inc | 1 + > 2 files changed, 135 insertions(+) > create mode 100644 meta/recipes-support/vim/files/CVE-2026-59858.patch > > diff --git a/meta/recipes-support/vim/files/CVE-2026-59858.patch > b/meta/recipes-support/vim/files/CVE-2026-59858.patch > new file mode 100644 > index 0000000000..0b754ec2d3 > --- /dev/null > +++ b/meta/recipes-support/vim/files/CVE-2026-59858.patch > @@ -0,0 +1,134 @@ > +From 6b611b0d15603c52ebdad17172b0232b4f65704e Mon Sep 17 00:00:00 2001 > +From: Hirohito Higashi <[email protected]> > +Date: Fri, 26 Jun 2026 15:41:24 +0900 > +Subject: [PATCH] patch 9.2.0735: [security]: arbitrary Ex command > execution > + during C omni-completion > + > +Problem: [security]: With C omni-completion, a crafted tags file can > execute > + arbitrary Ex commands when completing a struct/union member > + (cipher-creator) > +Solution: Escape the type field before inserting it into the :vimgrep > + pattern so it cannot close the pattern and start a new command > + (Hirohito Higashi). > + > +Github Security Advisory: > +https://github.com/vim/vim/security/advisories/GHSA-mf92-v4xw-j45x > + > +Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>" > +Signed-off-by: Hirohito Higashi <[email protected]> > +Signed-off-by: Christian Brabandt <[email protected]> > + > +Upstream-Status: Backport [ > https://github.com/vim/vim/commit/6b611b0d15603c52ebdad17172b0232b4f65704e > ] > +CVE: CVE-2026-59858 > +Signed-off-by: Siddharth Doshi <[email protected]> > +--- > + runtime/autoload/ccomplete.vim | 2 +- > + src/testdir/Make_all.mak | 2 + > + src/testdir/test_plugin_ccomplete.vim | 62 +++++++++++++++++++++++++++ > + 3 files changed, 65 insertions(+), 1 deletion(-) > + create mode 100644 src/testdir/test_plugin_ccomplete.vim > + > +diff --git a/runtime/autoload/ccomplete.vim > b/runtime/autoload/ccomplete.vim > +index cb4bb2c167..248d6f2e60 100644 > +--- a/runtime/autoload/ccomplete.vim > ++++ b/runtime/autoload/ccomplete.vim > +@@ -593,7 +593,7 @@ def StructMembers( # {{{1 > + return [] > + endif > + execute 'silent! keepjumps noautocmd ' > +- .. n .. 'vimgrep ' .. '/\t' .. typename .. '\(\t\|$\)/j ' > ++ .. n .. 'vimgrep ' .. '/\t' .. escape(typename, '/\') .. > '\(\t\|$\)/j ' > + .. fnames > + > + qflist = getqflist() > +diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak > +index 7d57b2e727..681e9b3b2a 100644 > +--- a/src/testdir/Make_all.mak > ++++ b/src/testdir/Make_all.mak > +@@ -242,6 +242,7 @@ NEW_TESTS = \ > + test_partial \ > + test_paste \ > + test_perl \ > ++ test_plugin_ccomplete \ > + test_plugin_comment \ > + test_plugin_glvs \ > + test_plugin_helptoc \ > +@@ -516,6 +517,7 @@ NEW_TESTS_RES = \ > + test_partial.res \ > + test_paste.res \ > + test_perl.res \ > ++ test_plugin_ccomplete.res \ > + test_plugin_comment.res \ > + test_plugin_glvs.res \ > + test_plugin_helptoc.res \ > +diff --git a/src/testdir/test_plugin_ccomplete.vim > b/src/testdir/test_plugin_ccomplete.vim > +new file mode 100644 > +index 0000000000..a635bd50bd > +--- /dev/null > ++++ b/src/testdir/test_plugin_ccomplete.vim > +@@ -0,0 +1,62 @@ > ++" Tests for the C omni-completion plugin > (runtime/autoload/ccomplete.vim). > ++ > ++func s:WriteTags(lines) > ++ " Mark unsorted so lookup is a linear scan regardless of entry order. > ++ let tagsfile = tempname() > ++ call writefile(["!_TAG_FILE_SORTED\t0\t/0/"] + a:lines, tagsfile) > ++ return tagsfile > ++endfunc > ++ > ++" A crafted typeref field is interpolated into the :vimgrep pattern in > ++" StructMembers(). Without escaping, "/" closes the pattern and "|" > starts a > ++" new Ex command, so the field runs as an Ex command during completion. > ++func Test_ccomplete_no_exec_via_typeref() > ++ unlet! g:ccomplete_injected > ++ let tagsfile = s:WriteTags([ > ++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:x/|let > g:ccomplete_injected = 1|\"", > ++ \ ]) > ++ > ++ let save_tags = &tags > ++ let &tags = tagsfile > ++ > ++ new > ++ call ccomplete#Complete(1, '') > ++ call ccomplete#Complete(0, 'myvar.x') > ++ > ++ call assert_false(exists('g:ccomplete_injected'), > ++ \ 'typeref field was executed as an Ex command during > omni-completion') > ++ > ++ bwipe! > ++ let &tags = save_tags > ++ unlet! g:ccomplete_injected > ++endfunc > ++ > ++" A legitimate typeref must still drive struct-member completion: > escaping the > ++" field value must not break the normal path. > ++func Test_ccomplete_typeref_completion_still_works() > ++ let tagsfile = s:WriteTags([ > ++ \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:struct:mystruct", > ++ \ "alpha\tmain.c\t/^x$/;\"\tm\tstruct:mystruct", > ++ \ "beta\tmain.c\t/^x$/;\"\tm\tstruct:mystruct", > ++ \ ]) > ++ > ++ let save_tags = &tags > ++ let &tags = tagsfile > ++ > ++ new > ++ call ccomplete#Complete(1, '') > ++ let items = ccomplete#Complete(0, 'myvar.') > ++ > ++ call assert_equal(type([]), type(items), > ++ \ 'ccomplete#Complete did not return a list') > ++ let names = map(copy(items), 'v:val.word') > ++ call assert_true(index(names, 'alpha') >= 0, > ++ \ 'struct member "alpha" missing from completion: ' . > string(names)) > ++ call assert_true(index(names, 'beta') >= 0, > ++ \ 'struct member "beta" missing from completion: ' . > string(names)) > ++ > ++ bwipe! > ++ let &tags = save_tags > ++endfunc > ++ > ++" vim: shiftwidth=2 sts=2 expandtab > +-- > +2.44.4 > + > diff --git a/meta/recipes-support/vim/vim.inc > b/meta/recipes-support/vim/vim.inc > index a484a5c840..6ef9745b57 100644 > --- a/meta/recipes-support/vim/vim.inc > +++ b/meta/recipes-support/vim/vim.inc > @@ -48,6 +48,7 @@ SRC_URI = "git:// > github.com/vim/vim.git;branch=master;protocol=https \ > file://CVE-2026-57455.patch \ > file://CVE-2026-59856.patch \ > file://CVE-2026-59857.patch \ > + file://CVE-2026-59858.patch \ > " > > PV .= ".1683" > -- > 2.34.1 > > > > >
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#244401): https://lists.openembedded.org/g/openembedded-core/message/244401 Mute This Topic: https://lists.openembedded.org/mt/120408052/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
