Hi Team,

Any update on this?

Thanks & Regards,
Vijay

On Wed, Jul 22, 2026 at 6:04 PM Vijay Anusuri <[email protected]> wrote:

> Pick patch per [1].
>
> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-59858
> [2] https://security-tracker.debian.org/tracker/CVE-2026-59858
>
> Signed-off-by: Vijay Anusuri <[email protected]>
> ---
>  .../vim/files/CVE-2026-59858.patch            | 134 ++++++++++++++++++
>  meta/recipes-support/vim/vim.inc              |   1 +
>  2 files changed, 135 insertions(+)
>  create mode 100644 meta/recipes-support/vim/files/CVE-2026-59858.patch
>
> diff --git a/meta/recipes-support/vim/files/CVE-2026-59858.patch
> b/meta/recipes-support/vim/files/CVE-2026-59858.patch
> new file mode 100644
> index 0000000000..a2b903be04
> --- /dev/null
> +++ b/meta/recipes-support/vim/files/CVE-2026-59858.patch
> @@ -0,0 +1,134 @@
> +From 6b611b0d15603c52ebdad17172b0232b4f65704e Mon Sep 17 00:00:00 2001
> +From: Hirohito Higashi <[email protected]>
> +Date: Fri, 26 Jun 2026 15:41:24 +0900
> +Subject: [PATCH] patch 9.2.0735: [security]: arbitrary Ex command
> execution
> + during C omni-completion
> +
> +Problem:  [security]: With C omni-completion, a crafted tags file can
> execute
> +          arbitrary Ex commands when completing a struct/union member
> +          (cipher-creator)
> +Solution: Escape the type field before inserting it into the :vimgrep
> +          pattern so it cannot close the pattern and start a new command
> +          (Hirohito Higashi).
> +
> +Github Security Advisory:
> +https://github.com/vim/vim/security/advisories/GHSA-mf92-v4xw-j45x
> +
> +Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>"
> +Signed-off-by: Hirohito Higashi <[email protected]>
> +Signed-off-by: Christian Brabandt <[email protected]>
> +
> +Upstream-Status: Backport [
> https://github.com/vim/vim/commit/6b611b0d15603c52ebdad17172b0232b4f65704e
> ]
> +CVE: CVE-2026-59858
> +Signed-off-by: Vijay Anusuri <[email protected]>
> +---
> + runtime/autoload/ccomplete.vim        |  2 +-
> + src/testdir/Make_all.mak              |  2 +
> + src/testdir/test_plugin_ccomplete.vim | 62 +++++++++++++++++++++++++++
> + 3 files changed, 65 insertions(+), 1 deletion(-)
> + create mode 100644 src/testdir/test_plugin_ccomplete.vim
> +
> +diff --git a/runtime/autoload/ccomplete.vim
> b/runtime/autoload/ccomplete.vim
> +index 51237be98b..dc3388b524 100644
> +--- a/runtime/autoload/ccomplete.vim
> ++++ b/runtime/autoload/ccomplete.vim
> +@@ -600,7 +600,7 @@ def StructMembers( # {{{1
> +         return []
> +       endif
> +       execute 'silent! keepjumps noautocmd '
> +-        .. n .. 'vimgrep ' .. '/\t' .. typename .. '\(\t\|$\)/j '
> ++        .. n .. 'vimgrep ' .. '/\t' .. escape(typename, '/\') ..
> '\(\t\|$\)/j '
> +         .. fnames
> +
> +       qflist = getqflist()
> +diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak
> +index b5735b6c3c..0cf2c41102 100644
> +--- a/src/testdir/Make_all.mak
> ++++ b/src/testdir/Make_all.mak
> +@@ -243,6 +243,7 @@ NEW_TESTS = \
> +       test_partial \
> +       test_paste \
> +       test_perl \
> ++      test_plugin_ccomplete \
> +       test_plugin_comment \
> +       test_plugin_glvs \
> +       test_plugin_helpcurwin \
> +@@ -523,6 +524,7 @@ NEW_TESTS_RES = \
> +       test_partial.res \
> +       test_paste.res \
> +       test_perl.res \
> ++      test_plugin_ccomplete.res \
> +       test_plugin_comment.res \
> +       test_plugin_glvs.res \
> +       test_plugin_helpcurwin.res \
> +diff --git a/src/testdir/test_plugin_ccomplete.vim
> b/src/testdir/test_plugin_ccomplete.vim
> +new file mode 100644
> +index 0000000000..a635bd50bd
> +--- /dev/null
> ++++ b/src/testdir/test_plugin_ccomplete.vim
> +@@ -0,0 +1,62 @@
> ++" Tests for the C omni-completion plugin
> (runtime/autoload/ccomplete.vim).
> ++
> ++func s:WriteTags(lines)
> ++  " Mark unsorted so lookup is a linear scan regardless of entry order.
> ++  let tagsfile = tempname()
> ++  call writefile(["!_TAG_FILE_SORTED\t0\t/0/"] + a:lines, tagsfile)
> ++  return tagsfile
> ++endfunc
> ++
> ++" A crafted typeref field is interpolated into the :vimgrep pattern in
> ++" StructMembers().  Without escaping, "/" closes the pattern and "|"
> starts a
> ++" new Ex command, so the field runs as an Ex command during completion.
> ++func Test_ccomplete_no_exec_via_typeref()
> ++  unlet! g:ccomplete_injected
> ++  let tagsfile = s:WriteTags([
> ++        \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:x/|let
> g:ccomplete_injected = 1|\"",
> ++        \ ])
> ++
> ++  let save_tags = &tags
> ++  let &tags = tagsfile
> ++
> ++  new
> ++  call ccomplete#Complete(1, '')
> ++  call ccomplete#Complete(0, 'myvar.x')
> ++
> ++  call assert_false(exists('g:ccomplete_injected'),
> ++        \ 'typeref field was executed as an Ex command during
> omni-completion')
> ++
> ++  bwipe!
> ++  let &tags = save_tags
> ++  unlet! g:ccomplete_injected
> ++endfunc
> ++
> ++" A legitimate typeref must still drive struct-member completion:
> escaping the
> ++" field value must not break the normal path.
> ++func Test_ccomplete_typeref_completion_still_works()
> ++  let tagsfile = s:WriteTags([
> ++        \ "myvar\tmain.c\t/^x$/;\"\tv\ttyperef:struct:mystruct",
> ++        \ "alpha\tmain.c\t/^x$/;\"\tm\tstruct:mystruct",
> ++        \ "beta\tmain.c\t/^x$/;\"\tm\tstruct:mystruct",
> ++        \ ])
> ++
> ++  let save_tags = &tags
> ++  let &tags = tagsfile
> ++
> ++  new
> ++  call ccomplete#Complete(1, '')
> ++  let items = ccomplete#Complete(0, 'myvar.')
> ++
> ++  call assert_equal(type([]), type(items),
> ++        \ 'ccomplete#Complete did not return a list')
> ++  let names = map(copy(items), 'v:val.word')
> ++  call assert_true(index(names, 'alpha') >= 0,
> ++        \ 'struct member "alpha" missing from completion: ' .
> string(names))
> ++  call assert_true(index(names, 'beta') >= 0,
> ++        \ 'struct member "beta" missing from completion: ' .
> string(names))
> ++
> ++  bwipe!
> ++  let &tags = save_tags
> ++endfunc
> ++
> ++" vim: shiftwidth=2 sts=2 expandtab
> +--
> +2.43.0
> +
> diff --git a/meta/recipes-support/vim/vim.inc
> b/meta/recipes-support/vim/vim.inc
> index ab7564c3b6..0642393db3 100644
> --- a/meta/recipes-support/vim/vim.inc
> +++ b/meta/recipes-support/vim/vim.inc
> @@ -32,6 +32,7 @@ SRC_URI = "git://
> github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
> <http://github.com/vim/vim.git;branch=master;protocol=https;tag=v$%7BPV%7D>
>             file://CVE-2026-57456.patch \
>             file://CVE-2026-59856.patch \
>             file://CVE-2026-59857.patch \
> +           file://CVE-2026-59858.patch \
>             "
>
>  PV .= ".0340"
> --
> 2.43.0
>
>
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244402): 
https://lists.openembedded.org/g/openembedded-core/message/244402
Mute This Topic: https://lists.openembedded.org/mt/120392673/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to