On Wed Sep 2, 2026 at 10:55 AM CEST, Bhavesh R Maheshwari via 
lists.openembedded.org wrote:
> From: Bhavesh R Maheshwari <[email protected]>
>
> Pick the patch from [1], also referenced in the NVD report [2].
>
> [1] https://github.com/vim/vim/commit/f8126294a526aa80c5123eb3079e325daee9ec75
> [2] https://nvd.nist.gov/vuln/detail/CVE-2026-73071
>
> Signed-off-by: Bhavesh R Maheshwari <[email protected]>
> ---
>  .../vim/files/CVE-2026-73071.patch            | 128 ++++++++++++++++++
>  meta/recipes-support/vim/vim.inc              |   1 +
>  2 files changed, 129 insertions(+)
>  create mode 100644 meta/recipes-support/vim/files/CVE-2026-73071.patch
>
> diff --git a/meta/recipes-support/vim/files/CVE-2026-73071.patch 
> b/meta/recipes-support/vim/files/CVE-2026-73071.patch
> new file mode 100644
> index 0000000000..6012bfd396
> --- /dev/null
> +++ b/meta/recipes-support/vim/files/CVE-2026-73071.patch
> @@ -0,0 +1,128 @@
> +From f09adcf1b1a876e8a9b00a7b3ea15865ff194aad Mon Sep 17 00:00:00 2001
> +From: Yasuhiro Matsumoto <[email protected]>
> +Date: Thu, 16 Jul 2026 18:39:24 +0900
> +Subject: [PATCH] patch 9.2.0844: [security]: use-after-free on json decode
> + error
> +
> +Problem:  [security]: use-after-free on json decode error
> +          (@tdjackey)
> +Solution: Report the position from the current reader
> +          (Matsumoto Yasuhiro)
> +
> +json_decode_item() caches "p" into js_buf, but json_decode_string() can
> +refill via channel_fill(), which frees the old js_buf. When the string
> +parse then fails (e.g. an invalid \u escape), the shared error path passed
> +the now-dangling "p" to semsg(), a heap use-after-free read reachable
> +pre-auth through the socketserver.
> +
> +Github Security Advisory:
> +https://github.com/vim/vim/security/advisories/GHSA-69ch-22ch-r887
> +
> +Signed-off-by: Yasuhiro Matsumoto <[email protected]>
> +Signed-off-by: Christian Brabandt <[email protected]>
> +
> +Upstream-Status: Backport 
> [https://github.com/vim/vim/commit/f8126294a526aa80c5123eb3079e325daee9ec75]
> +CVE: CVE-2026-73071
> +
> +Signed-off-by: Bhavesh R Maheshwari <[email protected]>
> +---
> + src/json.c                        |  4 ++-
> + src/testdir/test_clientserver.vim | 53 +++++++++++++++++++++++++++++++
> + src/version.c                     |  2 ++
> + 3 files changed, 58 insertions(+), 1 deletion(-)
> +
> +diff --git a/src/version.c b/src/version.c
> +index 92cd53129..43e4bb45b 100644
> +--- a/src/version.c
> ++++ b/src/version.c
> +@@ -734,6 +734,8 @@ static char *(features[]) =
> + 
> + static int included_patches[] =
> + {   /* Add new patch number below this line */
> ++/**/
> ++    844,

Hello,

Looks like this patch does not apply cleanly:
    NOTE: recipe vim-tiny-9.2.0340-r0: task do_patch: Started
    ERROR: vim-9.2.0340-r0 do_patch: QA Issue: Fuzz detected:

    Applying patch CVE-2026-73071.patch
    patching file src/json.c
    patching file src/testdir/test_clientserver.vim
    patching file src/version.c
    Hunk #1 succeeded at 734 with fuzz 2.

Can you rebase/refresh and resend?

In this case, do think you can drop the version.c update? Is this
included_patches list used meaningfully? If not, let's drop it, this is
bound to create conflicts...

Thanks!
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#245972): 
https://lists.openembedded.org/g/openembedded-core/message/245972
Mute This Topic: https://lists.openembedded.org/mt/121048091/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to