From: Siddharth Doshi <[email protected]> Picking patch as per [1], and same patch is mentioned in [2]
References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-42307 [2] https://security-tracker.debian.org/tracker/CVE-2026-42307 Signed-off-by: Siddharth Doshi <[email protected]> Signed-off-by: Yoann Congal <[email protected]> --- .../vim/files/CVE-2026-42307.patch | 177 ++++++++++++++++++ meta/recipes-support/vim/vim.inc | 1 + 2 files changed, 178 insertions(+) create mode 100644 meta/recipes-support/vim/files/CVE-2026-42307.patch diff --git a/meta/recipes-support/vim/files/CVE-2026-42307.patch b/meta/recipes-support/vim/files/CVE-2026-42307.patch new file mode 100644 index 00000000000..037f6cba273 --- /dev/null +++ b/meta/recipes-support/vim/files/CVE-2026-42307.patch @@ -0,0 +1,177 @@ +From 405e2fb6d54d5653523809e2853d99d1c000a5fc Mon Sep 17 00:00:00 2001 +From: Christian Brabandt <[email protected]> +Date: Tue, 21 Apr 2026 19:03:02 +0000 +Subject: [PATCH] patch 9.2.0383: [security]: runtime(netrw): shell-injection + via sftp: and file: URLs + +Problem: runtime(netrw): shell-injection via sftp: and file: URLs + (Joshua Rogers) +Solution: Escape temporary file names, harden filename suffix regex, + drop unused g:netrw_tmpfile_escape variable + +Supported by AI + +Signed-off-by: Christian Brabandt <[email protected]> + +Upstream-Status: Backport [https://github.com/vim/vim/commit/405e2fb6d54d5653523809e2853d99d1c000a5fc] +CVE: CVE-2026-42307 +Signed-off-by: Siddharth Doshi <[email protected]> +--- + runtime/doc/pi_netrw.txt | 4 --- + runtime/doc/tags | 1 - + .../pack/dist/opt/netrw/autoload/netrw.vim | 16 +++++----- + runtime/pack/dist/opt/netrw/doc/netrw.txt | 4 --- + src/testdir/test_plugin_netrw.vim | 30 +++++++++++++++++++ + src/version.c | 2 ++ + 6 files changed, 41 insertions(+), 16 deletions(-) + +diff --git a/runtime/doc/pi_netrw.txt b/runtime/doc/pi_netrw.txt +index a86cac36ba..2d98a8407b 100644 +--- a/runtime/doc/pi_netrw.txt ++++ b/runtime/doc/pi_netrw.txt +@@ -2854,10 +2854,6 @@ your browsing preferences. (see also: |netrw-settings|) + such as listing, file removal, etc. + default: ssh + +- *g:netrw_tmpfile_escape* =' &;' +- escape() is applied to all temporary files +- to escape these characters. +- + *g:netrw_timefmt* specify format string to vim's strftime(). + The default, "%c", is "the preferred date + and time representation for the current +diff --git a/runtime/doc/tags b/runtime/doc/tags +index 1e0720b21a..023996c0eb 100644 +--- a/runtime/doc/tags ++++ b/runtime/doc/tags +@@ -7966,7 +7966,6 @@ g:netrw_ssh_browse_reject pi_netrw.txt /*g:netrw_ssh_browse_reject* + g:netrw_ssh_cmd pi_netrw.txt /*g:netrw_ssh_cmd* + g:netrw_sshport pi_netrw.txt /*g:netrw_sshport* + g:netrw_timefmt pi_netrw.txt /*g:netrw_timefmt* +-g:netrw_tmpfile_escape pi_netrw.txt /*g:netrw_tmpfile_escape* + g:netrw_uid pi_netrw.txt /*g:netrw_uid* + g:netrw_use_noswf pi_netrw.txt /*g:netrw_use_noswf* + g:netrw_use_nt_rcp pi_netrw.txt /*g:netrw_use_nt_rcp* +diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +index 8e5fdb5397..78ce0cbc3c 100644 +--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim ++++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim +@@ -398,7 +398,6 @@ else + call s:NetrwInit("g:netrw_glob_escape",'*[]?`{~$\') + endif + call s:NetrwInit("g:netrw_menu_escape",'.&? \') +-call s:NetrwInit("g:netrw_tmpfile_escape",' &;') + call s:NetrwInit("s:netrw_map_escape","<|\n\r\\\<C-V>\"") + if has("gui_running") && (&enc == 'utf-8' || &enc == 'utf-16' || &enc == 'ucs-4') + let s:treedepthstring= "│ " +@@ -1819,14 +1818,14 @@ function netrw#NetRead(mode,...) + "......................................... + " NetRead: (sftp) NetRead Method #9 {{{3 + elseif b:netrw_method == 9 +- call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_sftp_cmd." ".netrw#os#Escape(g:netrw_machine.":".b:netrw_fname,1)." ".tmpfile) ++ call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_sftp_cmd." ".netrw#os#Escape(g:netrw_machine.":".b:netrw_fname,1)." ".netrw#os#Escape(tmpfile,1)) + let result = s:NetrwGetFile(readcmd, tmpfile, b:netrw_method) + let b:netrw_lastfile = choice + + "......................................... + " NetRead: (file) NetRead Method #10 {{{3 + elseif b:netrw_method == 10 && exists("g:netrw_file_cmd") +- call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_file_cmd." ".netrw#os#Escape(b:netrw_fname,1)." ".tmpfile) ++ call netrw#os#Execute(s:netrw_silentxfer."!".g:netrw_file_cmd." ".netrw#os#Escape(b:netrw_fname,1)." ".netrw#os#Escape(tmpfile,1)) + let result = s:NetrwGetFile(readcmd, tmpfile, b:netrw_method) + let b:netrw_lastfile = choice + +@@ -8959,14 +8958,17 @@ function s:GetTempfile(fname) + endif + + " use fname's suffix for the temporary file ++ " Restrict the suffix to word characters so shell metacharacters in a ++ " remote filename (e.g. sftp://host/foo.txt;id) cannot ride along into ++ " the tempfile name and out into a downstream shell command. + if a:fname != "" +- if a:fname =~ '\.[^./]\+$' ++ if a:fname =~ '\.\w\+$' + if a:fname =~ '\.tar\.gz$' || a:fname =~ '\.tar\.bz2$' || a:fname =~ '\.tar\.xz$' +- let suffix = ".tar".substitute(a:fname,'^.*\(\.[^./]\+\)$','\1','e') ++ let suffix = ".tar".substitute(a:fname,'^.*\(\.\w\+\)$','\1','e') + elseif a:fname =~ '.txz$' +- let suffix = ".txz".substitute(a:fname,'^.*\(\.[^./]\+\)$','\1','e') ++ let suffix = ".txz".substitute(a:fname,'^.*\(\.\w\+\)$','\1','e') + else +- let suffix = substitute(a:fname,'^.*\(\.[^./]\+\)$','\1','e') ++ let suffix = substitute(a:fname,'^.*\(\.\w\+\)$','\1','e') + endif + let tmpfile= substitute(tmpfile,'\.tmp$','','e') + let tmpfile .= suffix +diff --git a/runtime/pack/dist/opt/netrw/doc/netrw.txt b/runtime/pack/dist/opt/netrw/doc/netrw.txt +index 01a5bda597..144bab5fb3 100644 +--- a/runtime/pack/dist/opt/netrw/doc/netrw.txt ++++ b/runtime/pack/dist/opt/netrw/doc/netrw.txt +@@ -2854,10 +2854,6 @@ your browsing preferences. (see also: |netrw-settings|) + such as listing, file removal, etc. + default: ssh + +- *g:netrw_tmpfile_escape* =' &;' +- escape() is applied to all temporary files +- to escape these characters. +- + *g:netrw_timefmt* specify format string to vim's strftime(). + The default, "%c", is "the preferred date + and time representation for the current +diff --git a/src/testdir/test_plugin_netrw.vim b/src/testdir/test_plugin_netrw.vim +index b234670928..6be32911ce 100644 +--- a/src/testdir/test_plugin_netrw.vim ++++ b/src/testdir/test_plugin_netrw.vim +@@ -604,6 +604,36 @@ func Test_netrw_FileUrlEdit_pipe_injection() + call assert_false(filereadable(fname), 'Command injection via pipe in file URL') + endfunc + ++" The remote filename after '.' was allowed to contain shell metacharacters ++" and rode unescaped into the tempfile name passed to sftp/file_cmd, giving a ++" shell injection on :e sftp://host/foo.txt;<cmd>. ++func Test_netrw_tempfile_suffix_injection() ++ CheckUnix ++ CheckExecutable id ++ let save_sftp = g:netrw_sftp_cmd ++ let save_file = exists('g:netrw_file_cmd') ? g:netrw_file_cmd : v:null ++ let g:netrw_sftp_cmd = 'true' ++ let g:netrw_file_cmd = 'true' ++ let fname = 'Xrce_marker' ++ try ++ call delete(fname) ++ sil! call netrw#NetRead(2, 'sftp://localhost/foo.txt;id>'..fname) ++ call assert_false(filereadable(fname), 'Command injection via sftp:// tempfile suffix') ++ ++ call delete(fname) ++ sil! call netrw#NetRead(2, 'file://localhost/foo.txt;id>'..fname) ++ call assert_false(filereadable(fname), 'Command injection via file:// tempfile suffix') ++ finally ++ call delete(fname) ++ let g:netrw_sftp_cmd = save_sftp ++ if save_file is v:null ++ unlet! g:netrw_file_cmd ++ else ++ let g:netrw_file_cmd = save_file ++ endif ++ endtry ++endfunc ++ + func Test_netrw_RFC2396() + let fname = 'a%20b' + call assert_equal('a b', netrw#RFC2396(fname)) +diff --git a/src/version.c b/src/version.c +index 560233fafc..4508ae3f18 100644 +--- a/src/version.c ++++ b/src/version.c +@@ -734,6 +734,8 @@ static char *(features[]) = + + static int included_patches[] = + { /* Add new patch number below this line */ ++/**/ ++ 383, + /**/ + 340, + /**/ +-- +2.34.1 + diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc index e34cc17fe57..0ad78ab4f08 100644 --- a/meta/recipes-support/vim/vim.inc +++ b/meta/recipes-support/vim/vim.inc @@ -23,6 +23,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV} file://CVE-2026-52858.patch \ file://CVE-2026-52859.patch \ file://CVE-2026-52860.patch \ + file://CVE-2026-42307.patch \ " PV .= ".0340"
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#242148): https://lists.openembedded.org/g/openembedded-core/message/242148 Mute This Topic: https://lists.openembedded.org/mt/120476114/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
