Hi,

On investigation, i found that there are more CVEs reported for vim.
So, please ignore this submission. I'll send an updated patch series soon.


Thanks

Bhavesh Maheshwari
Engineer
+91 8827543501
[email protected]<mailto:[email protected]>
[cid:ab6810f4-c718-41d2-94de-f08096037123]<https://www.einfochips.com/>
________________________________
From: [email protected] 
<[email protected]> on behalf of bhavesh.maheshwari via 
lists.openembedded.org 
<[email protected]>
Sent: 29 July 2026 15:08
To: [email protected] 
<[email protected]>
Subject: [External] [OE-Core][wrynose][PATCH] vim: Fix for CVE-2026-57455

[You don't often get email from 
[email protected]. Learn why this is 
important at https://aka.ms/LearnAboutSenderIdentification ]

CAUTION: This email originated from outside of the organization. This message 
might not be safe, use caution in opening it. If in doubt, do not open the 
attachment nor links in the message.


From: Bhavesh R Maheshwari <[email protected]>

Pick patch from [1] also mentioned at NVD report in [2]

[1] 
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fvim%2Fvim%2Fcommit%2F497f931f85339d175d7f69588dd249e8ccfed41b&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C7060a87550a04aeea2fb08deed55257d%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639209147128824325%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=08qbWILIyYbGDpKWhYXESvo4X91nLR9CnJfoOobOD20%3D&reserved=0<https://github.com/vim/vim/commit/497f931f85339d175d7f69588dd249e8ccfed41b>
[2] 
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fnvd.nist.gov%2Fvuln%2Fdetail%2FCVE-2026-57455&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C7060a87550a04aeea2fb08deed55257d%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639209147128901047%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=P%2FBAtor%2BaS7EsBLR%2FDWpYLjJaUC1lreEMhJI5%2Bf%2FiD4%3D&reserved=0<https://nvd.nist.gov/vuln/detail/CVE-2026-57455>

Signed-off-by: Bhavesh R Maheshwari <[email protected]>
---
 .../vim/files/CVE-2026-57455.patch            | 77 +++++++++++++++++++
 meta/recipes-support/vim/vim.inc              |  1 +
 2 files changed, 78 insertions(+)
 create mode 100644 meta/recipes-support/vim/files/CVE-2026-57455.patch

diff --git a/meta/recipes-support/vim/files/CVE-2026-57455.patch 
b/meta/recipes-support/vim/files/CVE-2026-57455.patch
new file mode 100644
index 0000000000..c87b069173
--- /dev/null
+++ b/meta/recipes-support/vim/files/CVE-2026-57455.patch
@@ -0,0 +1,77 @@
+From b4ed0eb9ed412eb769a13d50932978593b062623 Mon Sep 17 00:00:00 2001
+From: Christian Brabandt <[email protected]>
+Date: Sun, 21 Jun 2026 19:20:03 +0000
+Subject: [PATCH] patch 9.2.0698: [security]: Out-of-bounds write with
+ soundfold()
+
+Problem:  [security]: Out-of-bounds write with soundfold()
+          (cipher-creator)
+Solution: Add an abort condition to the for loop to validate the buffer
+          size.
+
+Github Security Advisory:
+https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fvim%2Fvim%2Fsecurity%2Fadvisories%2FGHSA-q8mh-6qm3-25g4&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C7060a87550a04aeea2fb08deed55257d%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639209147128984009%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=EG3V0LgvUWWlS1SjN0DL78P%2BYKZaGvyGtbhd0kopT30%3D&reserved=0
+
+Supported by AI
+
+Signed-off-by: Christian Brabandt <[email protected]>
+
+CVE: CVE-2026-57455
+Upstream-Status: Backport 
[https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fvim%2Fvim%2Fcommit%2F497f931f85339d175d7f69588dd249e8ccfed41b&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C7060a87550a04aeea2fb08deed55257d%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639209147129056201%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=DWbNMW0O2TZ%2F3wpGFd1FgUlZfvoTfmAKczYJmDqlIwU%3D&reserved=0<https://github.com/vim/vim/commit/497f931f85339d175d7f69588dd249e8ccfed41b>]
+
+Backport Changes:
+- Discarded the changes from src/version.c file as it includes patch
+number
+
+Signed-off-by: Bhavesh R Maheshwari <[email protected]>
+---
+ src/spell.c                    |  2 +-
+ src/testdir/test_spellfile.vim | 21 +++++++++++++++++++++
+ 2 files changed, 22 insertions(+), 1 deletion(-)
+
+diff --git a/src/spell.c b/src/spell.c
+index 01eb57e3a..060a2251a 100644
+--- a/src/spell.c
++++ b/src/spell.c
+@@ -3270,7 +3270,7 @@ spell_soundfold_sofo(slang_T *slang, char_u *inword, 
char_u *res)
+     else
+     {
+       // The sl_sal_first[] table contains the translation.
+-      for (s = inword; (c = *s) != NUL; ++s)
++      for (s = inword; (c = *s) != NUL && ri < MAXWLEN - 1; ++s)
+       {
+           if (VIM_ISWHITE(c))
+               c = ' ';
+diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim
+index 8f3ef4907..b0b152b8c 100644
+--- a/src/testdir/test_spellfile.vim
++++ b/src/testdir/test_spellfile.vim
+@@ -1197,4 +1197,25 @@ func Test_mkspell_no_buffer_overflow()
+ endfunc
+
+
++" A word longer than MAXWLEN must not overflow the soundfold result buffer in
++" the single-byte SOFO branch of spell_soundfold_sofo().
++func Test_soundfold_overflow()
++  let _enc=&enc
++  set enc=latin1
++  call writefile(['SOFOFROM ab', 'SOFOTO xy'], 'Xtest.aff', 'D')
++  call writefile(['1', 'foo'], 'Xtest.dic', 'D')
++  mkspell! Xtest Xtest
++  defer delete('Xtest.latin1.spl')
++  defer delete('Xtest.latin1.sug')
++  setl spelllang=Xtest.latin1.spl spell
++
++  " Before the fix the copy loop wrote one byte per input byte into a
++  " MAXWLEN (254) stack buffer with no upper bound, smashing the stack.
++  let sound = soundfold(repeat('ab', 300))
++  call assert_true(strlen(sound) < 254, 'soundfold result exceeds MAXWLEN')
++
++  set spell& spelllang&
++  let &enc = _enc
++endfunc
++
+ " vim: shiftwidth=2 sts=2 expandtab
+--
+2.43.0
+
diff --git a/meta/recipes-support/vim/vim.inc b/meta/recipes-support/vim/vim.inc
index e34cc17fe5..402e39acff 100644
--- a/meta/recipes-support/vim/vim.inc
+++ b/meta/recipes-support/vim/vim.inc
@@ -23,6 +23,7 @@ SRC_URI = 
"git://github.com/vim/vim.git;branch=master;protocol=https;tag=v${PV}
            file://CVE-2026-52858.patch \
            file://CVE-2026-52859.patch \
            file://CVE-2026-52860.patch \
+           file://CVE-2026-57455.patch \
            "

 PV .= ".0340"
--
2.43.0

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#242346): 
https://lists.openembedded.org/g/openembedded-core/message/242346
Mute This Topic: https://lists.openembedded.org/mt/120500219/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • [OE-Core][wrynose][PATCH] ... bhavesh.maheshwari via lists.openembedded.org
    • Re: [OE-Core][wrynose... Bhavesh R Maheshwari via lists.openembedded.org

Reply via email to