On Wed, Aug 26, 2026 at 11:00 AM, Devansh Patel wrote: > > From: Devansh Patel <[email protected]> > > The older Vim patch 9.2.0073 fixed CVE-2026-28417 by tightening netrw > hostname validation. That CVE fix requires follow-up regression patches > because it rejects valid hostnames containing optional ports or > underscores. > > Vim 9.2.0340 already contains that CVE fix and patch 9.2.0089, which > corrects optional-port handling. It still needs patch 9.2.0553 to accept > underscores, so backport that commit and retain its _gateway regression > test. > > The netrw history hunk is adapted to preserve Wrynose's existing > multi-line history and append the upstream 2026 May 28 entry. The > src/version.c hunk is omitted because this backport does not change the > recipe version or Vim's upstream patch-number table. > > [1] https://github.com/vim/vim/commit/79348dbbc09332130f4c86045e1541d68514fcc1 > > [2] https://github.com/vim/vim/commit/a6198523fb28a50d96945458792cdb4787d3cdda > > [3] https://github.com/vim/vim/commit/93d177cd2b69bac58fc51a5a514d7bc71e264b11 > > [4] https://github.com/vim/vim/security/advisories/GHSA-m3xh-9434-g336 > > Signed-off-by: Devansh Patel <[email protected]> > --- > .../files/CVE-2026-28417-regression_p1.patch | 64 +++++++++++++++++++ > meta/recipes-support/vim/vim.inc | 1 + > 2 files changed, 65 insertions(+) > create mode 100644 > meta/recipes-support/vim/files/CVE-2026-28417-regression_p1.patch
Hi Yoann, Gentle reminder to review the above Vim regression patch when convenient. Please share your feedback. Thanks, Devansh
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#245339): https://lists.openembedded.org/g/openembedded-core/message/245339 Mute This Topic: https://lists.openembedded.org/mt/120932972/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
