patch 9.0.1992: [security] segfault in exmode

Commit: 
https://github.com/vim/vim/commit/20d161ace307e28690229b68584f2d84556f8960
Author: Christian Brabandt <[email protected]>
Date:   Thu Oct 5 22:08:30 2023 +0200

    patch 9.0.1992: [security] segfault in exmode
    
    Problem:  segfault in exmode when redrawing
    Solution: skip gui_scroll when exmode_active
    
    Signed-off-by: Christian Brabandt <[email protected]>

diff --git a/src/gui.c b/src/gui.c
index 1f546b2a7..9c9aa3cbe 100644
--- a/src/gui.c
+++ b/src/gui.c
@@ -4397,6 +4397,7 @@ gui_do_scrollbar(
  * Scroll a window according to the values set in the globals
  * "current_scrollbar" and "scrollbar_value".
  * Return TRUE if the cursor in the current window moved or FALSE otherwise.
+ * may eventually cause a redraw using updateWindow
  */
     int
 gui_do_scroll(void)
@@ -4416,6 +4417,9 @@ gui_do_scroll(void)
     if (wp == NULL)
        // Couldn't find window
        return FALSE;
+    // don't redraw, LineOffset and similar are not valid!
+    if (exmode_active)
+       return FALSE;
 
     /*
      * Compute number of lines to scroll.  If zero, nothing to do.
diff --git a/src/testdir/crash/crash_scrollbar 
b/src/testdir/crash/crash_scrollbar
new file mode 100644
index 000000000..1de590522
--- /dev/null
+++ b/src/testdir/crash/crash_scrollbar
@@ -0,0 +1,2 @@
+" this goes to insert mode and presses key k_VerScrollbar which may cause a 
redraw in exmode, which used ot crash Vim
+norm o€鵛
diff --git a/src/testdir/test_crash.vim b/src/testdir/test_crash.vim
index 5c83e3a2f..9a80340c2 100644
--- a/src/testdir/test_crash.vim
+++ b/src/testdir/test_crash.vim
@@ -72,6 +72,12 @@ func Test_crash1()
     \ '  || echo "crash 8: [OK]" >> X_crash1_result.txt' .. "\<cr>")
   call TermWait(buf, 3000)
 
+  let file = 'crash/crash_scrollbar'
+  let args = printf(cmn_args, vim, file)
+  call term_sendkeys(buf, args ..
+    \ '  && echo "crash 9: [OK]" >> X_crash1_result.txt' .. "\<cr>")
+  call TermWait(buf, 1000)
+
   " clean up
   exe buf .. "bw!"
 
@@ -86,6 +92,7 @@ func Test_crash1()
       \ 'crash 6: [OK]',
       \ 'crash 7: [OK]',
       \ 'crash 8: [OK]',
+      \ 'crash 9: [OK]',
       \ ]
 
   call assert_equal(expected, getline(1, '$'))
diff --git a/src/version.c b/src/version.c
index 9b1c0b4e9..2bb134a3b 100644
--- a/src/version.c
+++ b/src/version.c
@@ -704,6 +704,8 @@ static char *(features[]) =
 
 static int included_patches[] =
 {   /* Add new patch number below this line */
+/**/
+    1992,
 /**/
     1991,
 /**/

-- 
-- 
You received this message from the "vim_dev" maillist.
Do not top-post! Type your reply below the text you are replying to.
For more information, visit http://www.vim.org/maillist.php

--- 
You received this message because you are subscribed to the Google Groups 
"vim_dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/vim_dev/E1qoUkR-009TM1-Gp%40256bit.org.

Raspunde prin e-mail lui