mirror of
https://git.yoctoproject.org/poky
synced 2026-08-20 00:49:34 +02:00
vim: Security Fix for CVE-2026-47162
Picking patch as per [1], and same patch is mentioned in [2] References: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-47162 [2] https://security-tracker.debian.org/tracker/CVE-2026-47162 (From OE-Core rev: 2f2d13412852098c0a9c4d633d9f2f340d34b29b) Signed-off-by: Siddharth Doshi <sdoshi@mvista.com> Signed-off-by: Yoann Congal <yoann.congal@smile.fr> Signed-off-by: Paul Barker <paul@pbarker.dev>
This commit is contained in:
committed by
Paul Barker
parent
0623e8b986
commit
676f7e731a
39
meta/recipes-support/vim/files/CVE-2026-47162.patch
Normal file
39
meta/recipes-support/vim/files/CVE-2026-47162.patch
Normal file
@@ -0,0 +1,39 @@
|
||||
From d254c3b584e19555f2aecc4886ae7c92c0acc199 Mon Sep 17 00:00:00 2001
|
||||
From: Christian Brabandt <cb@256bit.org>
|
||||
Date: Sun, 17 May 2026 18:53:48 +0000
|
||||
Subject: [PATCH 04/17] patch 9.2.0495: [security]: runtime(netrw): code
|
||||
injection via NetrwBookHistSave()
|
||||
|
||||
Problem: [security]: runtime(netrw): code injection via
|
||||
NetrwBookHistSave()
|
||||
Solution: Properly quote the directory name using string() function
|
||||
(Srinivas Piskala Ganesh Babu)
|
||||
|
||||
Github Security Advisory:
|
||||
https://github.com/vim/vim/security/advisories/GHSA-crm5-rh6j-2c7c
|
||||
|
||||
Signed-off-by: Christian Brabandt <cb@256bit.org>
|
||||
|
||||
Upstream-Status: Backport [https://github.com/vim/vim/commit/f08ab2f4d7d2947c8dd6c179ae08ee6146a2694b]
|
||||
CVE: CVE-2026-47162
|
||||
Signed-off-by: Siddharth Doshi <sdoshi@mvista.com>
|
||||
---
|
||||
runtime/pack/dist/opt/netrw/autoload/netrw.vim | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/runtime/pack/dist/opt/netrw/autoload/netrw.vim b/runtime/pack/dist/opt/netrw/autoload/netrw.vim
|
||||
index e484de5c93..9014ca339b 100644
|
||||
--- a/runtime/pack/dist/opt/netrw/autoload/netrw.vim
|
||||
+++ b/runtime/pack/dist/opt/netrw/autoload/netrw.vim
|
||||
@@ -2921,7 +2921,7 @@ function s:NetrwBookHistSave()
|
||||
while ( first || cnt != g:netrw_dirhistcnt )
|
||||
let lastline= lastline + 1
|
||||
if exists("g:netrw_dirhist_{cnt}")
|
||||
- call setline(lastline,'let g:netrw_dirhist_'.cnt."='".g:netrw_dirhist_{cnt}."'")
|
||||
+ call setline(lastline,'let g:netrw_dirhist_'.cnt.'='.string(g:netrw_dirhist_{cnt}))
|
||||
endif
|
||||
let first = 0
|
||||
let cnt = ( cnt - 1 ) % g:netrw_dirhistmax
|
||||
--
|
||||
2.44.4
|
||||
|
||||
@@ -39,6 +39,7 @@ SRC_URI = "git://github.com/vim/vim.git;branch=master;protocol=https \
|
||||
file://CVE-2026-28422.patch \
|
||||
file://CVE-2026-42307.patch \
|
||||
file://CVE-2026-43961.patch \
|
||||
file://CVE-2026-47162.patch \
|
||||
"
|
||||
|
||||
PV .= ".1683"
|
||||
|
||||
Reference in New Issue
Block a user