import UBI vim-9.1.083-9.el10_2.7

This commit is contained in:
AlmaLinux RelEng Bot 2026-07-13 12:15:22 -04:00
parent 0bf21c1f3d
commit 111a6062a1
6 changed files with 475 additions and 1 deletions

View File

@ -0,0 +1,67 @@
diff --git a/runtime/autoload/tar.vim b/runtime/autoload/tar.vim
index a3abbc7..c8d5d03 100644
--- a/runtime/autoload/tar.vim
+++ b/runtime/autoload/tar.vim
@@ -780,9 +780,9 @@ fun! tar#Vimuntar(...)
" if necessary, decompress the tarball; then, extract it
if tartail =~ '\.tgz'
if executable("gunzip")
- silent exe "!gunzip ".shellescape(tartail)
+ silent exe "!gunzip ".shellescape(tartail, 1)
elseif executable("gzip")
- silent exe "!gzip -d ".shellescape(tartail)
+ silent exe "!gzip -d ".shellescape(tartail, 1)
else
echoerr "unable to decompress<".tartail."> on this system"
if simplify(curdir) != simplify(tarhome)
diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak
index 8dd04e7..2b3d16d 100644
--- a/src/testdir/Make_all.mak
+++ b/src/testdir/Make_all.mak
@@ -227,6 +227,7 @@ NEW_TESTS = \
test_partial \
test_paste \
test_perl \
+ test_plugin_tar \
test_plus_arg_edit \
test_popup \
test_popupwin \
@@ -476,6 +477,7 @@ NEW_TESTS_RES = \
test_partial.res \
test_paste.res \
test_perl.res \
+ test_plugin_tar.res \
test_plus_arg_edit.res \
test_popup.res \
test_popupwin.res \
diff --git a/src/testdir/test_plugin_tar.vim b/src/testdir/test_plugin_tar.vim
new file mode 100644
index 0000000..5e712df
--- /dev/null
+++ b/src/testdir/test_plugin_tar.vim
@@ -0,0 +1,25 @@
+vim9script
+
+source check.vim
+CheckNotMSWindows
+
+runtime plugin/tarPlugin.vim
+
+def g:Test_extract_command_injection()
+ CheckExecutable gunzip
+ CheckExecutable touch
+ var tgz = eval('0z1F8B08087795056A000364756D6D792E74617200EDCE2B12C2300004D01C254' ..
+ '7480269CE534080A8495BD1DBF3996106C3A08A7ACFACD8157B59A7690BFB4A0FC3707C666E357D' ..
+ 'E65BC8B5A47CC8A5D61A522EA5B510D3CEBF5ED679197B8CE17CEDB7F9D4C76FBB5F3D000000000' ..
+ '000000000FCD11D32415E2C00280000')
+ var dirname = tempname()
+
+ mkdir(dirname, 'R')
+ var tar = dirname .. "/';%$(touch pwned)'.tgz"
+ writefile(tgz, tar)
+ new
+ exe "e " .. fnameescape(tar)
+ exe ":Vimuntar " .. dirname
+ assert_false(filereadable(dirname .. "/pwned"))
+ bw!
+enddef

View File

@ -0,0 +1,63 @@
diff -up vim91/runtime/autoload/netrw.vim.netrw-hist-inject vim91/runtime/autoload/netrw.vim
--- vim91/runtime/autoload/netrw.vim.netrw-hist-inject 2026-07-01 14:34:45.906873026 +0200
+++ vim91/runtime/autoload/netrw.vim 2026-07-01 14:34:45.945873081 +0200
@@ -3803,7 +3803,7 @@ fun! s:NetrwBookHistSave()
while ( first || cnt != g:netrw_dirhistcnt )
let lastline= lastline + 1
if exists("g:netrw_dirhist_{cnt}")
- call setline(lastline,'let g:netrw_dirhist_'.cnt."='".g:netrw_dirhist_{cnt}."'")
+ call setline(lastline,'let g:netrw_dirhist_'.cnt.'='.string(g:netrw_dirhist_{cnt}))
" call Decho("..".lastline.'let g:netrw_dirhist_'.cnt."='".g:netrw_dirhist_{cnt}."'",'~'.expand("<slnum>"))
endif
let first = 0
diff -up vim91/src/testdir/Make_all.mak.netrw-hist-inject vim91/src/testdir/Make_all.mak
--- vim91/src/testdir/Make_all.mak.netrw-hist-inject 2026-07-01 14:34:45.943414655 +0200
+++ vim91/src/testdir/Make_all.mak 2026-07-01 14:37:15.027745781 +0200
@@ -227,6 +227,7 @@ NEW_TESTS = \
test_partial \
test_paste \
test_perl \
+ test_plugin_netrw \
test_plugin_tar \
test_plus_arg_edit \
test_popup \
@@ -477,6 +478,7 @@ NEW_TESTS_RES = \
test_partial.res \
test_paste.res \
test_perl.res \
+ test_plugin_netrw.res \
test_plugin_tar.res \
test_plus_arg_edit.res \
test_popup.res \
diff -up vim91/src/testdir/test_plugin_netrw.vim.netrw-hist-inject vim91/src/testdir/test_plugin_netrw.vim
--- vim91/src/testdir/test_plugin_netrw.vim.netrw-hist-inject 2026-07-01 14:34:45.947844274 +0200
+++ vim91/src/testdir/test_plugin_netrw.vim 2026-07-01 14:34:45.947839295 +0200
@@ -0,0 +1,28 @@
+const s:testdir = expand("<script>:h")
+const s:runtimedir = simplify(s:testdir . '/../../runtime')
+
+func SetUp()
+ let &runtimepath = s:runtimedir
+ runtime autoload/netrw.vim
+endfunction
+
+func Test_netrw_injection()
+ let g:netrw_home = getcwd()
+ let savefile = g:netrw_home . '/.netrwhist'
+ let g:netrw_dirhistmax = 10
+ let g:netrw_dirhistcnt = 1
+ let g:netrw_dirhist_1 = "x'|let g:injected = 1|let y='z"
+ call delete(savefile)
+ try
+ call netrw#Call('NetrwBookHistSave')
+ call assert_true(filereadable(savefile), savefile . ' must be written')
+ unlet g:netrw_dirhist_1
+ execute 'source ' . fnameescape(savefile)
+ call assert_false(exists("g:injected"), 'injected statement must not execute')
+ call assert_equal("x'|let g:injected = 1|let y='z", g:netrw_dirhist_1, 'dirname must round-trip')
+ finally
+ call delete(savefile)
+ unlet! g:netrw_home g:netrw_dirhistmax g:netrw_dirhistcnt g:netrw_dirhist_1 g:injected
+ endtry
+endfunc
+" vim:ts=8 sts=2 sw=2 et

View File

@ -0,0 +1,52 @@
diff -up vim91/runtime/ftplugin/cucumber.vim.cucumber-code-inject vim91/runtime/ftplugin/cucumber.vim
--- vim91/runtime/ftplugin/cucumber.vim.cucumber-code-inject 2024-02-09 06:33:54.000000000 +0100
+++ vim91/runtime/ftplugin/cucumber.vim 2026-06-30 15:39:27.581293444 +0200
@@ -96,7 +96,8 @@ function! s:stepmatch(receiver,target)
catch
endtry
if has("ruby") && pattern !~ '\\\@<!#{'
- ruby VIM.command("return #{if (begin; Kernel.eval('/'+VIM.evaluate('pattern')+'/'); rescue SyntaxError; end) === VIM.evaluate('a:target') then 1 else 0 end}")
+ " Use Regexp.new, so the pattern stays untrusted data and cannot inject Ruby
+ ruby VIM.command("return #{if (begin; Regexp.new(VIM.evaluate('pattern')); rescue RegexpError; end) === VIM.evaluate('a:target') then 1 else 0 end}")
else
return 0
endif
diff -up vim91/src/testdir/test_filetype.vim.cucumber-code-inject vim91/src/testdir/test_filetype.vim
--- vim91/src/testdir/test_filetype.vim.cucumber-code-inject 2024-02-09 06:33:54.000000000 +0100
+++ vim91/src/testdir/test_filetype.vim 2026-06-30 15:39:58.032115889 +0200
@@ -2413,4 +2413,35 @@ func Test_def_file()
filetype off
endfunc
+func Test_cucumber_code_injection()
+ source check.vim
+ CheckFeature ruby
+ filetype plugin on
+
+ call mkdir('Xcucu/features/step_definitions', 'pR')
+ call writefile([
+ \ 'Feature: demo',
+ \ ' Scenario: trigger',
+ \ ' Given xyzzy',
+ \ ], 'Xcucu/features/test.feature')
+ let marker = getcwd() . '/Xcucu/MARKER'
+ " Malicious step: terminates the regex literal, injects Ruby system(),
+ " comments the trailing slash. With the fix, the pattern is passed to
+ " Regexp.new() instead of Kernel.eval() and the payload is inert.
+ call writefile([
+ \ 'Given /xyzzy/; system("touch ' . marker . '"); #/ do',
+ \ 'end',
+ \ ], 'Xcucu/features/step_definitions/poc.rb')
+
+ new Xcucu/features/test.feature
+ call assert_equal('cucumber', &filetype)
+ call cursor(3, 1)
+ " Triggers s:jump -> s:steps -> s:stepmatch on every discovered step,
+ " including the malicious one. Suppress preview and error messages.
+ silent! normal [d
+ call assert_false(filereadable(marker), 'Ruby injection executed')
+ bwipe!
+ filetype plugin off
+endfunc
+
" vim: shiftwidth=2 sts=2 expandtab

View File

@ -0,0 +1,163 @@
From 54d6db77e26d1567e3c67d6f8a56738b46bf25ce Mon Sep 17 00:00:00 2001
From: Christian Brabandt <cb@256bit.org>
Date: Fri, 29 May 2026 19:05:53 +0000
Subject: [PATCH] patch 9.2.0561: [security]: possible code execution with
python3complete
Problem: [security]: possible code execution with python3complete
Solution: Disable execution of import/from statements
Github Security Advisory:
https://github.com/vim/vim/security/advisories/GHSA-52mc-rq6p-rc7c
Signed-off-by: Christian Brabandt <cb@256bit.org>
---
runtime/autoload/README.txt | 1 +
runtime/autoload/python3complete.vim | 17 ++++++++++++++---
runtime/autoload/pythoncomplete.vim | 17 ++++++++++++++---
runtime/doc/filetype.txt | 15 ++++++++++++++-
4 files changed, 43 insertions(+), 7 deletions(-)
diff --git a/runtime/autoload/README.txt b/runtime/autoload/README.txt
index 3b18d3dde..b22581963 100644
--- a/runtime/autoload/README.txt
+++ b/runtime/autoload/README.txt
@@ -17,6 +17,7 @@ htmlcomplete.vim HTML
javascriptcomplete.vim Javascript
phpcomplete.vim PHP
pythoncomplete.vim Python
+python3complete.vim Python
rubycomplete.vim Ruby
syntaxcomplete.vim from syntax highlighting
xmlcomplete.vim XML (uses files in the xml directory)
diff --git a/runtime/autoload/python3complete.vim b/runtime/autoload/python3complete.vim
index ea0a33136..aba341229 100644
--- a/runtime/autoload/python3complete.vim
+++ b/runtime/autoload/python3complete.vim
@@ -14,6 +14,10 @@
" i.e. "import url<c-x,c-o>"
" Continue parsing on invalid line??
"
+" v 0.10 by Vim project
+" * disables importing local modules, unless the global Vim variable
+" g:pythoncomplete_allow_import is set to non-zero
+"
" v 0.9
" * Fixed docstring parsing for classes and functions
" * Fixed parsing of *args and **kwargs type arguments
@@ -132,11 +136,20 @@ class Completer(object):
def evalsource(self,text,line=0):
sc = self.parser.parse(text,line)
+ try: allow_imports = int(
+ vim.eval("get(g:, 'pythoncomplete_allow_import', 0)"))
+ except Exception:
+ allow_imports = 0
src = sc.get_code()
dbg("source: %s" % src)
try: exec(src,self.compldict)
except: dbg("parser: %s, %s" % (sys.exc_info()[0],sys.exc_info()[1]))
for l in sc.locals:
+ # Executing import/from statements harvested from the buffer runs
+ # arbitrary package code; only do so when the user opted in.
+ if not allow_imports and (l.startswith('import')
+ or l.startswith('from ')):
+ continue
try: exec(l,self.compldict)
except: dbg("locals: %s, %s [%s]" % (sys.exc_info()[0],sys.exc_info()[1],l))
@@ -300,13 +313,11 @@ class Scope(object):
def get_code(self):
str = ""
if len(self.docstr) > 0: str += '"""'+self.docstr+'"""\n'
- for l in self.locals:
- if l.startswith('import'): str += l+'\n'
str += 'class _PyCmplNoType:\n def __getattr__(self,name):\n return None\n'
for sub in self.subscopes:
str += sub.get_code()
for l in self.locals:
- if not l.startswith('import'): str += l+'\n'
+ if not l.startswith('import') and not l.startswith('from '): str += l+'\n'
return str
diff --git a/runtime/autoload/pythoncomplete.vim b/runtime/autoload/pythoncomplete.vim
index aa28bb721..10147767e 100644
--- a/runtime/autoload/pythoncomplete.vim
+++ b/runtime/autoload/pythoncomplete.vim
@@ -12,6 +12,10 @@
" i.e. "import url<c-x,c-o>"
" Continue parsing on invalid line??
"
+" v 0.10 by Vim project
+" * disables importing local modules, unless the global Vim variable
+" g:pythoncomplete_allow_import is set to non-zero
+"
" v 0.9
" * Fixed docstring parsing for classes and functions
" * Fixed parsing of *args and **kwargs type arguments
@@ -146,11 +150,20 @@ class Completer(object):
def evalsource(self,text,line=0):
sc = self.parser.parse(text,line)
+ try: allow_imports = int(
+ vim.eval("get(g:, 'pythoncomplete_allow_import', 0)"))
+ except Exception:
+ allow_imports = 0
src = sc.get_code()
dbg("source: %s" % src)
try: exec(src) in self.compldict
except: dbg("parser: %s, %s" % (sys.exc_info()[0],sys.exc_info()[1]))
for l in sc.locals:
+ # Executing import/from statements harvested from the buffer runs
+ # arbitrary package code; only do so when the user opted in.
+ if not allow_imports and (l.startswith('import')
+ or l.startswith('from ')):
+ continue
try: exec(l) in self.compldict
except: dbg("locals: %s, %s [%s]" % (sys.exc_info()[0],sys.exc_info()[1],l))
@@ -315,13 +328,11 @@ class Scope(object):
def get_code(self):
str = ""
if len(self.docstr) > 0: str += '"""'+self.docstr+'"""\n'
- for l in self.locals:
- if l.startswith('import'): str += l+'\n'
str += 'class _PyCmplNoType:\n def __getattr__(self,name):\n return None\n'
for sub in self.subscopes:
str += sub.get_code()
for l in self.locals:
- if not l.startswith('import'): str += l+'\n'
+ if not l.startswith('import') and not l.startswith('from '): str += l+'\n'
return str
diff --git a/runtime/doc/filetype.txt b/runtime/doc/filetype.txt
index 4876e3d75..4b57e839f 100644
--- a/runtime/doc/filetype.txt
+++ b/runtime/doc/filetype.txt
@@ -740,7 +740,20 @@ By default the following options are set, in accordance with PEP8: >
To disable this behavior, set the following variable in your vimrc: >
let g:python_recommended_style = 0
-
+<
+Python omni-completion |compl-omni| is provided by python3complete.vim (or
+pythoncomplete.vim) for Vim builds with the |+python|/|+python3| interpreter.
+By default it does not inspect the import / from statements found in the
+buffer. This means completion of names defined in the buffer itself (classes,
+functions, variables) works, but completion of members of imported modules is
+not offered.
+
+To enable completion of imported module members, set: >
+ let g:pythoncomplete_allow_import = 1
+<
+WARNING: enabling this causes omni-completion to execute the import statements
+found in the buffer through Python's import machinery, which runs the imported
+modules' top-level code. Only enable this for code you trust.
QF QUICKFIX *qf.vim* *ft-qf-plugin*
--
2.52.0

View File

@ -0,0 +1,87 @@
From a2e55906ab2f70b63f55479aaa3743f36b05566d Mon Sep 17 00:00:00 2001
From: thinca <thinca@gmail.com>
Date: Sun, 31 May 2026 12:33:07 +0000
Subject: [PATCH] patch 9.2.0568: pythoncomplete: g:pythoncomplete_allow_import
had no effect
Problem: The security patch 9.2.0561 added a vim.eval() call inside
Completer.evalsource() to honor g:pythoncomplete_allow_import.
But the 'vim' module is only imported inside the outer
vimcomplete() / vimpy3complete() function, not at the script's
top level, so referring to it from a Completer method raises
NameError. The surrounding bare 'except' silently swallows
the error and leaves allow_imports at 0, meaning the opt-in
never takes effect -- 'import os' (and any other
buffer-level import) is always skipped, no candidates are
produced for 'os.<...>' and
Test_popup_and_preview_autocommand() fails on the Windows
CI matrix (Linux skips the test because Python 2 is absent).
Solution: Re-import 'vim' at the top of evalsource() in both
pythoncomplete.vim and python3complete.vim so the eval reads
the global, and set g:pythoncomplete_allow_import = 1 in the
test (it is the opt-in intended for callers that trust the
buffer contents) (thinca).
closes: #20386
Signed-off-by: thinca <thinca@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
---
runtime/autoload/python3complete.vim | 3 +++
runtime/autoload/pythoncomplete.vim | 3 +++
src/testdir/test_popup.vim | 4 ++++
3 files changed, 10 insertions(+)
diff --git a/runtime/autoload/python3complete.vim b/runtime/autoload/python3complete.vim
index aba341229..1c432f3c8 100644
--- a/runtime/autoload/python3complete.vim
+++ b/runtime/autoload/python3complete.vim
@@ -135,6 +135,9 @@ class Completer(object):
self.parser = PyParser()
def evalsource(self,text,line=0):
+ # vim is imported locally in vimpy3complete(); re-import here so the
+ # vim.eval() below works (otherwise NameError, silently caught).
+ import vim
sc = self.parser.parse(text,line)
try: allow_imports = int(
vim.eval("get(g:, 'pythoncomplete_allow_import', 0)"))
diff --git a/runtime/autoload/pythoncomplete.vim b/runtime/autoload/pythoncomplete.vim
index 10147767e..b4340f7ae 100644
--- a/runtime/autoload/pythoncomplete.vim
+++ b/runtime/autoload/pythoncomplete.vim
@@ -149,6 +149,9 @@ class Completer(object):
self.parser = PyParser()
def evalsource(self,text,line=0):
+ # vim is imported locally in vimcomplete(); re-import here so the
+ # vim.eval() below works (otherwise NameError, silently caught).
+ import vim
sc = self.parser.parse(text,line)
try: allow_imports = int(
vim.eval("get(g:, 'pythoncomplete_allow_import', 0)"))
diff --git a/src/testdir/test_popup.vim b/src/testdir/test_popup.vim
index 879d1fa3e..be27097a1 100644
--- a/src/testdir/test_popup.vim
+++ b/src/testdir/test_popup.vim
@@ -724,6 +724,9 @@ func Test_popup_and_preview_autocommand()
au!
au BufAdd * nested tab sball
augroup END
+ " Let pythoncomplete follow the buffer's 'import os' (off by default
+ " since v9.2.0561) so 'os.' can be completed.
+ let g:pythoncomplete_allow_import = 1
set omnifunc=pythoncomplete#Complete
call setline(1, 'import os')
" make the line long
@@ -746,6 +749,7 @@ func Test_popup_and_preview_autocommand()
augroup END
augroup! MyBufAdd
bw!
+ unlet g:pythoncomplete_allow_import
endfunc
func Test_popup_and_previewwindow_dump()
--
2.52.0

View File

@ -51,7 +51,7 @@ Summary: The VIM editor
URL: http://www.vim.org/
Name: vim
Version: %{baseversion}.%{patchlevel}
Release: 9%{?dist}.4
Release: 9%{?dist}.7
Epoch: 2
# swift.vim contains Apache 2.0 with runtime library exception:
# which is taken as Apache-2.0 WITH Swift-exception - reported to legal as https://gitlab.com/fedora/legal/fedora-license-data/-/issues/188
@ -149,6 +149,33 @@ Patch3021: 0001-patch-9.2.0304-zip-block-absolute-paths-in-Extract.patch
# https://redhat.atlassian.net/browse/RHEL-171481
# https://github.com/vim/vim/commit/c78194e41d5a0b05b0ddf383b6679b1503f977fb
Patch3022: 0001-patch-9.2.0357-security-command-injection-via-backti.patch
# RHEL-178233 CVE-2026-46483 runtime(tar): command injection in tar plugin
# https://redhat.atlassian.net/browse/RHEL-178233
# https://github.com/vim/vim/commit/3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1
# Omitted src/version.c changes per downstream policy
# Omitted 'Last Change' comments in tar.vim per downstream policy
# Reduced test file to only Test_extract_command_injection
# Added Make_all.mak changes from upstream commit 87757c6b0a4
Patch3023: 0001-patch-9.2.0479-security-runtime-tar-command-injectio.patch
# RHEL-185867 CVE-2026-47167 vim: Code Injection in cucumber filetype plugin
# https://redhat.atlassian.net/browse/RHEL-185867
# https://github.com/vim/vim/commit/a65a52d684bc58535ad28a4ae824d22e76399934
# stripped src/version.c hunk and omitted 'Last Change' comment per maintainer rules
Patch3024: 0001-patch-9.2.0496-security-Code-Injection-in-cucumber-f.patch
# RHEL-186660 CVE-2026-47162 vim: netrw code injection via NetrwBookHistSave()
# https://redhat.atlassian.net/browse/RHEL-186660
# https://github.com/vim/vim/commit/f08ab2f4d7d2947c8dd6c179ae08ee6146a2694b
# Adapted: omitted src/version.c hunk and 'Last Change' date; test file created
# minimal (only injection test) since test_plugin_netrw.vim is new downstream,
# Function SetUp() is required because the part we want to test is plugin;
# netrw.vim fix applied to runtime/autoload/ path (downstream location)
Patch3025: 0001-patch-9.2.0495-security-runtime-netrw-code-injectio.patch
# RHEL-186671 CVE-2026-52858 vim: possible code execution with python3complete
# https://redhat.atlassian.net/browse/RHEL-186671
# https://github.com/vim/vim/commit/4b850457e12e1a678dd209f2868154f7553cbf8d
Patch3026: 0001-patch-9.2.0561-security-possible-code-execution-with.patch
# https://github.com/vim/vim/commit/868ad62cb8bf8038322eab2badd31bd98b02b9df
Patch3027: 0001-patch-9.2.0568-pythoncomplete-g-pythoncomplete_allow.patch
# uses autoconf in spec file
@ -489,6 +516,11 @@ perl -pi -e "s,bin/nawk,bin/awk,g" runtime/tools/mve.awk
%patch -P 3020 -p1 -b .zip-abs-write
%patch -P 3021 -p1 -b .zip-abs-extract
%patch -P 3022 -p1 -b .tag-backtick-inject
%patch -P 3023 -p1 -b .tar-cmd-inject
%patch -P 3024 -p1 -b .cucumber-code-inject
%patch -P 3025 -p1 -b .netrw-hist-inject
%patch -P 3026 -p1 -b .python3complete-cve
%patch -P 3027 -p1 -b .pythoncomplete-import-fix
%build
cd src
@ -1119,6 +1151,16 @@ touch %{buildroot}/%{_datadir}/%{name}/vimfiles/doc/tags
%changelog
* Wed Jul 01 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 2:9.1.083-9.7
- RHEL-186660 CVE-2026-47162 vim: netrw code injection via NetrwBookHistSave()
- RHEL-186671 CVE-2026-52858 vim: possible code execution with python3complete
* Tue Jun 30 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 2:9.1.083-9.6
- RHEL-185867 CVE-2026-47167 vim: Code Injection in cucumber filetype plugin
* Thu Jun 25 2026 Zdenek Dohnal <zdohnal@redhat.com> - 2:9.1.083-9.5
- RHEL-178233 CVE-2026-46483 vim: command injection in tar plugin
* Thu May 21 2026 Zdenek Dohnal <zdohnal@redhat.com> - 2:9.1.083-9.4
- RHEL-171481 CVE-2026-41411 vim: Command injection via backticks in tag files