CVE-2026-46483 vim: command injection in tar plugin
Resolves: RHEL-178241
This commit is contained in:
parent
8fcaff82ca
commit
82edcac8aa
@ -0,0 +1,67 @@
|
||||
diff --git a/runtime/autoload/tar.vim b/runtime/autoload/tar.vim
|
||||
index a3abbc7..c8d5d03 100644
|
||||
--- a/runtime/autoload/tar.vim
|
||||
+++ b/runtime/autoload/tar.vim
|
||||
@@ -780,9 +780,9 @@ fun! tar#Vimuntar(...)
|
||||
" if necessary, decompress the tarball; then, extract it
|
||||
if tartail =~ '\.tgz'
|
||||
if executable("gunzip")
|
||||
- silent exe "!gunzip ".shellescape(tartail)
|
||||
+ silent exe "!gunzip ".shellescape(tartail, 1)
|
||||
elseif executable("gzip")
|
||||
- silent exe "!gzip -d ".shellescape(tartail)
|
||||
+ silent exe "!gzip -d ".shellescape(tartail, 1)
|
||||
else
|
||||
echoerr "unable to decompress<".tartail."> on this system"
|
||||
if simplify(curdir) != simplify(tarhome)
|
||||
diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak
|
||||
index 8dd04e7..2b3d16d 100644
|
||||
--- a/src/testdir/Make_all.mak
|
||||
+++ b/src/testdir/Make_all.mak
|
||||
@@ -227,6 +227,7 @@ NEW_TESTS = \
|
||||
test_partial \
|
||||
test_paste \
|
||||
test_perl \
|
||||
+ test_plugin_tar \
|
||||
test_plus_arg_edit \
|
||||
test_popup \
|
||||
test_popupwin \
|
||||
@@ -476,6 +477,7 @@ NEW_TESTS_RES = \
|
||||
test_partial.res \
|
||||
test_paste.res \
|
||||
test_perl.res \
|
||||
+ test_plugin_tar.res \
|
||||
test_plus_arg_edit.res \
|
||||
test_popup.res \
|
||||
test_popupwin.res \
|
||||
diff --git a/src/testdir/test_plugin_tar.vim b/src/testdir/test_plugin_tar.vim
|
||||
new file mode 100644
|
||||
index 0000000..5e712df
|
||||
--- /dev/null
|
||||
+++ b/src/testdir/test_plugin_tar.vim
|
||||
@@ -0,0 +1,25 @@
|
||||
+vim9script
|
||||
+
|
||||
+source check.vim
|
||||
+CheckNotMSWindows
|
||||
+
|
||||
+runtime plugin/tarPlugin.vim
|
||||
+
|
||||
+def g:Test_extract_command_injection()
|
||||
+ CheckExecutable gunzip
|
||||
+ CheckExecutable touch
|
||||
+ var tgz = eval('0z1F8B08087795056A000364756D6D792E74617200EDCE2B12C2300004D01C254' ..
|
||||
+ '7480269CE534080A8495BD1DBF3996106C3A08A7ACFACD8157B59A7690BFB4A0FC3707C666E357D' ..
|
||||
+ 'E65BC8B5A47CC8A5D61A522EA5B510D3CEBF5ED679197B8CE17CEDB7F9D4C76FBB5F3D000000000' ..
|
||||
+ '000000000FCD11D32415E2C00280000')
|
||||
+ var dirname = tempname()
|
||||
+
|
||||
+ mkdir(dirname, 'R')
|
||||
+ var tar = dirname .. "/';%$(touch pwned)'.tgz"
|
||||
+ writefile(tgz, tar)
|
||||
+ new
|
||||
+ exe "e " .. fnameescape(tar)
|
||||
+ exe ":Vimuntar " .. dirname
|
||||
+ assert_false(filereadable(dirname .. "/pwned"))
|
||||
+ bw!
|
||||
+enddef
|
||||
10
vim.spec
10
vim.spec
@ -51,7 +51,7 @@ Summary: The VIM editor
|
||||
URL: http://www.vim.org/
|
||||
Name: vim
|
||||
Version: %{baseversion}.%{patchlevel}
|
||||
Release: 13%{?dist}
|
||||
Release: 14%{?dist}
|
||||
Epoch: 2
|
||||
# swift.vim contains Apache 2.0 with runtime library exception:
|
||||
# which is taken as Apache-2.0 WITH Swift-exception - reported to legal as https://gitlab.com/fedora/legal/fedora-license-data/-/issues/188
|
||||
@ -151,6 +151,10 @@ Patch3020: 0001-patch-9.2.0357-security-command-injection-via-backti.patch
|
||||
# https://github.com/vim/vim/commit/8c8772c6b321d4955c8f09926e3eda2b4cd83680
|
||||
Patch3021: 0001-patch-9.2.0276-security-modeline-security-bypass.patch
|
||||
Patch3022: 0001-patch-9.2.0277-tests-test_modeline.vim-fails.patch
|
||||
# RHEL-178241 CVE-2026-46483 runtime(tar): command injection in tar plugin
|
||||
# https://redhat.atlassian.net/browse/RHEL-178241
|
||||
# https://github.com/vim/vim/commit/3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1
|
||||
Patch3023: 0001-patch-9.2.0479-security-runtime-tar-command-injectio.patch
|
||||
|
||||
|
||||
# uses autoconf in spec file
|
||||
@ -491,6 +495,7 @@ perl -pi -e "s,bin/nawk,bin/awk,g" runtime/tools/mve.awk
|
||||
%patch -P 3020 -p1 -b .tag-backtick-inject
|
||||
%patch -P 3021 -p1 -b .modeline-bypass
|
||||
%patch -P 3022 -p1 -b .modeline-tests
|
||||
%patch -P 3023 -p1 -b .tar-cmd-inject
|
||||
|
||||
%build
|
||||
cd src
|
||||
@ -1121,6 +1126,9 @@ touch %{buildroot}/%{_datadir}/%{name}/vimfiles/doc/tags
|
||||
|
||||
|
||||
%changelog
|
||||
* Thu Jul 16 2026 Zdenek Dohnal <zdohnal@redhat.com> - 2:9.1.083-14
|
||||
- RHEL-178241 CVE-2026-46483 vim: command injection in tar plugin
|
||||
|
||||
* Wed May 27 2026 Zdenek Dohnal <zdohnal@redhat.com> - 2:9.1.083-13
|
||||
- CVE-2026-34982 vim: arbitrary command execution via modeline sandbox bypass
|
||||
|
||||
|
||||
Loading…
Reference in New Issue
Block a user