From 82edcac8aa1aa505e97d1c9b35a45a1786fe0f18 Mon Sep 17 00:00:00 2001 From: Zdenek Dohnal Date: Thu, 16 Jul 2026 14:44:03 +0200 Subject: [PATCH] CVE-2026-46483 vim: command injection in tar plugin Resolves: RHEL-178241 --- ...ecurity-runtime-tar-command-injectio.patch | 67 +++++++++++++++++++ vim.spec | 10 ++- 2 files changed, 76 insertions(+), 1 deletion(-) create mode 100644 0001-patch-9.2.0479-security-runtime-tar-command-injectio.patch diff --git a/0001-patch-9.2.0479-security-runtime-tar-command-injectio.patch b/0001-patch-9.2.0479-security-runtime-tar-command-injectio.patch new file mode 100644 index 00000000..3c51ddfa --- /dev/null +++ b/0001-patch-9.2.0479-security-runtime-tar-command-injectio.patch @@ -0,0 +1,67 @@ +diff --git a/runtime/autoload/tar.vim b/runtime/autoload/tar.vim +index a3abbc7..c8d5d03 100644 +--- a/runtime/autoload/tar.vim ++++ b/runtime/autoload/tar.vim +@@ -780,9 +780,9 @@ fun! tar#Vimuntar(...) + " if necessary, decompress the tarball; then, extract it + if tartail =~ '\.tgz' + if executable("gunzip") +- silent exe "!gunzip ".shellescape(tartail) ++ silent exe "!gunzip ".shellescape(tartail, 1) + elseif executable("gzip") +- silent exe "!gzip -d ".shellescape(tartail) ++ silent exe "!gzip -d ".shellescape(tartail, 1) + else + echoerr "unable to decompress<".tartail."> on this system" + if simplify(curdir) != simplify(tarhome) +diff --git a/src/testdir/Make_all.mak b/src/testdir/Make_all.mak +index 8dd04e7..2b3d16d 100644 +--- a/src/testdir/Make_all.mak ++++ b/src/testdir/Make_all.mak +@@ -227,6 +227,7 @@ NEW_TESTS = \ + test_partial \ + test_paste \ + test_perl \ ++ test_plugin_tar \ + test_plus_arg_edit \ + test_popup \ + test_popupwin \ +@@ -476,6 +477,7 @@ NEW_TESTS_RES = \ + test_partial.res \ + test_paste.res \ + test_perl.res \ ++ test_plugin_tar.res \ + test_plus_arg_edit.res \ + test_popup.res \ + test_popupwin.res \ +diff --git a/src/testdir/test_plugin_tar.vim b/src/testdir/test_plugin_tar.vim +new file mode 100644 +index 0000000..5e712df +--- /dev/null ++++ b/src/testdir/test_plugin_tar.vim +@@ -0,0 +1,25 @@ ++vim9script ++ ++source check.vim ++CheckNotMSWindows ++ ++runtime plugin/tarPlugin.vim ++ ++def g:Test_extract_command_injection() ++ CheckExecutable gunzip ++ CheckExecutable touch ++ var tgz = eval('0z1F8B08087795056A000364756D6D792E74617200EDCE2B12C2300004D01C254' .. ++ '7480269CE534080A8495BD1DBF3996106C3A08A7ACFACD8157B59A7690BFB4A0FC3707C666E357D' .. ++ 'E65BC8B5A47CC8A5D61A522EA5B510D3CEBF5ED679197B8CE17CEDB7F9D4C76FBB5F3D000000000' .. ++ '000000000FCD11D32415E2C00280000') ++ var dirname = tempname() ++ ++ mkdir(dirname, 'R') ++ var tar = dirname .. "/';%$(touch pwned)'.tgz" ++ writefile(tgz, tar) ++ new ++ exe "e " .. fnameescape(tar) ++ exe ":Vimuntar " .. dirname ++ assert_false(filereadable(dirname .. "/pwned")) ++ bw! ++enddef diff --git a/vim.spec b/vim.spec index 536c8038..f739f0fe 100644 --- a/vim.spec +++ b/vim.spec @@ -51,7 +51,7 @@ Summary: The VIM editor URL: http://www.vim.org/ Name: vim Version: %{baseversion}.%{patchlevel} -Release: 13%{?dist} +Release: 14%{?dist} Epoch: 2 # swift.vim contains Apache 2.0 with runtime library exception: # which is taken as Apache-2.0 WITH Swift-exception - reported to legal as https://gitlab.com/fedora/legal/fedora-license-data/-/issues/188 @@ -151,6 +151,10 @@ Patch3020: 0001-patch-9.2.0357-security-command-injection-via-backti.patch # https://github.com/vim/vim/commit/8c8772c6b321d4955c8f09926e3eda2b4cd83680 Patch3021: 0001-patch-9.2.0276-security-modeline-security-bypass.patch Patch3022: 0001-patch-9.2.0277-tests-test_modeline.vim-fails.patch +# RHEL-178241 CVE-2026-46483 runtime(tar): command injection in tar plugin +# https://redhat.atlassian.net/browse/RHEL-178241 +# https://github.com/vim/vim/commit/3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1 +Patch3023: 0001-patch-9.2.0479-security-runtime-tar-command-injectio.patch # uses autoconf in spec file @@ -491,6 +495,7 @@ perl -pi -e "s,bin/nawk,bin/awk,g" runtime/tools/mve.awk %patch -P 3020 -p1 -b .tag-backtick-inject %patch -P 3021 -p1 -b .modeline-bypass %patch -P 3022 -p1 -b .modeline-tests +%patch -P 3023 -p1 -b .tar-cmd-inject %build cd src @@ -1121,6 +1126,9 @@ touch %{buildroot}/%{_datadir}/%{name}/vimfiles/doc/tags %changelog +* Thu Jul 16 2026 Zdenek Dohnal - 2:9.1.083-14 +- RHEL-178241 CVE-2026-46483 vim: command injection in tar plugin + * Wed May 27 2026 Zdenek Dohnal - 2:9.1.083-13 - CVE-2026-34982 vim: arbitrary command execution via modeline sandbox bypass