From f938f4060de4b79a7bf22381bb89994b74a03dc1 Mon Sep 17 00:00:00 2001 From: Zdenek Dohnal Date: Thu, 16 Jul 2026 15:24:07 +0200 Subject: [PATCH] CVE-2026-47167 vim: Code Injection in cucumber filetype plugin Resolves: RHEL-185864 --- ...ecurity-Code-Injection-in-cucumber-f.patch | 52 +++++++++++++++++++ vim.spec | 10 +++- 2 files changed, 61 insertions(+), 1 deletion(-) create mode 100644 0001-patch-9.2.0496-security-Code-Injection-in-cucumber-f.patch diff --git a/0001-patch-9.2.0496-security-Code-Injection-in-cucumber-f.patch b/0001-patch-9.2.0496-security-Code-Injection-in-cucumber-f.patch new file mode 100644 index 00000000..beefd4ae --- /dev/null +++ b/0001-patch-9.2.0496-security-Code-Injection-in-cucumber-f.patch @@ -0,0 +1,52 @@ +diff -up vim91/runtime/ftplugin/cucumber.vim.cucumber-code-inject vim91/runtime/ftplugin/cucumber.vim +--- vim91/runtime/ftplugin/cucumber.vim.cucumber-code-inject 2024-02-09 06:33:54.000000000 +0100 ++++ vim91/runtime/ftplugin/cucumber.vim 2026-06-30 15:39:27.581293444 +0200 +@@ -96,7 +96,8 @@ function! s:stepmatch(receiver,target) + catch + endtry + if has("ruby") && pattern !~ '\\\@ s:steps -> s:stepmatch on every discovered step, ++ " including the malicious one. Suppress preview and error messages. ++ silent! normal [d ++ call assert_false(filereadable(marker), 'Ruby injection executed') ++ bwipe! ++ filetype plugin off ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab diff --git a/vim.spec b/vim.spec index f739f0fe..433ed893 100644 --- a/vim.spec +++ b/vim.spec @@ -51,7 +51,7 @@ Summary: The VIM editor URL: http://www.vim.org/ Name: vim Version: %{baseversion}.%{patchlevel} -Release: 14%{?dist} +Release: 15%{?dist} Epoch: 2 # swift.vim contains Apache 2.0 with runtime library exception: # which is taken as Apache-2.0 WITH Swift-exception - reported to legal as https://gitlab.com/fedora/legal/fedora-license-data/-/issues/188 @@ -155,6 +155,10 @@ Patch3022: 0001-patch-9.2.0277-tests-test_modeline.vim-fails.patch # https://redhat.atlassian.net/browse/RHEL-178241 # https://github.com/vim/vim/commit/3fb5e58fbc63d86a3e65f1a141b0d67af2aa38a1 Patch3023: 0001-patch-9.2.0479-security-runtime-tar-command-injectio.patch +# RHEL-185864 CVE-2026-47167 vim: Code Injection in cucumber filetype plugin +# https://redhat.atlassian.net/browse/RHEL-185864 +# https://github.com/vim/vim/commit/a65a52d684bc58535ad28a4ae824d22e76399934 +Patch3024: 0001-patch-9.2.0496-security-Code-Injection-in-cucumber-f.patch # uses autoconf in spec file @@ -496,6 +500,7 @@ perl -pi -e "s,bin/nawk,bin/awk,g" runtime/tools/mve.awk %patch -P 3021 -p1 -b .modeline-bypass %patch -P 3022 -p1 -b .modeline-tests %patch -P 3023 -p1 -b .tar-cmd-inject +%patch -P 3024 -p1 -b .cucumber-code-inject %build cd src @@ -1126,6 +1131,9 @@ touch %{buildroot}/%{_datadir}/%{name}/vimfiles/doc/tags %changelog +* Thu Jul 16 2026 Zdenek Dohnal - 2:9.1.083-15 +- RHEL-185864 CVE-2026-47167 vim: Code Injection in cucumber filetype plugin + * Thu Jul 16 2026 Zdenek Dohnal - 2:9.1.083-14 - RHEL-178241 CVE-2026-46483 vim: command injection in tar plugin