58 lines
2.3 KiB
Diff
58 lines
2.3 KiB
Diff
From 6202f4f217c55590990e9562bf225be75e2367ce Mon Sep 17 00:00:00 2001
|
|
From: Yasuhiro Matsumoto <mattn.jp@gmail.com>
|
|
Date: Fri, 24 Jul 2026 00:58:37 +0900
|
|
Subject: [PATCH] patch 9.2.0846: [security]: heap buffer overflow in
|
|
set_sofo()
|
|
|
|
Problem: [security]: heap buffer overflow in set_sofo()
|
|
(Yazan Balawneh)
|
|
Solution: Reset sl_sal_first (Yasuhiro Matsumoto).
|
|
|
|
A crafted spell file with an empty SN_SAL section before an SN_SOFO
|
|
section reaches set_sofo() with sl_sal_first[] already set to -1 by
|
|
set_sal_first(). The counting loop then under-counts colliding
|
|
multi-byte "from" characters, allocates an undersized list and writes
|
|
past its end.
|
|
|
|
Github Security Advisory:
|
|
https://github.com/vim/vim/security/advisories/GHSA-9jqx-hgpr-6v64
|
|
|
|
Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
|
|
Signed-off-by: Christian Brabandt <cb@256bit.org>
|
|
---
|
|
src/spellfile.c | 4 +++-
|
|
src/testdir/test_spellfile.vim | 5 +++++
|
|
2 files changed, 8 insertions(+), 1 deletion(-)
|
|
|
|
diff --git a/src/spellfile.c b/src/spellfile.c
|
|
index 988bb56c0..5e263d3e2 100644
|
|
--- a/src/spellfile.c
|
|
+++ b/src/spellfile.c
|
|
@@ -1431,7 +1431,9 @@ set_sofo(slang_T *lp, char_u *from, char_u *to)
|
|
gap->ga_len = 256;
|
|
|
|
// First count the number of items for each list. Temporarily use
|
|
- // sl_sal_first[] for this.
|
|
+ // sl_sal_first[] for this. Reset it first: a preceding SN_SAL section
|
|
+ // may have set the entries to -1 via set_sal_first().
|
|
+ vim_memset(lp->sl_sal_first, 0, sizeof(salfirst_T) * 256);
|
|
for (p = from, s = to; *p != NUL && *s != NUL; )
|
|
{
|
|
c = mb_cptr2char_adv(&p);
|
|
diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim
|
|
index a5dde6d21..82f6ae465 100644
|
|
--- a/src/testdir/test_spellfile.vim
|
|
+++ b/src/testdir/test_spellfile.vim
|
|
@@ -322,6 +322,11 @@ func Test_spellfile_format_error()
|
|
" SN_SOFO: multi-byte characters in sofofrom and sofoto
|
|
call Spellfile_Test(0z0600000000080002CF810002CF82FF000000000000000000000000, '')
|
|
|
|
+ " SN_SAL (empty) followed by SN_SOFO with two multi-byte 'from' characters
|
|
+ " sharing the same low byte. A preceding SN_SAL poisons sl_sal_first[], so
|
|
+ " without a reset set_sofo() under-counts and writes out of bounds.
|
|
+ call Spellfile_Test(0z05000000000300000006000000000A0004CAABCEAB00024142FF000000000000000000000000, '')
|
|
+
|
|
" SN_COMPOUND: compmax is less than 2
|
|
call Spellfile_Test(0z08000000000101, 'E759:')
|
|
|