Opened 7 months ago

Closed 7 months ago

#22874 closed enhancement (fixed)

vim-9.2.0078 (Security update)

Reported by: Bruce Dubbs Owned by: zeckma
Priority: elevated Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

An OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using thescp:// protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process.

Change History (6)

comment:1 by Bruce Dubbs, 7 months ago

Milestone: 13.1 → 13.0

Fixed at commit 11c38e4de2b.

Leaving open for SA.

comment:2 by zeckma, 7 months ago

Owner: changed from blfs-book to zeckma
Status: new → assigned

comment:3 by zeckma, 7 months ago

I'll handle the SA. Thanks for doing the update, Bruce!

comment:4 by zeckma, 7 months ago

Priority: normal → elevated

comment:5 by zeckma, 7 months ago

Security fixes

Rating: Medium

  • CVE-2026-28417 (Medium): OS Command Injection in netrw
  • CVE-2026-28418 (Medium): Heap-based Buffer Overflow in Emacs tags parsing
  • CVE-2026-28419 (Medium): Heap-based Buffer Underflow in Emacs tags parsing
  • CVE-2026-28420 (Medium): Heap-based Buffer Overflow and OOB Read in :terminal
  • CVE-2026-28421 (Medium): Heap-based Buffer Overflow / Improper Input Validation
  • CVE-2026-28422 (Low): Stack-buffer-overflow in build_stl_str_hl()

comment:6 by zeckma, 7 months ago

Resolution: → fixed
Status: assigned → closed

SA-12.4-108 issued.

Note: See TracTickets for help on using tickets.