Re: [LFS Trac] #4500: vim-9.1.???? (Update before release)

"LFS Trac" ([email protected] via lfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.book
Message-ID <[email protected]>
#4500: vim-9.1.???? (Update before release)
-------------------------+-----------------------
 Reporter:  Bruce Dubbs  |       Owner:  lfs-book
     Type:  task         |      Status:  new
 Priority:  normal       |   Milestone:  Hold
Component:  Book         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-----------------------
Comment (by Joe Locash):

 {{{
 A heap use-after-free was found in str_to_reg() in Vim < 9.1.1115
 ==================================================================
 Date: 16.02.2025
 Severity: Medium
 CVE: *not yet assigned
 CWE: Use-after-free (CWE-416)

 Vim allows to redirect screen messages using the `:redir` ex command to
 register, variables and files. It also allows to show the contents of
 registers using the `:registers` or `:display` ex command.

 When redirecting the output of `:display` to a register, Vim will free
 the register content before storing the new content in the
 register. Now when redirecting the `:display` command to a register that
 is being displayed, Vim will free the content while shortly afterwards
 trying to access it, which leads to a use-after-free.

 Vim pre 9.1.1115 checks in the ex_display() function, that it does not
 try to redirect to a register while displaying this register at the same
 time. However this check is not complete, and so Vim does not check the
 `+` and `*` registers (which typically donate the X11/clipboard
 registers, and when a clipboard connection is not possible will fall
 back to use register 0 instead.

 In Patch 9.1.1115 Vim will therefore skip outputting to register zero
 when trying to redirect to the clipboard registers `*` or `+`.

 Impact is medium since this is a rather unusual situation and a user
 must explicitly run this command.

 The Vim project would like to thank github user @fizz-is-on-the-way
 for reporting this issue.

 The issue has been fixed as of Vim patch v9.1.1115

 References:
 https://github.com/vim/vim/commit/c0f0e2380e5954f4a52a131bf6b8
 https://github.com/vim/vim/security/advisories/GHSA-63p5-mwg2-787v

 }}}
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/4500#comment:37>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.

-- 
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.