Re: [LFS Trac] #4500: vim-9.1.???? (Update before release)

"LFS Trac" ([email protected] via lfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.book
Message-ID <[email protected]>
#4500: vim-9.1.???? (Update before release)
-------------------------+-----------------------
 Reporter:  Bruce Dubbs  |       Owner:  lfs-book
     Type:  task         |      Status:  new
 Priority:  normal       |   Milestone:  Hold
Component:  Book         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-----------------------
Comment (by Douglas R. Reno):

 Replying to [comment:55 Douglas R. Reno]:
 > Replying to [comment:53 Joe Locash]:
 > >
 > > {{{
 > > Vim tabpanel modeline escape affects Vim < 9.2.0272
 > > ===================================================
 > > Date: 30.03.2026
 > > Severity: High
 > > CVE: *not yet assigned*
 > > CWE: Improper Neutralization of Special Elements used in an OS Command
 (CWE-78)
 > >
 > > ## Summary
 > > A bug chain in Vim allows arbitrary OS command execution when a user
 > > opens a crafted file. The `tabpanel` option is missing the `P_MLE`
 flag,
 > > allowing a modeline to inject a `%{expr}` expression string without
 > > requiring `modelineexpr` to be enabled. Although Vim correctly
 evaluates
 > > the expression inside the sandbox, `autocmd_add()` lacks a
 > > `check_secure()` call, allowing sandboxed code to register an
 > > autocommand that fires after the sandbox exits.
 > >
 > > ## Description
 > > The `tabpanel` option (`src/optiondefs.h:2581`) accepts `%{expr}`
 format
 > > strings identically to `statusline` and `tabline`, both of which carry
 > > the `P_MLE` flag to require `modelineexpr` for modeline use.
 `tabpanel`
 > > is missing this flag, so the modeline security check at
 > > `src/option.c:1572-1576` is never reached and arbitrary expression
 > > strings are accepted from modelines.
 > >
 > > Vim correctly detects that the option was set insecurely and evaluates
 > > the expression inside the sandbox (`src/eval.c:747-758`). However,
 > > `autocmd_add()` (`src/autocmd.c:3316`) contains no `check_secure()`
 > > call. While the `:autocmd` ex command is properly blocked in the
 sandbox
 > > (no `EX_SBOXOK`), but the function interface bypasses this
 restriction.
 > >
 > > ## Impact
 > > An attacker who can deliver a crafted file to a victim achieves
 > > arbitrary command execution with the privileges of the user running
 Vim.
 > > The attack requires only that the victim opens the file; no further
 > > interaction is needed. `modeline` is enabled by default and
 > > `modelineexpr` does not need to be enabled. Vim builds with
 `+tabpanel`
 > > (FEAT_HUGE, the default) are affected.
 > >
 > > ## Acknowledgements
 > > The Vim project would like to thank Koda Reef for identifying the
 > > vulnerability chain, providing a detailed root cause analysis,
 reproduction steps, and
 > > suggested fixes.
 > >
 > > ## References
 > > The issue has been fixed as of Vim patch
 > > [v9.2.0272](https://github.com/vim/vim/releases/tag/v9.2.0272)
 > >
 > > -
 [Commit](https://github.com/vim/vim/commit/664701eb7576edb7c7c7d9f2d600815ec1f43459)
 > > - [GitHub Advisory](https://github.com/vim/vim/security/advisories
 /GHSA-2gmj-rpqf-pxvh)
 > > }}}
 >
 > CVE-2026-34714  has been assigned for this issue. Working up a security
 advisory for this now.


 SA-13.0-025 issued.

 I highly recommend ALL EDITORS especially to upgrade to this version of
 vim. We especially are at risk because we regularly open source code from
 other packages, and the vulnerability requires no action on our part other
 than just opening an affected file. For us this is extremely dangerous.
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/4500#comment:56>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.

-- 
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.