From: Yasuhiro Matsumoto Date: Thu, 23 Jul 2026 15:58:37 +0000 (+0900) Subject: patch 9.2.0846: [security]: heap buffer overflow in set_sofo() X-Git-Tag: v9.2.0846^0 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;ds=inline;p=thirdparty%2Fvim.git patch 9.2.0846: [security]: heap buffer overflow in set_sofo() Problem: [security]: heap buffer overflow in set_sofo() (Yazan Balawneh) Solution: Reset sl_sal_first (Yasuhiro Matsumoto). A crafted spell file with an empty SN_SAL section before an SN_SOFO section reaches set_sofo() with sl_sal_first[] already set to -1 by set_sal_first(). The counting loop then under-counts colliding multi-byte "from" characters, allocates an undersized list and writes past its end. Github Security Advisory: https://github.com/vim/vim/security/advisories/GHSA-9jqx-hgpr-6v64 Signed-off-by: Yasuhiro Matsumoto Signed-off-by: Christian Brabandt --- diff --git a/src/spellfile.c b/src/spellfile.c index 8000cdb550..e90c89b73d 100644 --- a/src/spellfile.c +++ b/src/spellfile.c @@ -1434,7 +1434,9 @@ set_sofo(slang_T *lp, char_u *from, char_u *to) lp->sl_sofo = TRUE; // First count the number of items for each list. Temporarily use - // sl_sal_first[] for this. + // sl_sal_first[] for this. Reset it first: a preceding SN_SAL section + // may have set the entries to -1 via set_sal_first(). + vim_memset(lp->sl_sal_first, 0, sizeof(salfirst_T) * 256); for (p = from, s = to; *p != NUL && *s != NUL; ) { c = mb_cptr2char_adv(&p); diff --git a/src/testdir/test_spellfile.vim b/src/testdir/test_spellfile.vim index fa3fb14fd8..b8e710eb64 100644 --- a/src/testdir/test_spellfile.vim +++ b/src/testdir/test_spellfile.vim @@ -319,6 +319,11 @@ func Test_spellfile_format_error() " SN_SOFO: multi-byte characters in sofofrom and sofoto call Spellfile_Test(0z0600000000080002CF810002CF82FF000000000000000000000000, '') + " SN_SAL (empty) followed by SN_SOFO with two multi-byte 'from' characters + " sharing the same low byte. A preceding SN_SAL poisons sl_sal_first[], so + " without a reset set_sofo() under-counts and writes out of bounds. + call Spellfile_Test(0z05000000000300000006000000000A0004CAABCEAB00024142FF000000000000000000000000, '') + " SN_COMPOUND: compmax is less than 2 call Spellfile_Test(0z08000000000101, 'E759:') diff --git a/src/version.c b/src/version.c index a93ef03842..5547cf4d52 100644 --- a/src/version.c +++ b/src/version.c @@ -758,6 +758,8 @@ static char *(features[]) = static int included_patches[] = { /* Add new patch number below this line */ +/**/ + 846, /**/ 845, /**/