]> git.ipfire.org Git - thirdparty/vim.git/commitdiff
patch 9.2.0846: [security]: heap buffer overflow in set_sofo() master v9.2.0846
authorYasuhiro Matsumoto <mattn.jp@gmail.com>
Thu, 23 Jul 2026 15:58:37 +0000 (00:58 +0900)
committerChristian Brabandt <cb@256bit.org>
Fri, 24 Jul 2026 18:50:25 +0000 (18:50 +0000)
Problem:  [security]: heap buffer overflow in set_sofo()
          (Yazan Balawneh)
Solution: Reset sl_sal_first (Yasuhiro Matsumoto).

A crafted spell file with an empty SN_SAL section before an SN_SOFO
section reaches set_sofo() with sl_sal_first[] already set to -1 by
set_sal_first(). The counting loop then under-counts colliding
multi-byte "from" characters, allocates an undersized list and writes
past its end.

Github Security Advisory:
https://github.com/vim/vim/security/advisories/GHSA-9jqx-hgpr-6v64

Signed-off-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
Signed-off-by: Christian Brabandt <cb@256bit.org>
src/spellfile.c
src/testdir/test_spellfile.vim
src/version.c

index 8000cdb550efcde0a1515844a3bb6523978de1db..e90c89b73d2b541d07d7dd1b61d857f9ef23e93f 100644 (file)
@@ -1434,7 +1434,9 @@ set_sofo(slang_T *lp, char_u *from, char_u *to)
        lp->sl_sofo = TRUE;
 
        // First count the number of items for each list.  Temporarily use
-       // sl_sal_first[] for this.
+       // sl_sal_first[] for this.  Reset it first: a preceding SN_SAL section
+       // may have set the entries to -1 via set_sal_first().
+       vim_memset(lp->sl_sal_first, 0, sizeof(salfirst_T) * 256);
        for (p = from, s = to; *p != NUL && *s != NUL; )
        {
            c = mb_cptr2char_adv(&p);
index fa3fb14fd8ee6adee4e32c5971b86108d2b718f3..b8e710eb64cc1b34fd849b57e568a73636456edb 100644 (file)
@@ -319,6 +319,11 @@ func Test_spellfile_format_error()
   " SN_SOFO: multi-byte characters in sofofrom and sofoto
   call Spellfile_Test(0z0600000000080002CF810002CF82FF000000000000000000000000, '')
 
+  " SN_SAL (empty) followed by SN_SOFO with two multi-byte 'from' characters
+  " sharing the same low byte.  A preceding SN_SAL poisons sl_sal_first[], so
+  " without a reset set_sofo() under-counts and writes out of bounds.
+  call Spellfile_Test(0z05000000000300000006000000000A0004CAABCEAB00024142FF000000000000000000000000, '')
+
   " SN_COMPOUND: compmax is less than 2
   call Spellfile_Test(0z08000000000101, 'E759:')
 
index a93ef0384262ed93f5f17d7522cd20ca57f5e00f..5547cf4d524ad7ac46750c68bfa4c2756a850f49 100644 (file)
@@ -758,6 +758,8 @@ static char *(features[]) =
 
 static int included_patches[] =
 {   /* Add new patch number below this line */
+/**/
+    846,
 /**/
     845,
 /**/