diff --git a/backport-CVE-2022-3705.patch b/backport-CVE-2022-3705.patch new file mode 100644 index 0000000000000000000000000000000000000000..28d227049608ba2a001c292366ad50ddec2f44bd --- /dev/null +++ b/backport-CVE-2022-3705.patch @@ -0,0 +1,64 @@ +From d0fab10ed2a86698937e3c3fed2f10bd9bb5e731 Mon Sep 17 00:00:00 2001 +From: Bram Moolenaar +Date: Thu, 20 Oct 2022 16:03:33 +0100 +Subject: [PATCH] patch 9.0.0805: filetype autocmd may cause freed memory + access + +Problem: Filetype autocmd may cause freed memory access. +Solution: Set the quickfix-busy flag while filling the buffer. +--- + src/quickfix.c | 6 ++++++ + src/testdir/test_quickfix.vim | 15 +++++++++++++++ + 2 files changed, 21 insertions(+) + +diff --git a/src/quickfix.c b/src/quickfix.c +index a90611475ab1..f85fff56f23d 100644 +--- a/src/quickfix.c ++++ b/src/quickfix.c +@@ -4420,6 +4420,9 @@ qf_update_buffer(qf_info_T *qi, qfline_T *old_last) + { + linenr_T old_line_count = buf->b_ml.ml_line_count; + ++ // autocommands may cause trouble ++ incr_quickfix_busy(); ++ + if (old_last == NULL) + // set curwin/curbuf to buf and save a few things + aucmd_prepbuf(&aco, buf); +@@ -4441,6 +4444,9 @@ qf_update_buffer(qf_info_T *qi, qfline_T *old_last) + // when the added lines are not visible. + if ((win = qf_find_win(qi)) != NULL && old_line_count < win->w_botline) + redraw_buf_later(buf, NOT_VALID); ++ ++ // always called after incr_quickfix_busy() ++ decr_quickfix_busy(); + } + } + +diff --git a/src/testdir/test_quickfix.vim b/src/testdir/test_quickfix.vim +index 2ee754b39690..bcaef5da175c 100644 +--- a/src/testdir/test_quickfix.vim ++++ b/src/testdir/test_quickfix.vim +@@ -4771,4 +4771,19 @@ func Test_lopen_bwipe() + delfunc R + endfunc + ++func Test_filetype_autocmd() ++ " this changes the location list while it is in use to fill a buffer ++ lexpr '' ++ lopen ++ augroup FT_loclist ++ au FileType * call setloclist(0, [], 'f') ++ augroup END ++ silent! lolder ++ lexpr '' ++ ++ augroup FT_loclist ++ au! FileType ++ augroup END ++endfunc ++ + " vim: shiftwidth=2 sts=2 expandtab +-- +2.33.0 + diff --git a/vim.spec b/vim.spec index 0937b463acf32ec6fabd4422a3b85bfc1420fea6..164791482ab9c16c6c4e1d4be61108878adc6a05 100644 --- a/vim.spec +++ b/vim.spec @@ -12,7 +12,7 @@ Name: vim Epoch: 2 Version: 8.2 -Release: 71 +Release: 72 Summary: Vim is a highly configurable text editor for efficiently creating and changing any kind of text. License: Vim and MIT URL: http://www.vim.org @@ -193,6 +193,7 @@ Patch6151: backport-CVE-2022-3296.patch Patch6152: backport-CVE-2022-3297.patch Patch6153: backport-9.0.0581-adding-a-character-for-incsearch-fails-at-end-of-line.patch Patch6154: backport-CVE-2022-3324.patch +Patch6155: backport-CVE-2022-3705.patch BuildRequires: autoconf python3-devel ncurses-devel gettext perl-devel perl-generators gcc BuildRequires: perl(ExtUtils::Embed) perl(ExtUtils::ParseXS) libacl-devel gpm-devel file @@ -582,6 +583,12 @@ LC_ALL=en_US.UTF-8 make -j1 test %{_mandir}/man1/evim.* %changelog +* Mon Oct 31 2022 wangjiang - 2:8.2-72 +- Type:CVE +- ID:CVE-2022-3705 +- SUG:NA +- DESC:fix CVE-2022-3705 + * Mon Oct 17 2022 dongyuzhen - 2:8.2-71 - Type:CVE - ID:CVE-2022-3324