macvim-dev / macvim-dev/macvim

[Security] MacVim affected by GHSA-q4jv-r9gj-6cwv — heap buffer overflow in spellfile.c read_compound() (vim < 9.2.0450)

Offen
#1,660 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Vorherrschende Sprache
Vim Script
Sterne
7.9k
Forks
691
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

Summary

MacVim's src/spellfile.c contains a heap buffer overflow in read_compound() when loading specially crafted spell files. An integer overflow in the allocation size computation allows a malicious .spl file to cause out-of-bounds writes. The fix from vim 9.2.0450 (92993329) has not been applied to macvim r183.

Vulnerability Details

  • GHSA: GHSA-q4jv-r9gj-6cwv
  • CVE: CVE-2026-45130
  • Upstream fix (vim): 9.2.0450 (commit 929933294a5c56ef8e9dab03e0b8c61bbb1dc3cd, 2026-05-07)
  • Affected code: src/spellfile.cread_compound() function
  • Vulnerability type: CWE-122 — Heap-based Buffer Overflow

Root Cause

In read_compound(), the todo variable (derived from the SN_COMPOUND section length in the spell file) is used directly in buffer size calculations without an upper bound check:

/* src/spellfile.c line 1278 (macvim r183) */
c = todo * 2 + 7;

A malicious spell file can set todo to a large value (e.g., 0x40000000), causing todo * 2 to overflow a 32-bit integer to 7, resulting in an undersized allocation. Subsequent writes to the buffer cause a heap overflow.

Attack Scenario
  1. Attacker provides a malicious .spl spell file (e.g., in a project's spell directory)
  2. Victim loads the spell file in MacVim (:setlocal spelllang=... or via modeline)
  3. read_compound() allocates an undersized buffer and writes beyond it, potentially enabling arbitrary code execution

Verification

$ grep -n 'todo.*2.*7\|read_compound\|COMPOUND_MAX_LEN' src/spellfile.c
1278:    c = todo * 2 + 7;

Missing the COMPOUND_MAX_LEN guard and safe size computation. Patch 9.2.0450 not present:

$ git log --all --oneline | grep -i '9.2.0450\|spellfile\|q4jv'
(no output)

Suggested Fix

Merge vim patches up to at least 9.2.0450. The fix adds an upper bound check and uses size_t arithmetic:

/* Fixed (vim 9.2.0450): */
#define COMPOUND_MAX_LEN 100000

if ((size_t)todo > COMPOUND_MAX_LEN)
    return SP_FORMERROR;
size_t patsize = (size_t)todo * 2 + 7;
size_t flagsize = (size_t)todo + 1;
pat = alloc(patsize);
cp = alloc(flagsize);
ap = alloc(flagsize);
crp = alloc(flagsize);

References

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Beginnen Sie in src/spellfile.c bei read_compound(), insbesondere bei der TODO-basierten Allokation um Zeile 1278, und vergleichen Sie sie mit dem Vim-Commit 929933294a5c56ef8e9dab03e0b8c61bbb1dc3cd. Wenden Sie den Upstream-Fix für begrenzte, sichere Größenberechnungen an und überprüfen Sie, dass die verwundbare Allokation in MacVim r183 nicht mehr vorhanden ist.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
c, vim
Bereich
desktop, security
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Ruhig
Klarheit
Klar beschrieben
Anfängerfreundlichkeit
68/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.