macvim-dev / macvim-dev/macvim
[Security] MacVim affected by GHSA-q4jv-r9gj-6cwv — heap buffer overflow in spellfile.c read_compound() (vim < 9.2.0450)
Nadie ha tomado este issue todavía.
- Lenguaje dominante
- Vim Script
- Estrellas
- 7.9k
- Forks
- 691
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Descripción
Summary
MacVim's src/spellfile.c contains a heap buffer overflow in read_compound() when loading specially crafted spell files. An integer overflow in the allocation size computation allows a malicious .spl file to cause out-of-bounds writes. The fix from vim 9.2.0450 (92993329) has not been applied to macvim r183.
Vulnerability Details
- GHSA: GHSA-q4jv-r9gj-6cwv
- CVE: CVE-2026-45130
- Upstream fix (vim): 9.2.0450 (commit
929933294a5c56ef8e9dab03e0b8c61bbb1dc3cd, 2026-05-07) - Affected code:
src/spellfile.c—read_compound()function - Vulnerability type: CWE-122 — Heap-based Buffer Overflow
Root Cause
In read_compound(), the todo variable (derived from the SN_COMPOUND section length in the spell file) is used directly in buffer size calculations without an upper bound check:
/* src/spellfile.c line 1278 (macvim r183) */
c = todo * 2 + 7;
A malicious spell file can set todo to a large value (e.g., 0x40000000), causing todo * 2 to overflow a 32-bit integer to 7, resulting in an undersized allocation. Subsequent writes to the buffer cause a heap overflow.
Attack Scenario
- Attacker provides a malicious
.splspell file (e.g., in a project's spell directory) - Victim loads the spell file in MacVim (
:setlocal spelllang=...or via modeline) read_compound()allocates an undersized buffer and writes beyond it, potentially enabling arbitrary code execution
Verification
$ grep -n 'todo.*2.*7\|read_compound\|COMPOUND_MAX_LEN' src/spellfile.c
1278: c = todo * 2 + 7;
Missing the COMPOUND_MAX_LEN guard and safe size computation. Patch 9.2.0450 not present:
$ git log --all --oneline | grep -i '9.2.0450\|spellfile\|q4jv'
(no output)
Suggested Fix
Merge vim patches up to at least 9.2.0450. The fix adds an upper bound check and uses size_t arithmetic:
/* Fixed (vim 9.2.0450): */
#define COMPOUND_MAX_LEN 100000
if ((size_t)todo > COMPOUND_MAX_LEN)
return SP_FORMERROR;
size_t patsize = (size_t)todo * 2 + 7;
size_t flagsize = (size_t)todo + 1;
pat = alloc(patsize);
cp = alloc(flagsize);
ap = alloc(flagsize);
crp = alloc(flagsize);
References
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Línea de trabajo
Comience en src/spellfile.c, en read_compound(), especialmente con la asignación basada en TODO alrededor de la línea 1278, y compárela con el commit de Vim 929933294a5c56ef8e9dab03e0b8c61bbb1dc3cd. Aplique la corrección upstream para realizar cálculos de tamaño acotados y seguros, y verifique que la asignación vulnerable ya no esté presente en MacVim r183.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- c, vim
- Área
- desktop, security
- Tipo de issue
- Error
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Estado de actividad
- Tranquilo
- Claridad
- Bien especificado
- Aptitud para principiantes
- 68/100