¡¾·ì϶¹«¸æ¡¿Vim modeline ɳÏäÈÆ¹ýºÅÁîÖ´Ðзì϶(CVE-2026-34982)
°ä²¼¹¦·ò 2026-04-02Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Vim modeline ɳÏäÈÆ¹ýºÅÁîÖ´Ðзì϶ | ||
CVE ID | CVE-2026-34982 | ||
·ì϶ÀàÐÍ | ºÅÁîÖ´ÐÐ | ·¢ÏÖ¹¦·ò | 2026-4-2 |
·ì϶ÆÀ·Ö | 8.8 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ±¾µØ | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ±ØÒª |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
VimÊÇÒ»¿î¿í·ºÊ¹ÓõĿªÔ´Îı¾±à×ëÆ÷£¬Ö§³Ö¶àƽ̨ÔËÐУ¬¾ß±¸¸ßЧ±à×ë¡¢¾ç±¾À©´ó¼°·á˶²å¼þÉú̬µÈ¸öÐÔ¡£Æämodeline¡¢autocmdµÈ»úÔì¿ÉʵÏÖ×Ô¶¯»¯ÅäÖÃÓëÐÐΪ½ÚÔ죬¿í·ºÀûÓÃÓÚ¿ª·¢¡¢ÔËά¼°ÏµÍ³ÖÎÀí³¡¾°£¬ÊÇÀàUnixϵͳÖеÄÖ÷Ì⹤¾ßÖ®Ò»¡£
2026Äê4ÔÂ2ÈÕ£¬±¦ÔËÀ³¹Ù·½ÍøÕ¾°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½Vim modeline ɳÏäÈÆ¹ýºÅÁîÖ´Ðзì϶¡£¸Ã·ì϶´æÔÚÓÚmodeline½âÎö»úÔì¼°ÓйØÑ¡ÏîʵÏÖÖУ¬ÓÉÓÚcomplete¡¢guitabtooltipºÍprintheaderµÈÑ¡ÏîδÕýÈ·ÉèÖÃP_MLE»òP_SECURE°²È«±êÖ¾£¬µ¼ÖÂmodeline°²È«²é³±»Èƹý¡£Í¬Ê±£¬mapset()º¯Êý¶Ìȱcheck_secure()УÑ飬ʹ¹¥»÷Õß¿ÉÔÚÊÜÏÞ»·¾³ÖÐÖ´ÐжñÒâ±í°×ʽ¡£¹¥»÷Õß¿Éͨ¹ý»ú¹ØÌØÔìÎļþÓÕµ¼Óû§´ò¿ª£¬´Ó¶øÔÚ±¾µØÖ´ÐÐËÁÒâ²Ù×÷ϵͳºÅÁ»ñÈ¡Óû§È¨ÏÞ²¢½øÒ»²½½ÚÔìϵͳ¡£¸Ã·ì϶¿ÉÄÜÎ¥·´ÆóÒµÖն˰²È«¼°Êý¾Ý±£»¤ÓйغϹæÒªÇ󣬶Կª·¢»·¾³¼°ÔËάÖ÷»ú°²È«×é³ÉÑϳÁÍþв¡£
¶þ¡¢Ó°ÏìÁìÓò
Vim < 9.2.0276
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/vim/vim/tags/
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£


¾©¹«Íø°²±¸11010802024551ºÅ