CVE-2025-22134 was announced here: https://openwall.com/lists/oss-security/2025/01/11/1
CVE: (none) => CVE-2025-22134Whiteboard: (none) => MGA9TOOSource RPM: (none) => vim-9.1.771-2.mga10.src.rpm, vim-9.1.771-1.mga9.src.rpm
Status comment: (none) => Fixed upstream in 9.1.1003
Suggested advisory: ======================== The updated packages fix a security vulnerability: Heap-buffer-overflow with visual mode in Vim < 9.1.1003. (CVE-2025-22134) References: https://openwall.com/lists/oss-security/2025/01/11/1 ======================== Updated packages in core/updates_testing: ======================== vim-X11-9.1.1012-1.mga9 vim-common-9.1.1012-1.mga9 vim-enhanced-9.1.1012-1.mga9 vim-minimal-9.1.1012-1.mga9 from SRPM: vim-9.1.1012-1.mga9.src.rpm
Status comment: Fixed upstream in 9.1.1003 => (none)Status: NEW => ASSIGNEDVersion: Cauldron => 9Whiteboard: MGA9TOO => (none)Source RPM: vim-9.1.771-2.mga10.src.rpm, vim-9.1.771-1.mga9.src.rpm => vim-9.1.771-1.mga9.src.rpmAssignee: bugsquad => qa-bugs
Keywords: (none) => advisory
Something is rotten the packages still not arrive to testing and https://pkgsubmit.mageia.org/ shows "partial" as status, The mirror status show 2025-01-10 as last update and the packages are of 2025-01-14 Lack of space again ?
Keywords: (none) => feedbackCC: (none) => sysadmin-bugs
(In reply to katnatek from comment #2) > Something is rotten the packages still not arrive to testing and > https://pkgsubmit.mageia.org/ shows "partial" as status, The mirror status > show 2025-01-10 as last update and the packages are of 2025-01-14 I mean 2025-01-13
At least packages are in http://mirror.accum.se/mirror/mageia/distrib/9/x86_64/media/core/updates_testing/
CC: (none) => fri
(In reply to Morgan Leijström from comment #4) > At least packages are in > http://mirror.accum.se/mirror/mageia/distrib/9/x86_64/media/core/ > updates_testing/ Looks like mirrors start to update again RH x86_64 I test the POC file and command and vim freeza after that installing vim-X11-9.1.1012-1.mga9.x86_64.rpm vim-common-9.1.1012-1.mga9.x86_64.rpm vim-minimal-9.1.1012-1.mga9.x86_64.rpm vim-enhanced-9.1.1012-1.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64 Preparing... ################################################################################################## 1/4: vim-common ################################################################################################## 2/4: vim-X11 ################################################################################################## 3/4: vim-enhanced ################################################################################################## 4/4: vim-minimal ################################################################################################## 1/4: removing vim-enhanced-9.1.771-1.mga9.x86_64 ################################################################################################## 2/4: removing vim-X11-9.1.771-1.mga9.x86_64 ################################################################################################## 3/4: removing vim-common-9.1.771-1.mga9.x86_64 ################################################################################################## 4/4: removing vim-minimal-9.1.771-1.mga9.x86_64 ################################################################################################## Still the same with the POC Edit files, close and reopen the files edited, the changes persist Load the files with Gvim, OK OK with exception of the POC test Let to others decide if should be validated
CC: sysadmin-bugs => (none)
(In reply to katnatek from comment #5) > Still the same with the POC > Edit files, close and reopen the files edited, the changes persist > Load the files with Gvim, OK > > OK with exception of the POC test > Let to others decide if should be validated Hi, I was not able to find the POC. Where did you find it, please? Best regards,
(In reply to Nicolas Salguero from comment #6) > Hi, > > I was not able to find the POC. Where did you find it, please? > > Best regards, https://github.com/vim/vim/security/advisories/GHSA-5rgf-26wj-48v8 If you click on Details, you will find a link to the POC file and the suggested command to make the test
$ vim -u NONE -i NONE -n -m -X -Z -e -s -S ./vim_hbo_1272 -c ':qa!' o 8 -¹ð Stuck at this point. Had to remove the terminal. After updating: $ vim -u NONE -i NONE -n -m -X -Z -e -s -S ./vim_hbo_1272 -c ':qa!' $ So the PoC succeeds.
CC: (none) => tarazed25
Thank you Len :) Validating.
Keywords: feedback => validated_updateWhiteboard: (none) => MGA9-64-OKCC: (none) => sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2025-0014.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED