logo

Vulnerabilities in GNU Emacs software

ID: b13219a8-1e32-5486-bcc9-de0dc29bae4c

STIX ID: report--b13219a8-1e32-5486-bcc9-de0dc29bae4c

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2026-08-10

Date Updated: 2026-08-10

Author: CERT Polska

...
...

CERT Polska coordinated disclosure of four vulnerabilities (CVE-2026-71391–71394) in GNU Emacs for Android (<= 30.2) that stem from flaws in the sfnt font parser (off-by-one, integer overflows, and improper validation). Crafted TrueType variable fonts delivered via email, EWW, or documents with custom faces can trigger out-of-bounds reads, heap overflows, or use of uninitialized memory, potentially leading to information disclosure or remote code execution; fixes are referenced by commit IDs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.