Vulnerabilities in GNU Emacs software
ID: b13219a8-1e32-5486-bcc9-de0dc29bae4c
STIX ID: report--b13219a8-1e32-5486-bcc9-de0dc29bae4c
Feed Name: CERT Polska
CERT Polska coordinated disclosure of four vulnerabilities (CVE-2026-71391–71394) in GNU Emacs for Android (<= 30.2) that stem from flaws in the sfnt font parser (off-by-one, integer overflows, and improper validation). Crafted TrueType variable fonts delivered via email, EWW, or documents with custom faces can trigger out-of-bounds reads, heap overflows, or use of uninitialized memory, potentially leading to information disclosure or remote code execution; fixes are referenced by commit IDs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
