Re: Fixing security vulnerabilities before new releases
Eshel Yaron <[email protected]> Wed, 29 Jul 2026 19:37:41 +0200
| Newsgroups | gmane.emacs.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi, Manuel Giraud <[email protected]> writes: > Eshel Yaron <[email protected]> writes: > >> Sean Whitton <[email protected]> writes: >> >>> Eshel Yaron [29/Jul 1:16pm +02] wrote: >>>> >>>> Hmm... There's an arbitrary code execution vulnerability that makes >>>> opening files with Emacs unsafe. Indeed, it affects existing Emacs >>>> versions as well---that's a good reason to mitigate it ASAP and maybe >>>> provide a security fix for Emacs 30, but it wouldn't make sense to >>>> release another vulnerable version. >>>> ISTM that if anything is a release-blocker, this is it. >>> >>> I don't understand your reasoning at all here. We do not make the >>> situation worse by releasing Emacs 31. Therefore the issues are not >>> interdependent. >> >> OK, let me try to clarify it further: >> Releasing a new version invites more users to install and use it, >> and encouraging users to run vulnerable software is at best a disservice. >> True, it wouldn't make things worse for users who are already running a >> vulnerable version, but I don't think that's the right bar to aim for. >> Instead, we should make sure we make things better for them, by providing >> a version that mitigates this issue ASAP. AFAICT, releasing a vulnerable >> Emacs 31.1 would delay that mitigation unnecessarily. >> >> To be clear, I think a mitigation can be rather simple/straightforward, >> and it doesn't have to be the permanent solution. I'd recommend >> releasing Emacs 31 with a "bandaid" solution (I can suggest something if >> you agree), and fixing it properly in a later release. > > I'm with you and Óscar on this one but FWIW I was not able to reproduce > the code execution example given by Stefan. Writing the following in > /tmp/test.el and opening it doesn't do anything for me (I'm on current > master): [...] > What am I missing? I can readily reproduce it here, so your guess is as good as mine... Did you try with emacs -Q? Perhaps it's something in your config, like a non-default value of vc-handled-backends, or maybe you have trust-manager-mode enabled? :) Best, Eshel