Re: CVE-2026-79992: local shell command injection through the user field in emacs tramp

Sam James <[email protected]>
Newsgroups gmane.emacs.devel
Organization Gentoo
Message-ID <[email protected]>
Peter Oliver <[email protected]> writes:

> I see that CVE-2026-79992 has been reported against TRAMP, but is
> quite vague (https://www.cve.org/CVERecord?id=CVE-2026-79992).  Does
> anyone know more about it, and whether it is already fixed on some
> branch(es)?  I don’t see anything obviously related in the Emacs
> bugtracker.

See https://www.openwall.com/lists/oss-security/2026/08/21/1.

I think it's only fixed on the emacs-31 and master branches. We did
backports downstream, listed at
https://www.openwall.com/lists/oss-security/2026/08/24/3.

commit f3e7104d05bdb8e32ba13bf75604108ad88536dc
Author:     Michael Albinus <[email protected]>
AuthorDate: Fri Aug 21 14:23:38 2026 +0200
Commit:     Michael Albinus <[email protected]>
CommitDate: Fri Aug 21 14:23:38 2026 +0200

    Restrict Tramp user name

...

is the fix.

sam
signature.asc (application/pgp-signature, 418 B)
-----BEGIN PGP SIGNATURE-----

iQEBBAEWCgCpFiEEJaa7iN2bdkxrVUHCc4QJ9SDfkZAFAmqO7ZMbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25z
Lm9wZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQyNUE2QkI4OEREOUI3NjRDNkI1NTQx
QzI3Mzg0MDlGNTIwREY5MTkwDxxzYW1AZ2VudG9vLm9yZwAKCRBzhAn1IN+RkKTd
AP44bmLyi2MOUVvT1paEF8IK6Wcvk59BV+hLvpBbH0X3EQD+Kli3N/xntlglfN5J
tifgVRCmI2NLTWnVL/HMrtlZ/wk=
=iaAR
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.