Re: CVE-2026-79992: local shell command injection through the user field in emacs tramp
Sam James <[email protected]>
| Newsgroups | gmane.emacs.devel |
|---|---|
| Organization | Gentoo |
| Message-ID | <[email protected]> |
Peter Oliver <[email protected]> writes: > I see that CVE-2026-79992 has been reported against TRAMP, but is > quite vague (https://www.cve.org/CVERecord?id=CVE-2026-79992). Does > anyone know more about it, and whether it is already fixed on some > branch(es)? I don’t see anything obviously related in the Emacs > bugtracker. See https://www.openwall.com/lists/oss-security/2026/08/21/1. I think it's only fixed on the emacs-31 and master branches. We did backports downstream, listed at https://www.openwall.com/lists/oss-security/2026/08/24/3. commit f3e7104d05bdb8e32ba13bf75604108ad88536dc Author: Michael Albinus <[email protected]> AuthorDate: Fri Aug 21 14:23:38 2026 +0200 Commit: Michael Albinus <[email protected]> CommitDate: Fri Aug 21 14:23:38 2026 +0200 Restrict Tramp user name ... is the fix. sam
signature.asc
(application/pgp-signature, 418 B)
-----BEGIN PGP SIGNATURE----- iQEBBAEWCgCpFiEEJaa7iN2bdkxrVUHCc4QJ9SDfkZAFAmqO7ZMbFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMiwyXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25z Lm9wZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQyNUE2QkI4OEREOUI3NjRDNkI1NTQx QzI3Mzg0MDlGNTIwREY5MTkwDxxzYW1AZ2VudG9vLm9yZwAKCRBzhAn1IN+RkKTd AP44bmLyi2MOUVvT1paEF8IK6Wcvk59BV+hLvpBbH0X3EQD+Kli3N/xntlglfN5J tifgVRCmI2NLTWnVL/HMrtlZ/wk= =iaAR -----END PGP SIGNATURE-----