emacs-31 8466eb44991: Mitigate arbitrary code execution vulnerability
Eshel Yaron via Mailing list for Emacs changes <[email protected]> Wed, 5 Aug 2026 14:14:20 -0400 (EDT)
| Newsgroups | gmane.emacs.diffs |
|---|---|
| Message-ID | <[email protected]> |
branch: emacs-31 commit 8466eb44991707d128110bdc549fad14c8e1d61e Author: Eshel Yaron <[email protected]> Commit: Eshel Yaron <[email protected]> Mitigate arbitrary code execution vulnerability This mitigates a vulnerability that allowed a specially crafted file to trigger execution of attacker-controlled arbitrary Emacs Lisp code immediately when the file is visited in Emacs (before the file's malicious contents are even displayed). See demonstration in bug#80574. * lisp/progmodes/cc-fonts.el (c-compose-keywords-list): * lisp/vc/vc-hooks.el (vc-find-backend-function): Nullify 'read-symbol-shorthands' around risky 'intern' calls. Do not merge to master. --- lisp/progmodes/cc-fonts.el | 10 +++++++--- lisp/vc/vc-hooks.el | 5 ++++- 2 files changed, 11 insertions(+), 4 deletions(-) diff --git a/lisp/progmodes/cc-fonts.el b/lisp/progmodes/cc-fonts.el index 9103787df7a..49346f81dfb 100644 --- a/lisp/progmodes/cc-fonts.el +++ b/lisp/progmodes/cc-fonts.el @@ -2585,9 +2585,13 @@ higher." (let* ((doc-keywords (c-get-doc-comment-style)) (list (nconc (c--mapcan (lambda (doc-style) - (let ((sym (intern - (concat (symbol-name doc-style) - "-font-lock-keywords")))) + (let ((sym + ;; Guard `intern' from potentially + ;; malicious shorthands. + (let (read-symbol-shorthands) + (intern + (concat (symbol-name doc-style) + "-font-lock-keywords"))))) (cond ((fboundp sym) (funcall sym)) ((boundp sym) diff --git a/lisp/vc/vc-hooks.el b/lisp/vc/vc-hooks.el index 132b9211f88..5775983fd91 100644 --- a/lisp/vc/vc-hooks.el +++ b/lisp/vc/vc-hooks.el @@ -299,7 +299,10 @@ properties further down the directory hierarchy override ones higher up." "Return BACKEND-specific implementation of FUN. If there is no such implementation, return the default implementation; if that doesn't exist either, return nil." - (let ((f (vc-make-backend-sym backend fun))) + ;; Nullify `read-symbol-shorthands' to guard the `intern' calls below + ;; and in `vc-make-backend-sym' from potentially malicious shorthands. + (let* ((read-symbol-shorthands nil) + (f (vc-make-backend-sym backend fun))) (if (fboundp f) f ;; Load vc-BACKEND.el if needed. (require (intern (concat "vc-" (downcase (symbol-name backend)))))