emacs-31 8466eb44991: Mitigate arbitrary code execution vulnerability

Eshel Yaron via Mailing list for Emacs changes <[email protected]> Wed, 5 Aug 2026 14:14:20 -0400 (EDT)
Newsgroups gmane.emacs.diffs
Message-ID <[email protected]>
branch: emacs-31
commit 8466eb44991707d128110bdc549fad14c8e1d61e
Author: Eshel Yaron <[email protected]>
Commit: Eshel Yaron <[email protected]>

    Mitigate arbitrary code execution vulnerability
    
    This mitigates a vulnerability that allowed a specially
    crafted file to trigger execution of attacker-controlled
    arbitrary Emacs Lisp code immediately when the file is
    visited in Emacs (before the file's malicious contents are
    even displayed).  See demonstration in bug#80574.
    
    * lisp/progmodes/cc-fonts.el (c-compose-keywords-list):
    * lisp/vc/vc-hooks.el (vc-find-backend-function):
    Nullify 'read-symbol-shorthands' around risky 'intern' calls.
    Do not merge to master.
---
 lisp/progmodes/cc-fonts.el | 10 +++++++---
 lisp/vc/vc-hooks.el        |  5 ++++-
 2 files changed, 11 insertions(+), 4 deletions(-)

diff --git a/lisp/progmodes/cc-fonts.el b/lisp/progmodes/cc-fonts.el
index 9103787df7a..49346f81dfb 100644
--- a/lisp/progmodes/cc-fonts.el
+++ b/lisp/progmodes/cc-fonts.el
@@ -2585,9 +2585,13 @@ higher."
   (let* ((doc-keywords (c-get-doc-comment-style))
 	 (list (nconc (c--mapcan
 		       (lambda (doc-style)
-			 (let ((sym (intern
-				     (concat (symbol-name doc-style)
-					     "-font-lock-keywords"))))
+			 (let ((sym
+				;; Guard `intern' from potentially
+				;; malicious shorthands.
+				(let (read-symbol-shorthands)
+				  (intern
+				   (concat (symbol-name doc-style)
+					   "-font-lock-keywords")))))
 			   (cond ((fboundp sym)
 				  (funcall sym))
 				 ((boundp sym)
diff --git a/lisp/vc/vc-hooks.el b/lisp/vc/vc-hooks.el
index 132b9211f88..5775983fd91 100644
--- a/lisp/vc/vc-hooks.el
+++ b/lisp/vc/vc-hooks.el
@@ -299,7 +299,10 @@ properties further down the directory hierarchy override ones higher up."
   "Return BACKEND-specific implementation of FUN.
 If there is no such implementation, return the default implementation;
 if that doesn't exist either, return nil."
-  (let ((f (vc-make-backend-sym backend fun)))
+  ;; Nullify `read-symbol-shorthands' to guard the `intern' calls below
+  ;; and in `vc-make-backend-sym' from potentially malicious shorthands.
+  (let* ((read-symbol-shorthands nil)
+         (f (vc-make-backend-sym backend fun)))
     (if (fboundp f) f
       ;; Load vc-BACKEND.el if needed.
       (require (intern (concat "vc-" (downcase (symbol-name backend)))))