[ GLSA 202608-18 ] Emacs: Arbitrary code execution

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <178719480285.1.4271362688084709365@f5bc8f6d682b>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202608-18
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: Emacs: Arbitrary code execution
     Date: August 20, 2026
     Bugs: #980616
       ID: 202608-18

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A vulnerability has been discovered in Emacs which could lead to
arbitrary code execution.

Background
==========

Emacs is the extensible, customizable, self-documenting real-time
display editor. org-mode is an Emacs mode for notes and project
planning.

Affected packages
=================

Package            Vulnerable     Unaffected
-----------------  -------------  --------------
app-editors/emacs  < 28.2-r21:28  >= 28.2-r21:28
                   < 29.4-r9:29   >= 29.4-r9:29
                   < 30.2-r5:30   >= 30.2-r5:30
                   < 28.2-r21     >= 28.2-r21

Description
===========

A vulnerability has been discovered in Emacs. Please review the CVE
identifier referenced below for details.

Impact
======

An attacker could achieve arbitrary code execution by tricking a user
into opening a file with malicious content. No other action by the user
is required.

Workaround
==========

Avoid opening any untrusted files.

Resolution
==========

All Emacs 28 users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=app-editors/emacs-28.2-r21:28"

All Emacs 29 users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=app-editors/emacs-29.4-r9:29"

All Emacs 30 users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=app-editors/emacs-30.2-r5:30"

References
==========


Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202608-18

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 870 B)
-----BEGIN PGP SIGNATURE-----

iQJPBAEBCAA5FiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmqGbbIbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyAAoJEBTEJDmlcvvZhpMP/irjOyInyLGmdykbUhcl
v+IVK+EIeT1gqUYdbAcXvdtiY4Cq+xwEfcWVAcDM24XqGzItDZhXFl8syjK5Wfqg
PFybHok54DVJ5n3oa/qMG77DbOfrow6U3MUOCBbHkb6XlAYZNAX8nFzQU2cQ6KB4
qwTVZdze5eim6rQxcNRFmJhlaRJXdruN7BHzXUqPmUL9ddE7jcIDC08jBE3lOH93
/TD35pUsdtFgjYWCOCLObhXJ9kP/MstB5RzDBUMyVavTxdETO/NYkeSkfBwXccMp
8vBXucKpRDjMao6t746R0ZD8guBfPuv6V/KSRZthVemUA9HjaHd4Y9Q8DEU+nl3Z
iL6jicGXarCbbIFlroIGDe5DabcmlR8oiYbDys9CuVIzPx/FYdwuDOAbq9apIRJ0
8tn/B1RSLrHRwxMQfjb2oTKtXqFQNS4QVUMaRS0ttsZNadR5imN3yya4FfOREYdr
vWKKQKm5Tmm+9NRnXqxhCz0jods4PuycMZ267U84q0rddO3d+9IfOZmAzkO17P0F
LDppmfpTTmY4i4F1SuQLfttGesxhaoAhDzbKtCbNQgawNP5RbC7zMMr8kDFzT3XF
2feqyZjsBG6y+/KRldJ9MYSifBHyjhiO6e+ADa/IIkvDjy0tDD8jeV/mRgZ9recJ
p6PNsWKh5Ixbm7sW7T56iR2K
=oUg6
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.