[ GLSA 202608-21 ] GNU Emacs: Arbitrary code execution

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <178755344763.1.8978922206760670223@f5bc8f6d682b>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202608-21
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: GNU Emacs: Arbitrary code execution
     Date: August 24, 2026
     Bugs: #981157
       ID: 202608-21

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A vulnerability has been discovered in GNU Emacs allowing arbitrary code
execution.

Background
==========

GNU Emacs is the extensible, customizable, self-documenting real-time
display editor.

Affected packages
=================

Package            Vulnerable     Unaffected
-----------------  -------------  --------------
app-editors/emacs  < 27.2-r4:27   >= 27.2-r4:27
                   < 28.2-r22:28  >= 28.2-r22:28
                   < 29.4-r10:29  >= 29.4-r10:29
                   < 30.2-r6:30   >= 30.2-r6:30

Description
===========

A vulnerability has been discovered in GNU Emacs. Please review the CVE
identifier referenced below for details.

Impact
======

An attacker could achieve arbitrary code execution by tricking a user
into opening a file or directory with a malicious filename via TRAMP.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All GNU Emacs users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=app-editors/emacs-30.2-r6"

References
==========


Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202608-21

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 870 B)
-----BEGIN PGP SIGNATURE-----

iQJOBAEBCAA5FiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmqL5qcbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyAAoJEBTEJDmlcvvZW1AP9jE8SdwN5G+Xv9agwQyy
ZOm1NPql+xCawQ5G6owCut1osues5AQ51wdvEmVMlz7NyKuWgwB88O+XMpJf5KJ5
EQrGu6Glu4GKjVQLRWiPA12ex/rRRH7FchA+DXiM5GZF/lJaYwkb3/oPKeH6QZ4J
fxn0JnjAK7fcFVhCTn77Gk0giYGxWBNUuj1pBaoUh13L/M9/Dj6zuOnG59Ja2bwR
4Og/sdh4q/kXCxfPdN/b+Y721BrALLgxOQBgGHl4U142KpTX2DXV/pkhK28WMpE1
aVc1yS2yYrZHY8Mkc1FHzFD2neGGRh/ZoleyKLP1WW4VrdaYcREsCpyymV3ACiNJ
Rcy4wyNwkz+dc6ViPzU8TweHMoV1uAbXEkZOM2B0OnvUi7EcOu8dRmt9Udr2M9x6
O2W8/BeSwFtDLqM4nGfvaWUqs+XYLdWrUyzjCfMwM2zXnuxgF7IUCaMq2DMpNUw3
JXb7raZVfO67ZUNjerJo0qsPJsn0E8f70JcM45YhSlzRyW455gc2l1A9Ol77otIp
V2vDZrK9JaWrpWMBkqXmgUduTbgnWMiZfNmKGXuqneY3UFhnyuDjm2QPOTexuqDA
PhoZ7Zsg1+D19SQ5ev4998qoXLH8MUcRlx0UiZ72ix4etfCwgipvUo4l76/ODGmQ
31LW1I+6PvfG9nruG1fL/Hk=
=CFMU
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.