• Emacs arbitrary code execution flaw

    From LWN.net@1337:1/100 to All on Mon Sep 14 16:30:05 2026
    Emacs arbitrary code execution flaw

    Date:
    Mon, 14 Sep 2026 15:20:00 +0000

    Description:
    Sean Whitton has announced that the original fix for an arbitrary code execution flaw in Emacs ( CVE-2024-53920 ) was
    incomplete. Bas Alberts discovered that viewing or editing untrusted files in modes other than Emacs's Lisp mode can also result in arbitrary code
    execution. This problem affects all Emacs versions affected by CVE-2024-53920. This means Emacs 24 and newer, and possibly also older versions. A minimal fix, attached, is queued up for release with Emacs 31.2.
    We (the Emacs upstream maintainers) don't expect to backport the fix to
    older Emacs releases ourselves. LWN covered the original
    vulnerability in December 2024.

    ======================================================================
    Link to news story:
    https://lwn.net/Articles/1094224/


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet UK HUB @ hub.uk.erb.pw (1337:1/100)