Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-96269

Опубликовано: 22 сент. 2026
Источник: debian
EPSS Низкий

Описание

GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular user settings are required to trigger it.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
emacsfixed1:30.2+1-11package

Примечания

  • https://www.openwall.com/lists/oss-security/2026/08/20/3

  • https://eshelyaron.com/posts/2026-08-06-emacs-arbitrary-code-execution-returns.html

  • https://debbugs.gnu.org/cgi/bugreport.cgi?bug=80574#227

  • Mitigated by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-31&id=8466eb44991707d128110bdc549fad14c8e1d61e

  • Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=c1337758a6c00e22e2a685e0556068fd73fa9a54

EPSS

Процентиль: 8%
0.00184
Низкий

Связанные уязвимости

CVSS3: 7.8
redhat
2 дня назад

A flaw was found in GNU Emacs. A remote attacker could achieve arbitrary code execution by tricking a user into opening a specially crafted file. This vulnerability arises because an untrusted value of read-symbol-shorthands affects the intern and unintern functions, allowing for code execution without specific user settings.

nvd
1 день назад

GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular user settings are required to trigger it.

msrc
около 13 часов назад

GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular user settings are required to trigger it.

github
1 день назад

GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular user settings are required to trigger it.

EPSS

Процентиль: 8%
0.00184
Низкий