Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-77219

Опубликовано: 21 авг. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image loader multiplies image dimensions and channel count using signed integer arithmetic; for sufficiently large values, the result wraps to a negative number, bypassing the bounds check and causing the pixel reader to access heap memory past the end of the allocated buffer. The over-read contents are interpreted as pixel color values and rendered on screen.

A flaw was found in GNU Emacs. An integer overflow in the PBM/PPM/PGM image loader allows a remote attacker to leak heap memory contents. By supplying a specially crafted image with large dimensions and an elevated maximum color index, the image loader's internal calculations can wrap to a negative number, bypassing memory bounds checks. This enables the pixel reader to access and render sensitive information from heap memory.

Меры по смягчению последствий

To mitigate this issue, users should avoid opening or displaying untrusted PBM, PPM, or PGM image files within GNU Emacs. Exercise caution when handling image files from unknown or unverified sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10emacsAffected
Red Hat Enterprise Linux 6emacsOut of support scope
Red Hat Enterprise Linux 7emacsAffected
Red Hat Enterprise Linux 8emacsAffected
Red Hat Enterprise Linux 9emacsAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2521196emacs: GNU Emacs: Heap over-read leading to information disclosure via crafted image

EPSS

Процентиль: 3%
0.00128
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
22 дня назад

(GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/P ...)

CVSS3: 7.1
nvd
27 дней назад

GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image loader multiplies image dimensions and channel count using signed integer arithmetic; for sufficiently large values, the result wraps to a negative number, bypassing the bounds check and causing the pixel reader to access heap memory past the end of the allocated buffer. The over-read contents are interpreted as pixel color values and rendered on screen.

msrc
26 дней назад

GNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image Loader

CVSS3: 7.1
debian
27 дней назад

GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/P ...

CVSS3: 7.1
github
27 дней назад

GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image loader multiplies image dimensions and channel count using signed integer arithmetic; for sufficiently large values, the result wraps to a negative number, bypassing the bounds check and causing the pixel reader to access heap memory past the end of the allocated buffer. The over-read contents are interpreted as pixel color values and rendered on screen.

EPSS

Процентиль: 3%
0.00128
Низкий

7.1 High

CVSS3