Emacs Vulnerability Fix Incomplete, Affects Multiple Versions
Tech
⚠ Single-source
1h ago

Emacs Vulnerability Fix Incomplete, Affects Multiple Versions

AI-synthesized · Bias removed · Facts only

Sean Whitton has announced that a previous fix for an arbitrary code execution flaw in Emacs (CVE-2024-53920) was not comprehensive. Bas Alberts discovered that the vulnerability extends to viewing or editing untrusted files in Emacs modes other than Lisp mode, potentially allowing arbitrary code execution.

This issue impacts all Emacs versions affected by CVE-2024-53920, which includes Emacs 24 and newer, and potentially older releases as well. A minimal fix has been queued for inclusion in Emacs 31.2.

The Emacs upstream maintainers do not plan to backport the fix to older Emacs releases. LWN previously reported on the original vulnerability in December 2024.

Was this useful?

Read the original coverage

💬 Comments

📜 Comment Policy