#1148177 emacs: Incomplete fix for CVE-2024-53920

Package:
src:emacs
Source:
src:emacs
Submitter:
Salvatore Bonaccorso
Date:
2026-09-17 20:25:02 UTC
Severity:
normal
Tags:
#1148177#5
Date:
2026-09-17 20:22:45 UTC
From:
To:
Hi

As reported in
https://www.openwall.com/lists/oss-security/2026/09/14/1, the fix for
CVE-2024-53920 was incomplete:
| Bas Alberts of the GitHub Security Lab discovered that the fix for
| CVE-2024-53920, an arbitrary code execution flaw in Emacs, was
| incomplete.  Viewing or editing untrusted text files in modes other than
| Emacs Lisp mode can also permit arbitrary code execution.

Regards,
Salvatore