PT-2026-69445 · Gnu · Emacs For Android
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
GNU Emacs for Android (affected versions not specified)
Description
An integer overflow exists in the
sfnt read cmap format 12() function within src/sfnt.c. On 32-bit builds, an unguarded addition during an xmalloc allocation call can wrap around when processing a specially crafted TrueType font file. This leads to a heap buffer overflow write and subsequent heap memory corruption, which may allow for remote code execution. An attacker can trigger this by delivering a malicious font file through email, EWW (Emacs Web Wowser), or documents utilizing custom faces.Recommendations
Apply the fix provided in commit c4e20777c26548722a37b03db93243e83a0d6188.
Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emacs For Android