PT-2026-69447 · Gnu · Gnu Emacs
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
GNU Emacs for Android (affected versions not specified)
Description
Improper validation of table header input occurs in the
sfnt read table directory() function within src/sfnt.c. An incorrect comparison variable during the read-length check allows a specially crafted font file to claim it contains more table directory entries than are actually present. This causes the parser to return a structure containing uninitialized heap memory. An attacker can trigger this by delivering a malicious font file via email, Emacs Web Wowser (EWW), or documents with custom faces. The subsequent use of this uninitialized heap data during table lookups can lead to information disclosure, system crashes, or arbitrary memory access on 32-bit targets.Recommendations
Update to the version containing commit 7621ee1d01229d50e5c0cddea6bf0b01095a62cf or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gnu Emacs