PT-2026-97059 · Gnu · Emacs
CVE-2026-96269
·
Published
2026-09-22
·
Updated
2026-09-24
CVSS v4.0
7.5
High
| Vector | AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
GNU Emacs versions 28.1 through 31.1
Description
Opening a file can lead to arbitrary code execution due to an issue where an untrusted value of
read-symbol-shorthands affects the intern() and unintern() functions. This issue occurs with the default configuration and does not require specific user settings to be triggered.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emacs