Bug 2293942 (CVE-2024-39331) - CVE-2024-39331 emacs: org-link-expand-abbrev: Do not evaluate arbitrary unsafe Elisp code
Summary: CVE-2024-39331 emacs: org-link-expand-abbrev: Do not evaluate arbitrary unsaf...
Keywords:
Status: NEW
Alias: CVE-2024-39331
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2293944
Blocks: 2293945
TreeView+ depends on / blocked
 
Reported: 2024-06-24 13:38 UTC by Avinash Hanwate
Modified: 2024-12-09 09:15 UTC (History)
1 user (show)

Fixed In Version: emacs 29.4
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2024:6519 0 None None None 2024-09-09 21:46:33 UTC
Red Hat Product Errata RHBA-2024:6537 0 None None None 2024-09-10 15:16:23 UTC
Red Hat Product Errata RHBA-2024:6585 0 None None None 2024-09-11 11:29:49 UTC
Red Hat Product Errata RHBA-2024:6651 0 None None None 2024-09-12 14:37:59 UTC
Red Hat Product Errata RHBA-2024:6864 0 None None None 2024-09-19 14:26:41 UTC
Red Hat Product Errata RHBA-2024:7038 0 None None None 2024-09-24 09:09:33 UTC
Red Hat Product Errata RHBA-2024:7039 0 None None None 2024-09-24 09:09:51 UTC
Red Hat Product Errata RHBA-2024:7040 0 None None None 2024-09-24 09:10:32 UTC
Red Hat Product Errata RHBA-2024:7041 0 None None None 2024-09-24 09:12:29 UTC
Red Hat Product Errata RHBA-2024:7056 0 None None None 2024-09-24 14:01:48 UTC
Red Hat Product Errata RHBA-2024:7061 0 None None None 2024-09-24 15:13:57 UTC
Red Hat Product Errata RHBA-2024:7062 0 None None None 2024-09-24 15:22:51 UTC
Red Hat Product Errata RHBA-2024:7510 0 None None None 2024-10-02 12:19:40 UTC
Red Hat Product Errata RHBA-2024:7631 0 None None None 2024-10-03 13:32:04 UTC
Red Hat Product Errata RHBA-2024:7754 0 None None None 2024-10-07 13:41:58 UTC
Red Hat Product Errata RHSA-2024:4971 0 None None None 2024-08-01 08:03:51 UTC
Red Hat Product Errata RHSA-2024:6203 0 None None None 2024-09-03 16:04:08 UTC
Red Hat Product Errata RHSA-2024:6510 0 None None None 2024-09-09 18:28:07 UTC
Red Hat Product Errata RHSA-2024:6987 0 None None None 2024-09-24 02:58:51 UTC

Description Avinash Hanwate 2024-06-24 13:38:43 UTC
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.

References and upstream patch:
https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29
https://list.orgmode.org/87sex5gdqc.fsf%40localhost/
https://news.ycombinator.com/item?id=40768225
https://www.openwall.com/lists/oss-security/2024/06/23/1
https://www.openwall.com/lists/oss-security/2024/06/23/2
https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=f4cc61636947b5c2f0afc67174dd369fe3277aa8

Comment 1 Avinash Hanwate 2024-06-24 13:42:40 UTC
Created emacs tracking bugs for this issue:

Affects: fedora-all [bug 2293944]

Comment 4 errata-xmlrpc 2024-08-01 08:03:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2024:4971 https://access.redhat.com/errata/RHSA-2024:4971

Comment 5 errata-xmlrpc 2024-09-03 16:04:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2024:6203 https://access.redhat.com/errata/RHSA-2024:6203

Comment 6 errata-xmlrpc 2024-09-09 18:28:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2024:6510 https://access.redhat.com/errata/RHSA-2024:6510

Comment 7 errata-xmlrpc 2024-09-24 02:58:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:6987 https://access.redhat.com/errata/RHSA-2024:6987


Note You need to log in before you can comment on or make changes to this bug.