Bug 2513086 (CVE-2026-71392) - CVE-2026-71392 emacs: integer overflow via a malicious font file
Summary: CVE-2026-71392 emacs: integer overflow via a malicious font file
Keywords:
Status: NEW
Alias: CVE-2026-71392
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-10 10:31 UTC by OSIDB Bzimport
Modified: 2026-08-12 19:47 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-10 10:31:58 UTC
GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueType font file, an unguarded addition in the xmalloc allocation call wraps around on 32-bit builds, causing a heap buffer overflow write. An attacker can deliver a malicious font file via email, EWW (Emacs Web Wowser), or documents with custom faces, causing Emacs to load it. This results in heap memory corruption that can lead to code execution.


This issue was fixed in commit c4e20777c26548722a37b03db93243e83a0d6188


Note You need to log in before you can comment on or make changes to this bug.