Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package emacs for openSUSE:Factory checked 
in at 2026-09-28 10:37:04
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/emacs (Old)
 and      /work/SRC/openSUSE:Factory/.emacs.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "emacs"

Mon Sep 28 10:37:04 2026 rev:225 rq:1380658 version:31.1

Changes:
--------
--- /work/SRC/openSUSE:Factory/emacs/emacs.changes      2026-09-04 
12:37:24.005241087 +0200
+++ /work/SRC/openSUSE:Factory/.emacs.new.383539/emacs.changes  2026-09-28 
10:38:07.041004004 +0200
@@ -1,0 +2,8 @@
+Thu Sep 24 09:28:46 UTC 2026 - Dr. Werner Fink <[email protected]>
+
+- Add patch bsc1282390.patch
+  * Fix bsc#1282390 (CVE-2026-96442): arbitrary code execution when
+    viewing or editing untrusted text files in modes other than
+    Emacs Lisp mode due to incomplete fix for older CVE
+
+-------------------------------------------------------------------

New:
----
  bsc1282390.patch

----------(New B)----------
  New:
- Add patch bsc1282390.patch
  * Fix bsc#1282390 (CVE-2026-96442): arbitrary code execution when
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ emacs.spec ++++++
--- /var/tmp/diff_new_pack.RZ1Jsd/_old  2026-09-28 10:38:09.319099266 +0200
+++ /var/tmp/diff_new_pack.RZ1Jsd/_new  2026-09-28 10:38:09.322099391 +0200
@@ -259,6 +259,7 @@
 Patch55:        0015-Change-native-comp-async-jobs-number-default-to-1.patch
 Patch56:        0016-Change-native-comp-async-report-warnings-errors-to-s.patch
 Patch57:        emacs-30.2-fix-zoom.patch
+Patch58:        bsc1282390.patch
 
 BuildRoot:      %{_tmppath}/%{name}-%{version}-build
 %{expand: %%global include_info %(test -s /usr/share/info/info.info* && echo 0 
|| echo 1)}
@@ -433,6 +434,7 @@
 %patch -P55 -p1
 %patch -P56 -p1
 %patch -P57 -p1
+%patch -P58 -p1
 %patch -P1  -p0 -b .xauth
 %if %{with memmmap}
 %patch -P2  -p0 -b .glibc

++++++ bsc1282390.patch ++++++
>From abc802ee2eb0b1663349ddf22a461f8e54a383fb Mon Sep 17 00:00:00 2001
From: Stefan Monnier <[email protected]>
Date: Mon, 14 Sep 2026 11:30:39 +0100
Subject: [PATCH] flymake.el: Generalize trusted-content-p check to all
 backends

Minimal safe backport of this change:

    Author:     Stefan Monnier <[email protected]>
    AuthorDate: Fri Sep 11 21:48:55 2026 -0400

      flymake.el: Generalize trusted-content-p check to all backends

      Rather than have each and every backend check
      'trusted-content-p' if it feels necessary, implement the check
      once and forall in flymake.el and provide a wat for backends to
      skip that test, so we replace an "opt-in" with an "opt-out"
      that's a bit more secure by design.

      * lisp/progmodes/elisp-mode.el (elisp-flymake-byte-compile):
      Move 'trusted-content-p' to flymake.el.
      * lisp/progmodes/flymake.el (flymake--run-backend):
      Move 'trusted-content-p' from elisp-mode.el.

      * lisp/progmodes/eglot.el (eglot-flymake-backend): Mark as safe.

* lisp/progmodes/flymake.el (flymake--run-backend): Copy
trusted-content-p check from elisp-mode.el.  Do not merge to
master.
---
 lisp/progmodes/flymake.el |    9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

--- a/lisp/progmodes/flymake.el
+++ b/lisp/progmodes/flymake.el 2026-09-24 09:25:30.062549983 +0000
@@ -1271,8 +1271,13 @@ with a report function."
             (flymake--state-disabled state) nil
             (flymake--state-reported-p state) nil))
     (condition-case-unless-debug err
-        (apply backend (flymake-make-report-fn backend run-token)
-               args)
+        (if (or (trusted-content-p) (function-get backend 
'flymake-always-safe))
+            (apply backend (flymake-make-report-fn backend run-token)
+                   args)
+          (message "Disabling %S in %s (untrusted content)"
+                   backend (buffer-name))
+          (user-error "Disabling %S in %s (untrusted content)"
+                      backend (buffer-name)))
       (error
        (flymake--disable-backend backend err)))))
 
--- a/test/lisp/progmodes/flymake-tests.el
+++ b/test/lisp/progmodes/flymake-tests.el      2026-09-24 10:50:17.188047553 
+0000
@@ -71,6 +71,7 @@ SEVERITY-PREDICATE is used to setup
          (warning-minimum-log-level :error))
     (unwind-protect
         (with-current-buffer buffer
+          (setq-local trusted-content :all)
           (save-excursion
             (when sev-pred-supplied-p
               (setq-local flymake-proc-diagnostic-type-pred 
severity-predicate))
@@ -236,6 +237,7 @@ SEVERITY-PREDICATE is used to setup
   "Test many different kinds of backends."
   (let ((debug-on-error nil))
   (with-temp-buffer
+    (setq-local trusted-content :all)
     (cl-letf
         (((symbol-function 'error-backend)
           (lambda (report-fn)
@@ -318,6 +320,7 @@ SEVERITY-PREDICATE is used to setup
 (ert-deftest recurrent-backend ()
   "Test a backend that calls REPORT-FN multiple times."
   (with-temp-buffer
+    (setq-local trusted-content :all)
     (let (tick)
       (cl-letf
           (((symbol-function 'eager-backend)

Reply via email to