Source: emacs
Version: 1:30.2+1-11
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi

As reported in
https://www.openwall.com/lists/oss-security/2026/09/14/1, the fix for
CVE-2024-53920 was incomplete:
| Bas Alberts of the GitHub Security Lab discovered that the fix for
| CVE-2024-53920, an arbitrary code execution flaw in Emacs, was
| incomplete.  Viewing or editing untrusted text files in modes other than
| Emacs Lisp mode can also permit arbitrary code execution.

Regards,
Salvatore

Reply via email to