CVE-2026-71391

EUVD-2026-55260
GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_simple_glyph() and sfnt_vary_compound_glyph() uses a strict greater-than comparison instead of greater-than-or-equal, allowing a crafted TrueType variable font to bypass the check and trigger a heap-based out-of-bounds read via memcpy. An attacker can deliver a malicious font file via email, EWW (Emacs Web Wowser), or documents with custom faces, causing Emacs to load it. This exposes heap memory contents which can be later used to defeat ASLR.


This issue was fixed in commit 95ab9ef627b212d74d321c5bbb5b56a1be7b9fbe
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
CERT-PLCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 43.09%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
gnuemacs
𝑥
≤ 30.2
CNA
Debian logo
Debian Releases
Debian Product
Codename
emacs
bookworm
1:28.2+1-15+deb12u4
fixed
bookworm (security)
1:28.2+1-15+deb12u4
fixed
forky
1:30.2+1-11
fixed
sid
1:30.2+1-11
fixed
trixie
1:30.1+1-6+deb13u1
fixed
trixie (security)
1:30.1+1-6+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
emacs
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xemacs21
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
xemacs21-packages
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
emacs24
jammy
dne
noble
dne
resolute
dne
xenial
needs-triage
emacs25
bionic
needs-triage
jammy
dne
noble
dne
resolute
dne