CVE-2026-71392

EUVD-2026-55259
GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueType font file, an unguarded addition in the xmalloc allocation call wraps around on 32-bit builds, causing a heap buffer overflow write. An attacker can deliver a malicious font file via email, EWW (Emacs Web Wowser), or documents with custom faces, causing Emacs to load it. This results in heap memory corruption that can lead to code execution.


This issue was fixed in commit c4e20777c26548722a37b03db93243e83a0d6188
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
CERT-PLCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 49.98%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
gnuemacs
𝑥
≤ 30.2
CNA
Debian logo
Debian Releases
Debian Product
Codename
emacs
bookworm
1:28.2+1-15+deb12u4
fixed
bookworm (security)
1:28.2+1-15+deb12u4
fixed
forky
1:30.2+1-11
fixed
sid
1:30.2+1-11
fixed
trixie
1:30.1+1-6+deb13u1
fixed
trixie (security)
1:30.1+1-6+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
emacs
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xemacs21
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
xemacs21-packages
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
emacs24
jammy
dne
noble
dne
resolute
dne
xenial
needs-triage
emacs25
bionic
needs-triage
jammy
dne
noble
dne
resolute
dne