CVE-2026-71393

EUVD-2026-55258
GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a 32-bit length value from a TrueType font file without overflow checking. On 32-bit targets, a crafted font causes the calculation to wrap, resulting in an undersized heap allocation. A subsequent read() call writes beyond the buffer, causing a heap buffer overflow. An attacker can deliver a malicious font file via email, EWW (Emacs Web Wowser), or documents with custom faces, causing Emacs to load it. This can lead to heap memory corruption and potential code execution.




This issue was fixed in commit d51a4722316efe0960994d371e1859099894d1ca
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
CERT-PLCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 49.98%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
gnuemacs
𝑥
≤ 30.2
CNA
Debian logo
Debian Releases
Debian Product
Codename
emacs
bookworm
1:28.2+1-15+deb12u4
fixed
bookworm (security)
1:28.2+1-15+deb12u4
fixed
forky
1:30.2+1-11
fixed
sid
1:30.2+1-11
fixed
trixie
1:30.1+1-6+deb13u1
fixed
trixie (security)
1:30.1+1-6+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
emacs
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xemacs21
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
xemacs21-packages
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
emacs24
jammy
dne
noble
dne
resolute
dne
xenial
needs-triage
emacs25
bionic
needs-triage
jammy
dne
noble
dne
resolute
dne