🔐 CVE Alert

CVE-2026-71393

UNKNOWN 0.0

Heap Buffer Overflow in GNU Emacs for Android

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a 32-bit length value from a TrueType font file without overflow checking. On 32-bit targets, a crafted font causes the calculation to wrap, resulting in an undersized heap allocation. A subsequent read() call writes beyond the buffer, causing a heap buffer overflow. An attacker can deliver a malicious font file via email, EWW (Emacs Web Wowser), or documents with custom faces, causing Emacs to load it. This can lead to heap memory corruption and potential code execution. This issue was fixed in commit d51a4722316efe0960994d371e1859099894d1ca

CWE CWE-190
Vendor gnu
Product emacs
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for gnu emacs

Be the first to know when new unknown vulnerabilities affecting gnu emacs are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

GNU / Emacs
0 ≤ 30.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/en/posts/2026/08/CVE-2026-71391 gnu.org: https://www.gnu.org/savannah-checkouts/gnu/emacs/emacs.html git.savannah.gnu.org: https://git.savannah.gnu.org/cgit/emacs.git/commit/?id=d51a4722316efe0960994d371e1859099894d1ca

Credits

Michał Majchrowicz (AFINE Team) Marcin Wyczechowski (AFINE Team)