Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-84638.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-84638
Upstream
  • CVE-2026-6861
Published
2026-04-22T14:17:07Z
Modified
2026-09-07T05:28:29Z
Summary
CVE-2026-6861 affecting package emacs for versions less than 29.4-4
Details

A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a denial of service (DoS) or potentially information disclosure.

References

Affected packages

Azure Linux:3 / emacs

Package

Name
emacs
Purl
pkg:rpm/azure-linux/emacs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
29.4-4

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-84638.json"