CVE-2026-71392

Source
https://cve.org/CVERecord?id=CVE-2026-71392
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71392.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-71392
Downstream
Published
2026-08-10T10:22:26Z
Modified
2026-08-23T03:53:40Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N CVSS Calculator
Summary
Integer Overflow in GNU Emacs for Android
Details

GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueType font file, an unguarded addition in the xmalloc allocation call wraps around on 32-bit builds, causing a heap buffer overflow write. An attacker can deliver a malicious font file via email, EWW (Emacs Web Wowser), or documents with custom faces, causing Emacs to load it. This results in heap memory corruption that can lead to code execution.

This issue was fixed in commit c4e20777c26548722a37b03db93243e83a0d6188

Database specific
{
    "cna_assigner": "CERT-PL",
    "cwe_ids": [
        "CWE-190"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71392.json"
}
References

Affected packages

Git / cgit.git.savannah.gnu.org/cgit/emacs.git

Affected ranges

Type
GIT
Repo
https://cgit.git.savannah.gnu.org/cgit/emacs.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
c4e20777c26548722a37b03db93243e83a0d6188
Database specific
Show details
{
    "source": "REFERENCES"
}
Type
GIT
Repo
https://https.git.savannah.gnu.org/git/emacs.git/
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
636f166cfc86aa90d63f592fd99f3fdd9ef95ebd
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "30.2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

emacs-19.*
emacs-19.34
emacs-20.*
emacs-20.1
emacs-20.2
emacs-20.3
emacs-20.4
emacs-30.*
emacs-30.0.90
emacs-30.0.91
emacs-30.0.92
emacs-30.0.93
emacs-30.1
emacs-30.1-rc1
emacs-30.1.90
emacs-30.2
emacs-pretest-21.*
emacs-pretest-21.0.100
emacs-pretest-21.0.101
emacs-pretest-21.0.102
emacs-pretest-21.0.103
emacs-pretest-21.0.104
emacs-pretest-21.0.105
emacs-pretest-21.0.106
emacs-pretest-21.0.90
emacs-pretest-21.0.91
emacs-pretest-21.0.92
emacs-pretest-21.0.93
emacs-pretest-21.0.95
emacs-pretest-21.0.96
emacs-pretest-21.0.97
emacs-pretest-21.0.98
emacs-pretest-21.0.99
emacs-pretest-22.*
emacs-pretest-22.0.90
emacs-pretest-22.0.91
emacs-pretest-22.0.92
emacs-pretest-22.0.93
emacs-pretest-22.0.94
emacs-pretest-22.0.95
emacs-pretest-22.0.96
emacs-pretest-22.0.97
emacs-pretest-22.0.98
emacs-pretest-23.*
emacs-pretest-23.0.90
emacs-pretest-23.0.91
emacs-pretest-23.0.92
emacs-pretest-23.0.93
emacs-pretest-23.0.94
emacs-pretest-23.0.95
emacs-pretest-23.1.90
emacs-pretest-23.1.91
emacs-pretest-23.1.92
mh-e-8.*
mh-e-8.0
mh-e-8.0.1
mh-e-8.0.2
mh-e-8.0.3
mh-e-8.1
mh-e-8.2
mh-e-doc-8.*
mh-e-doc-8.0
mh-e-doc-8.0.1
mh-e-doc-8.0.3
mh-e-doc-8.1
mh-e-doc-8.2
Other
ttn-vms-21-2-B4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71392.json"