CVE-2026-71393

Source
https://cve.org/CVERecord?id=CVE-2026-71393
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71393.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-71393
Downstream
Published
2026-08-10T10:22:37Z
Modified
2026-09-10T11:30:51Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N CVSS Calculator
Summary
Heap Buffer Overflow in GNU Emacs for Android
Details

GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a 32-bit length value from a TrueType font file without overflow checking. On 32-bit targets, a crafted font causes the calculation to wrap, resulting in an undersized heap allocation. A subsequent read() call writes beyond the buffer, causing a heap buffer overflow. An attacker can deliver a malicious font file via email, EWW (Emacs Web Wowser), or documents with custom faces, causing Emacs to load it. This can lead to heap memory corruption and potential code execution.

This issue was fixed in commit d51a4722316efe0960994d371e1859099894d1ca

Database specific
{
    "cna_assigner": "CERT-PL",
    "cwe_ids": [
        "CWE-190"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71393.json"
}
References

Affected packages

Git / cgit.git.savannah.gnu.org/cgit/emacs.git

Affected ranges

Type
GIT
Repo
https://cgit.git.savannah.gnu.org/cgit/emacs.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
d51a4722316efe0960994d371e1859099894d1ca
Database specific
Show details
{
    "source": "REFERENCES"
}
Type
GIT
Repo
https://https.git.savannah.gnu.org/git/emacs.git/
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
636f166cfc86aa90d63f592fd99f3fdd9ef95ebd
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "30.2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

emacs-19.*
emacs-19.34
emacs-20.*
emacs-20.1
emacs-20.2
emacs-20.3
emacs-20.4
emacs-30.*
emacs-30.0.90
emacs-30.0.91
emacs-30.0.92
emacs-30.0.93
emacs-30.1
emacs-30.1-rc1
emacs-30.1.90
emacs-30.2
emacs-pretest-21.*
emacs-pretest-21.0.100
emacs-pretest-21.0.101
emacs-pretest-21.0.102
emacs-pretest-21.0.103
emacs-pretest-21.0.104
emacs-pretest-21.0.105
emacs-pretest-21.0.106
emacs-pretest-21.0.90
emacs-pretest-21.0.91
emacs-pretest-21.0.92
emacs-pretest-21.0.93
emacs-pretest-21.0.95
emacs-pretest-21.0.96
emacs-pretest-21.0.97
emacs-pretest-21.0.98
emacs-pretest-21.0.99
emacs-pretest-22.*
emacs-pretest-22.0.90
emacs-pretest-22.0.91
emacs-pretest-22.0.92
emacs-pretest-22.0.93
emacs-pretest-22.0.94
emacs-pretest-22.0.95
emacs-pretest-22.0.96
emacs-pretest-22.0.97
emacs-pretest-22.0.98
emacs-pretest-23.*
emacs-pretest-23.0.90
emacs-pretest-23.0.91
emacs-pretest-23.0.92
emacs-pretest-23.0.93
emacs-pretest-23.0.94
emacs-pretest-23.0.95
emacs-pretest-23.1.90
emacs-pretest-23.1.91
emacs-pretest-23.1.92
mh-e-8.*
mh-e-8.0
mh-e-8.0.1
mh-e-8.0.2
mh-e-8.0.3
mh-e-8.1
mh-e-8.2
mh-e-doc-8.*
mh-e-doc-8.0
mh-e-doc-8.0.1
mh-e-doc-8.0.3
mh-e-doc-8.1
mh-e-doc-8.2
Other
ttn-vms-21-2-B4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71393.json"