openSUSE-SU-2026:21711-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21711-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21711-1
Upstream
CVE (2)
Related
Published
2026-08-31T11:49:39Z
Modified
2026-09-02T18:23:08Z
Summary
Security update for emacs
Details

This update for emacs fixes the following issues:

Security issues fixed:

  • Arbitrary code execution when opening a specially crafted file (bsc#1275941).
  • CVE-2026-77219: integer overflow in the PBM/PPM/PGM image loader leads to heap memory content leaks when a crafted image with large dimensions and an elevated max color index is processed (bsc#1276264).
  • CVE-2026-79992: improper argument sanitization in TRAMP leads to arbitrary code execution via crafted filenames (bsc#1275927).

Other updates and bugfixes:

  • Fix memory leak in wayland port (bsc#1271643).
References

Affected packages

openSUSE:Leap 16.0 / emacs

Package

Name
emacs
Purl
pkg:rpm/opensuse/emacs&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
30.2-160000.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "emacs":  "30.2-160000.3.1",
            "emacs-el":  "30.2-160000.3.1",
            "emacs-eln":  "30.2-160000.3.1",
            "emacs-games":  "30.2-160000.3.1",
            "emacs-info":  "30.2-160000.3.1",
            "emacs-nox":  "30.2-160000.3.1",
            "emacs-x11":  "30.2-160000.3.1",
            "etags":  "30.2-160000.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21711-1.json"