Re: Emacs arbitrary code execution: incomplete fix for CVE-2024-53920
CVE-2026-96442 was assigned for an incomplete Emacs fix of arbitrary code execution CVE-2024-53920.
An oss-security follow-up states that CVE-2026-96442 was assigned for an Emacs arbitrary code execution issue. The flaw is described as an incomplete fix for earlier vulnerability CVE-2024-53920. Tomas Hoger's September 23, 2026 note does not include affected versions, a patch, exploit details, or evidence of in-the-wild use.
- CVE-2026-96442 was assigned for the Emacs issue.
- It is an incomplete fix for CVE-2024-53920.
- The impact is described as arbitrary code execution.
- The post gives no versions, patch, or exploitation evidence.
Vulnerabilities mentionedAll →
- CVE-2024-539207.8<1%In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can…published · gnu emacs
- CVE-2026-964427.8—Arbitrary Code Execution via Flymake in GNU Emacspublished · GNU Emacs
Posted by Tomas Hoger on Sep 23 CVE-2026-96442 was assigned for this issue.
This source does not provide full text. Read it at seclists.org.