Re: Emacs arbitrary code execution: incomplete fix for CVE-2024-53920
Tomas Hoger asks oss-security whether GitHub or Red Hat will assign a CVE for Emacs's incomplete fix of arbitrary code execution bug CVE-2024-53920.
An oss-security mailing list reply by Tomas Hoger raises the question of CVE assignment for an incomplete fix to CVE-2024-53920, an Emacs arbitrary code execution vulnerability. Hoger notes GitHub's CNA scope may cover it since it involves an open source project, and offers that Red Hat can assign the identifier if GitHub does not.
- Incomplete fix reported for Emacs arbitrary code execution flaw CVE-2024-53920
- CVE assignment pending between GitHub and Red Hat CNAs
Vulnerabilities mentionedAll →
- CVE-2024-539207.8<1%In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can…published · gnu emacs
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-53920 | In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can… In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.) |
Posted by Tomas Hoger on Sep 21 Is GitHub going to assign a CVE here? I think GitHub assignment would be ok per this part of the GitHub CNA scope definition: "vulnerabilities affecting open source projects discovered by security researchers at GitHub or Microsoft not covered by another CNA’s scope." If GitHub is not doing assignment, Red Hat can provide it instead.
This source does not provide full text. Read it at seclists.org.