Re: Emacs arbitrary code execution: incomplete fix for CVE-2024-53920
Bas Alberts asks Red Hat to assign a CVE for an incomplete Emacs fix of CVE-2024-53920.
Bas Alberts asked on oss-security for Red Hat to assign a CVE, in line with earlier batch item CVE-2026-79992, for an incomplete fix of Emacs arbitrary code execution flaw CVE-2024-53920. The short reply gives no technical details, patch status, or evidence of exploitation.
- Incomplete fix reported for Emacs arbitrary code execution CVE-2024-53920.
- Bas Alberts asks Red Hat to assign a new CVE.
- He cites CVE-2026-79992 as the model for assignment.
Vulnerabilities mentionedAll →
- CVE-2024-539207.8<1%In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can…published · gnu emacs
- CVE-2026-799927.8<1%Shell argument injection in GNU Emacs TRAMP (incomplete fix of CVE-2024-53920)
Posted by Bas Alberts on Sep 22 If Red Hat could provide the CVE in line with the previous finding of this report batch (CVE-2026-79992) that would be greatly appreciated. Thanks, Bas
This source does not provide full text. Read it at seclists.org.