Emacs incomplete CVE-2024-53920 fix and separate file-open flaw get CVEs
CVE-2026-96442 covers an incomplete Emacs fix for CVE-2024-53920; separate CVE-2026-96269 involves opening an arbitrary file.
From 2026-09-21 to 2026-09-23, oss-security discussion concerned an incomplete fix for GNU Emacs arbitrary code execution vulnerability CVE-2024-53920. Tomas Hoger first asked whether GitHub's CNA would cover a follow-up identifier because the issue involves an open source project, offering Red Hat as the fallback. On 2026-09-22 Bas Alberts asked Red Hat to assign a CVE, citing earlier batch item CVE-2026-79992 as the model, without technical details, patch status, or evidence of exploitation. On 2026-09-23 Hoger reported that CVE-2026-96442 had been assigned to that incomplete fix, still described as arbitrary code execution, and gave no affected versions, patch, or in-the-wild use. A separate same-day note says CVE-2026-96269 was assigned on 2026-09-22 to a previously discussed GNU Emacs issue triggered by opening an arbitrary file, again without versions, impact details, exploit information, or patch guidance. The posts do not conflict on the assignment timeline, but they do not identify the assigning CNA or say whether the two new CVEs describe the same flaw.
- On 2026-09-21 Tomas Hoger asked oss-security whether GitHub or Red Hat would assign a CVE for an incomplete fix of Emacs arbitrary code execution flaw CVE-2024-53920.
- Hoger said GitHub's CNA scope may cover the issue because it involves an open source project, and offered Red Hat's CNA if GitHub does not assign it.
- On 2026-09-22 Bas Alberts asked Red Hat to assign a CVE, citing earlier batch item CVE-2026-79992 as the model; that reply gave no technical details, patch status, or exploitation evidence.
- On 2026-09-23 Hoger said CVE-2026-96442 was assigned for the incomplete fix of CVE-2024-53920, with the impact still described as arbitrary code execution.
- The CVE-2026-96442 note includes no affected versions, patch, or evidence of in-the-wild use.
- A separate 2026-09-23 oss-security note says CVE-2026-96269 was assigned on 2026-09-22 to a GNU Emacs flaw triggered by opening an arbitrary file, with no versions, impact details, exploit information, or patch guidance.
- The reports do not name the assigning CNA or state whether CVE-2026-96442 and CVE-2026-96269 are the same issue.
Coverage timelineoldest first · each row is one article
- · 5d agoRe: Emacs arbitrary code execution: incomplete fix for CVE-2024-53920
oss-security· 12
Tomas Hoger asks oss-security whether GitHub or Red Hat will assign a CVE for Emacs's incomplete fix of arbitrary code execution bug CVE-2024-53920.
- · 4d agoRe: Emacs arbitrary code execution: incomplete fix for CVE-2024-53920
oss-security· 42
Bas Alberts asks Red Hat to assign a CVE for an incomplete Emacs fix of CVE-2024-53920.
- · 3d ago
Vulnerabilities in this storyAll →
- CVE-2024-539207.8<1%In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can…published · gnu emacs
- CVE-2026-799927.8<1%Shell argument injection in GNU Emacs TRAMP (incomplete fix of CVE-2024-53920)