[Git][security-tracker-team/security-tracker][master] Add four new emacs issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 10 20:22:41 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b2ecf5c3 by Salvatore Bonaccorso at 2026-08-10T21:22:04+02:00
Add four new emacs issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -169,13 +169,21 @@ CVE-2026-71577 (A flaw was found in multicluster-global-hub. During a ManagedClu
 CVE-2026-71576 (A flaw was found in multicluster-global-hub. The manager component imp ...)
 	TODO: check
 CVE-2026-71394 (GNU Emacs for Android improperly validates the table header input in s ...)
-	TODO: check
+	- emacs <unfixed>
+	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391
+	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=7621ee1d01229d50e5c0cddea6bf0b01095a62cf
 CVE-2026-71393 (GNU Emacs for Android is vulnerable to an integer overflow in sfnt_rea ...)
-	TODO: check
+	- emacs <unfixed>
+	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391/
+	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=d51a4722316efe0960994d371e1859099894d1ca
 CVE-2026-71392 (GNU Emacs for Android is vulnerable to an integer overflow in the sfnt ...)
-	TODO: check
+	- emacs <unfixed>
+	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391/
+	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=c4e20777c26548722a37b03db93243e83a0d6188
 CVE-2026-71391 (GNU Emacs for Android contains an off-by-one error in the gvar table p ...)
-	TODO: check
+	- emacs <unfixed>
+	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391/
+	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=95ab9ef627b212d74d321c5bbb5b56a1be7b9fbe
 CVE-2026-70622 (tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnera ...)
 	TODO: check
 CVE-2026-6374 (Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2ecf5c3ae0285e7b14bfdb4a66fbc7aa1007a4b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2ecf5c3ae0285e7b14bfdb4a66fbc7aa1007a4b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/96556ac8/attachment.htm>


More information about the debian-security-tracker-commits mailing list