[Git][security-tracker-team/security-tracker][master] One emacs CVE assigned
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 23 08:21:59 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3272544e by Salvatore Bonaccorso at 2026-09-23T09:21:42+02:00
One emacs CVE assigned
- - - - -
2 changed files:
- data/CVE/list
- data/DSA/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -4,8 +4,6 @@ CVE-2026-96272 (ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection v
TODO: check
CVE-2026-96271 (Photoview through 2.4.0 contains an authorization bypass vulnerability ...)
TODO: check
-CVE-2026-96269 (GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon openi ...)
- TODO: check
CVE-2026-96260 (Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7 ...)
TODO: check
CVE-2026-96259 (Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7 ...)
@@ -41277,9 +41275,8 @@ CVE-2026-79992 (A flaw was found in Emacs TRAMP. A local attacker could exploit
- emacs <unfixed> (bug #1145049)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/21/1
NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=f3e7104d05bdb8e32ba13bf75604108ad88536dc
-CVE-2026-XXXX [arbitrary code execution upon opening file]
+CVE-2026-96269 [arbitrary code execution upon opening file]
- emacs 1:30.2+1-11
- [trixie] - emacs 1:30.1+1-6+deb13u1
NOTE: https://www.openwall.com/lists/oss-security/2026/08/20/3
NOTE: https://eshelyaron.com/posts/2026-08-06-emacs-arbitrary-code-execution-returns.html
NOTE: https://debbugs.gnu.org/cgi/bugreport.cgi?bug=80574#227
=====================================
data/DSA/list
=====================================
@@ -122,7 +122,7 @@
{CVE-2026-32105 CVE-2026-32107 CVE-2026-32623 CVE-2026-32624 CVE-2026-33145 CVE-2026-33516 CVE-2026-33689 CVE-2026-35512 CVE-2026-41252 CVE-2026-41521 CVE-2026-42218 CVE-2026-44178 CVE-2026-44978 CVE-2026-54538 CVE-2026-55238 CVE-2026-55639 CVE-2026-55645}
[trixie] - xrdp 0.10.1-3.1+deb13u2
[26 Aug 2026] DSA-6468-1 emacs - security update
- {CVE-2026-6861}
+ {CVE-2026-6861 CVE-2026-96269}
[trixie] - emacs 1:30.1+1-6+deb13u1
[26 Aug 2026] DSA-6467-1 freecad - security update
{CVE-2026-34398 CVE-2026-34399 CVE-2026-34789 CVE-2026-73233 CVE-2026-73234 CVE-2026-73235}
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3272544ed40b6f6193d31e7f99dbe89898014dce
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3272544ed40b6f6193d31e7f99dbe89898014dce
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/16c69fb9/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list