Integer Overflow Vulnerability in GNU Emacs for Android
CVE-2026-71392
5.3MEDIUM
What is CVE-2026-71392?
GNU Emacs for Android features a significant vulnerability due to an integer overflow in the sfnt_read_cmap_format_12() function located in src/sfnt.c. This flaw arises when processing maliciously crafted TrueType font files, wherein an unguarded addition during the memory allocation process can lead to a heap buffer overflow. This exploitation can be carried out via delivery methods such as email, the Emacs Web Wowser (EWW), or documents containing specially crafted custom faces, allowing an attacker to load a harmful font file into Emacs. The result is memory corruption within the heap, potentially enabling arbitrary code execution.
Affected Version(s)
Emacs Android 0 <= 30.2
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michał Majchrowicz (AFINE Team)
Marcin Wyczechowski (AFINE Team)