Executive brief
GNU Emacs is a widely-used text editor and computing environment available on multiple platforms including Android. An attacker can deliver a malicious font file—via email, web content (EWW), or documents with custom formatting—that causes Emacs to load it. The vulnerability allows the font parser to read uninitialized heap memory, potentially exposing sensitive data or causing crashes; on 32-bit systems this could lead to arbitrary memory access and further compromise.
Technical details
The vulnerability exists in the sfnt_read_table_directory() function in src/sfnt.c, where an incorrect comparison variable in the read-length check allows improper validation of TrueType font table headers. A crafted font file claiming more table directory entries than actually present causes the parser to return a struct containing uninitialized heap memory. The attack is network-reachable; an attacker simply needs to trick a user into opening a malicious font-bearing file or visiting a site serving one. The flaw leads to use of uninitialized heap data in subsequent table lookups, resulting in information disclosure (heap leakage to defeat ASLR), crashes (denial of service), or on 32-bit targets, arbitrary memory access. The fix is available after commit 7621ee1d01229d50e5c0cddea6bf0b01095a62cf.
Affected products
- GNU Emacs through 30.2
Timeline
- 2026-08-10: disclosed
- 2026: patched: Fixed after commit 7621ee1d01229d50e5c0cddea6bf0b01095a62cf