CVE-2026-71392: CWE-190 Integer Overflow or Wraparound in GNU Emacs
GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueType font file, an unguarded addition in the xmalloc allocation call wraps around on 32-bit builds, causing a heap buffer overflow write. An attacker can deliver a malicious font file via email, EWW (Emacs Web Wowser), or documents with custom faces, causing Emacs to load it. This results in heap memory corruption that can lead to code execution. This issue was fixed in commit c4e20777c26548722a37b03db93243e83a0d6188
AI Analysis
Technical Summary
CVE-2026-71392 is an integer overflow vulnerability (CWE-190) in GNU Emacs for Android's sfnt_read_cmap_format_12() function located in src/sfnt.c. On 32-bit builds, an unguarded addition in the xmalloc allocation call wraps around, causing a heap buffer overflow write when processing a crafted TrueType font file. An attacker can exploit this by delivering a malicious font file through email, EWW, or documents with custom faces, causing Emacs to load the file and leading to heap memory corruption and potential code execution. The vulnerability was fixed in commit c4e20777c26548722a37b03db93243e83a0d6188.
Potential Impact
Successful exploitation results in heap memory corruption that can lead to arbitrary code execution. The vulnerability is remotely exploitable without privileges or user interaction beyond opening a malicious font file in Emacs. The CVSS 4.0 base score is 5.3 (medium severity), reflecting network attack vector, low attack complexity, no privileges required, user interaction required, and limited impact on confidentiality and integrity.
Mitigation Recommendations
A fix for this vulnerability is available and was implemented in commit c4e20777c26548722a37b03db93243e83a0d6188. Users should update GNU Emacs for Android to a version that includes this commit. Patch status is not explicitly confirmed in vendor advisories; therefore, verify the presence of this fix in your Emacs build. Until patched, avoid opening untrusted TrueType font files via email, EWW, or documents with custom faces.
CVE-2026-71392: CWE-190 Integer Overflow or Wraparound in GNU Emacs
Description
GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueType font file, an unguarded addition in the xmalloc allocation call wraps around on 32-bit builds, causing a heap buffer overflow write. An attacker can deliver a malicious font file via email, EWW (Emacs Web Wowser), or documents with custom faces, causing Emacs to load it. This results in heap memory corruption that can lead to code execution. This issue was fixed in commit c4e20777c26548722a37b03db93243e83a0d6188
CVSS v4.0
Score 5.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-71392 is an integer overflow vulnerability (CWE-190) in GNU Emacs for Android's sfnt_read_cmap_format_12() function located in src/sfnt.c. On 32-bit builds, an unguarded addition in the xmalloc allocation call wraps around, causing a heap buffer overflow write when processing a crafted TrueType font file. An attacker can exploit this by delivering a malicious font file through email, EWW, or documents with custom faces, causing Emacs to load the file and leading to heap memory corruption and potential code execution. The vulnerability was fixed in commit c4e20777c26548722a37b03db93243e83a0d6188.
Potential Impact
Successful exploitation results in heap memory corruption that can lead to arbitrary code execution. The vulnerability is remotely exploitable without privileges or user interaction beyond opening a malicious font file in Emacs. The CVSS 4.0 base score is 5.3 (medium severity), reflecting network attack vector, low attack complexity, no privileges required, user interaction required, and limited impact on confidentiality and integrity.
Mitigation Recommendations
A fix for this vulnerability is available and was implemented in commit c4e20777c26548722a37b03db93243e83a0d6188. Users should update GNU Emacs for Android to a version that includes this commit. Patch status is not explicitly confirmed in vendor advisories; therefore, verify the presence of this fix in your Emacs build. Until patched, avoid opening untrusted TrueType font files via email, EWW, or documents with custom faces.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERT-PL
- Date Reserved
- 2026-08-06T09:25:32.311Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a79aaecbf8831d53985a8e5
Added to database: 08/10/2026, 10:41:48 UTC
Last enriched: 08/10/2026, 11:03:06 UTC
Last updated: 08/10/2026, 17:57:00 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.