CVE-2026-71392: CWE-190 Integer Overflow or Wraparound in GNU Emacs
GNU Emacs for Android contains an integer overflow vulnerability in the sfnt_read_cmap_format_12() function when processing crafted TrueType font files. This overflow occurs due to an unguarded addition in a memory allocation call on 32-bit builds, leading to a heap buffer overflow. An attacker can exploit this by delivering a malicious font file through email, the Emacs Web Wowser (EWW), or documents with custom faces, potentially causing heap corruption and code execution. The issue has been fixed in a specific commit.
AI Analysis
Technical Summary
The vulnerability in GNU Emacs for Android (CVE-2026-71392) is an integer overflow in the sfnt_read_cmap_format_12() function within src/sfnt.c. On 32-bit builds, an unguarded addition in the xmalloc call wraps around, causing a heap buffer overflow write when processing a malicious TrueType font file. This can be triggered by an attacker delivering a crafted font file via email, EWW, or documents with custom faces, leading to heap memory corruption and possible code execution. The issue was resolved in commit c4e20777c26548722a37b03db93243e83a0d6188.
Potential Impact
Successful exploitation can result in heap memory corruption and potentially allow remote code execution on affected 32-bit GNU Emacs for Android systems. The attack vector includes delivery of malicious font files through common user-facing channels such as email and web browsing within Emacs. The CVSS 4.0 base score is 5.3, indicating a medium severity vulnerability with network attack vector, no privileges required, and user interaction needed.
Mitigation Recommendations
A fix for this vulnerability is available as it was resolved in commit c4e20777c26548722a37b03db93243e83a0d6188. Users should update GNU Emacs for Android to a version that includes this commit. Since no official patch version or advisory is provided here, users should consult the GNU Emacs project repository or official channels to obtain the fixed version. No alternative mitigations or workarounds are indicated.
CVE-2026-71392: CWE-190 Integer Overflow or Wraparound in GNU Emacs
Description
GNU Emacs for Android contains an integer overflow vulnerability in the sfnt_read_cmap_format_12() function when processing crafted TrueType font files. This overflow occurs due to an unguarded addition in a memory allocation call on 32-bit builds, leading to a heap buffer overflow. An attacker can exploit this by delivering a malicious font file through email, the Emacs Web Wowser (EWW), or documents with custom faces, potentially causing heap corruption and code execution. The issue has been fixed in a specific commit.
CVSS v4.0
Score 5.3medium
Affected software
GNU
Emacs
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in GNU Emacs for Android (CVE-2026-71392) is an integer overflow in the sfnt_read_cmap_format_12() function within src/sfnt.c. On 32-bit builds, an unguarded addition in the xmalloc call wraps around, causing a heap buffer overflow write when processing a malicious TrueType font file. This can be triggered by an attacker delivering a crafted font file via email, EWW, or documents with custom faces, leading to heap memory corruption and possible code execution. The issue was resolved in commit c4e20777c26548722a37b03db93243e83a0d6188.
Potential Impact
Successful exploitation can result in heap memory corruption and potentially allow remote code execution on affected 32-bit GNU Emacs for Android systems. The attack vector includes delivery of malicious font files through common user-facing channels such as email and web browsing within Emacs. The CVSS 4.0 base score is 5.3, indicating a medium severity vulnerability with network attack vector, no privileges required, and user interaction needed.
Mitigation Recommendations
A fix for this vulnerability is available as it was resolved in commit c4e20777c26548722a37b03db93243e83a0d6188. Users should update GNU Emacs for Android to a version that includes this commit. Since no official patch version or advisory is provided here, users should consult the GNU Emacs project repository or official channels to obtain the fixed version. No alternative mitigations or workarounds are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERT-PL
- Date Reserved
- 2026-08-06T09:25:32.311Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a79aaecbf8831d53985a8e5
Added to database: 08/10/2026, 10:41:48 UTC
Last enriched: 08/17/2026, 15:38:25 UTC
Last updated: 09/24/2026, 01:47:44 UTC
Views: 58
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.