CVE-2026-71393: CWE-190 Integer Overflow or Wraparound in GNU Emacs
GNU Emacs for Android contains an integer overflow vulnerability in the sfnt_read_name_table() function within src/sfnt.c. This flaw arises from improper handling of a 32-bit length value from TrueType font files, leading to an undersized heap allocation on 32-bit systems. Loading a crafted font file can cause a heap buffer overflow, potentially resulting in heap memory corruption and code execution. The vulnerability can be triggered by delivering a malicious font via email, the Emacs Web Wowser (EWW), or documents with custom faces. A fix has been implemented in commit d51a4722316efe0960994d371e1859099894d1ca.
AI Analysis
Technical Summary
The vulnerability in GNU Emacs for Android is an integer overflow in the sfnt_read_name_table() function, which calculates an allocation size from a 32-bit length value in a TrueType font file without checking for overflow. On 32-bit targets, this causes the allocation size calculation to wrap around, resulting in an undersized heap buffer. A subsequent read() operation writes beyond this buffer, causing a heap buffer overflow. This can be exploited by an attacker who delivers a malicious font file through email, EWW, or documents with custom faces, potentially leading to heap memory corruption and code execution. The issue was fixed in a specific commit identified as d51a4722316efe0960994d371e1859099894d1ca.
Potential Impact
Successful exploitation of this vulnerability can lead to heap memory corruption and potentially arbitrary code execution on affected systems running GNU Emacs for Android. The attack vector includes delivering a malicious TrueType font file via email, the Emacs Web Wowser, or documents with custom faces that cause Emacs to load the crafted font. The vulnerability affects 32-bit targets due to integer overflow in allocation size calculation.
Mitigation Recommendations
A fix for this vulnerability has been implemented in commit d51a4722316efe0960994d371e1859099894d1ca. Users and administrators should apply this update to mitigate the risk. Since no official patch link or advisory is provided, verify the presence of this commit in your Emacs build or update to a version including this fix. No additional vendor advisory states otherwise.
CVE-2026-71393: CWE-190 Integer Overflow or Wraparound in GNU Emacs
Description
GNU Emacs for Android contains an integer overflow vulnerability in the sfnt_read_name_table() function within src/sfnt.c. This flaw arises from improper handling of a 32-bit length value from TrueType font files, leading to an undersized heap allocation on 32-bit systems. Loading a crafted font file can cause a heap buffer overflow, potentially resulting in heap memory corruption and code execution. The vulnerability can be triggered by delivering a malicious font via email, the Emacs Web Wowser (EWW), or documents with custom faces. A fix has been implemented in commit d51a4722316efe0960994d371e1859099894d1ca.
CVSS v4.0
Score 5.3medium
Affected software
GNU
Emacs
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in GNU Emacs for Android is an integer overflow in the sfnt_read_name_table() function, which calculates an allocation size from a 32-bit length value in a TrueType font file without checking for overflow. On 32-bit targets, this causes the allocation size calculation to wrap around, resulting in an undersized heap buffer. A subsequent read() operation writes beyond this buffer, causing a heap buffer overflow. This can be exploited by an attacker who delivers a malicious font file through email, EWW, or documents with custom faces, potentially leading to heap memory corruption and code execution. The issue was fixed in a specific commit identified as d51a4722316efe0960994d371e1859099894d1ca.
Potential Impact
Successful exploitation of this vulnerability can lead to heap memory corruption and potentially arbitrary code execution on affected systems running GNU Emacs for Android. The attack vector includes delivering a malicious TrueType font file via email, the Emacs Web Wowser, or documents with custom faces that cause Emacs to load the crafted font. The vulnerability affects 32-bit targets due to integer overflow in allocation size calculation.
Mitigation Recommendations
A fix for this vulnerability has been implemented in commit d51a4722316efe0960994d371e1859099894d1ca. Users and administrators should apply this update to mitigate the risk. Since no official patch link or advisory is provided, verify the presence of this commit in your Emacs build or update to a version including this fix. No additional vendor advisory states otherwise.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERT-PL
- Date Reserved
- 2026-08-06T09:25:32.311Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a79aaecbf8831d53985a8eb
Added to database: 08/10/2026, 10:41:48 UTC
Last enriched: 08/17/2026, 15:38:39 UTC
Last updated: 09/24/2026, 13:47:48 UTC
Views: 53
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.