Mitigate arbitrary code execution vulnerability
authorEshel Yaron <me@eshelyaron.com>
Wed, 5 Aug 2026 17:58:32 +0000 (19:58 +0200)
committerRob Browning <rlb@defaultvalue.org>
Fri, 21 Aug 2026 17:24:00 +0000 (12:24 -0500)
commit9e5c559078fa0f66e5019e4b24b1717cb3de8410
tree30ed6f7a0a13e39370596d4b23cf43c17f03ef0b
parent61b4a2faa7e5856bc3b72672002b58c3bdde85c8
Mitigate arbitrary code execution vulnerability

This mitigates a vulnerability that allowed a specially
crafted file to trigger execution of attacker-controlled
arbitrary Emacs Lisp code immediately when the file is
visited in Emacs (before the file's malicious contents are
even displayed).  See demonstration in bug#80574.

* lisp/progmodes/cc-fonts.el (c-compose-keywords-list):
* lisp/vc/vc-hooks.el (vc-find-backend-function):
Nullify 'read-symbol-shorthands' around risky 'intern' calls.
Do not merge to master.

Orign: upstream, commit: 8466eb44991707d128110bdc549fad14c8e1d61e
Added-by: Rob Browning <rlb@defaultvalue.org>
Bug: https://debbugs.gnu.org/80574
README-Debian: Opening a file should have less risk of executing arbirary code
 The vulnerability that has been mitigated could allow a specially
 crafted file to trigger execution of attacker-controlled arbitrary
 Emacs Lisp code immediately when the file is visited in Emacs.  The
 broader issue is described here: https://debbugs.gnu.org/80574

Gbp-Pq: Name 0026-Mitigate-arbitrary-code-execution-vulnerability.patch
lisp/progmodes/cc-fonts.el
lisp/vc/vc-hooks.el