Mention CVE-2025-1244 in NEWS
authorStefan Kangas <stefankangas@gmail.com>
Sun, 23 Feb 2025 15:25:37 +0000 (16:25 +0100)
committerStefan Kangas <stefankangas@gmail.com>
Sun, 23 Feb 2025 15:31:03 +0000 (16:31 +0100)
* etc/NEWS: Document CVE-2025-1244.

For anyone looking to backport this, the fix is in commit
820f0793f0b46448928905552726c1f1b999062f.

etc/NEWS

index ec14e44785909c2e460050fde3f48ea508aaa1c4..1a68e70ce48393fc92ce093e18e180ef23a8a584 100644 (file)
--- a/etc/NEWS
+++ b/etc/NEWS
@@ -184,6 +184,9 @@ expectations.
 \f
 * Changes in Emacs 30.1
 
+** Fix shell injection vulnerability in man.el (CVE-2025-1244).
+We urge all users to upgrade immediately.
+
 ** New user option 'trusted-content' to allow potentially dangerous features.
 This option lists those files and directories whose content Emacs should
 consider as sufficiently trusted to run any part of the code contained