This mitigates a vulnerability that allowed a specially
crafted file to trigger execution of attacker-controlled
arbitrary Emacs Lisp code immediately when the file is
visited in Emacs (before the file's malicious contents are
even displayed). See demonstration in bug#80574.
* lisp/progmodes/cc-fonts.el (c-compose-keywords-list):
* lisp/vc/vc-hooks.el (vc-find-backend-function):
Nullify 'read-symbol-shorthands' around risky 'intern' calls.
Do not merge to master.
Orign: upstream, commit:
8466eb44991707d128110bdc549fad14c8e1d61e
Added-by: Rob Browning <rlb@defaultvalue.org>
Bug: https://debbugs.gnu.org/80574
README-Debian: Opening a file should have less risk of executing arbirary code
The vulnerability that has been mitigated could allow a specially
crafted file to trigger execution of attacker-controlled arbitrary
Emacs Lisp code immediately when the file is visited in Emacs. The
broader issue is described here: https://debbugs.gnu.org/80574
Gbp-Pq: Name 0026-Mitigate-arbitrary-code-execution-vulnerability.patch
(let* ((doc-keywords (c-get-doc-comment-style))
(list (nconc (c--mapcan
(lambda (doc-style)
- (let ((sym (intern
- (concat (symbol-name doc-style)
- "-font-lock-keywords"))))
+ (let ((sym
+ ;; Guard `intern' from potentially
+ ;; malicious shorthands.
+ (let (read-symbol-shorthands)
+ (intern
+ (concat (symbol-name doc-style)
+ "-font-lock-keywords")))))
(cond ((fboundp sym)
(funcall sym))
((boundp sym)
"Return BACKEND-specific implementation of FUN.
If there is no such implementation, return the default implementation;
if that doesn't exist either, return nil."
- (let ((f (vc-make-backend-sym backend fun)))
+ ;; Nullify `read-symbol-shorthands' to guard the `intern' calls below
+ ;; and in `vc-make-backend-sym' from potentially malicious shorthands.
+ (let* ((read-symbol-shorthands nil)
+ (f (vc-make-backend-sym backend fun)))
(if (fboundp f) f
;; Load vc-BACKEND.el if needed.
(require (intern (concat "vc-" (downcase (symbol-name backend)))))