A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a denial of service (DoS) or potentially information disclosure.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade emacs | Aug 27, 2026 | Aug 27, 2026 |
| Freebsd | — | Upgrade emacs-noxUpgrade emacs-cannaUpgrade emacs-devel-noxUpgrade emacsUpgrade emacs-develUpgrade emacs-wayland | Jul 7, 2026 | Jul 6, 2026 |
| Ubuntu | — | Upgrade emacs (Ubuntu Pro) | Sep 29, 2026 | Sep 28, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub