Skip to content

[AutoPR- Security] Patch emacs for CVE-2026-96269, CVE-2026-96442 [HIGH] - #18963

Draft
Azure Linux Security Servicing Account (azurelinux-security) wants to merge 3 commits into
microsoft:fasttrack/3.0from
azurelinux-security:azure-autosec/emacs/3.0/1208673
Draft

Azure Linux Security Servicing Account (azurelinux-security) wants to merge 3 commits into
microsoft:fasttrack/3.0from
azurelinux-security:azure-autosec/emacs/3.0/1208673

Conversation

@azurelinux-security

@azurelinux-security Azure Linux Security Servicing Account (azurelinux-security) commented Sep 23, 2026 •

Copy link
Copy Markdown

Auto Patch emacs for CVE-2026-96269, CVE-2026-96442.

Autosec pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1208673&view=results
Autosec pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1210608&view=results

CVE-2026-96269 : Single Patch Backporter Pipeline Run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1208689&view=results

Merge Checklist

All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)

  • The toolchain has been rebuilt successfully (or no changes were made to it)
  • The toolchain/worker package manifests are up-to-date
  • Any updated packages successfully build (or no packages were changed)
  • Packages depending on static components modified in this PR (Golang, *-static subpackages, etc.) have had their Release tag incremented.
  • Package tests (%check section) have been verified with RUN_CHECK=y for existing SPEC files, or added to new SPEC files
  • All package sources are available
  • cgmanifest files are up-to-date and sorted (./cgmanifest.json, ./toolkit/scripts/toolchain/cgmanifest.json, .github/workflows/cgmanifest.json)
  • LICENSE-MAP files are up-to-date (./LICENSES-AND-NOTICES/SPECS/data/licenses.json, ./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md, ./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)
  • All source files have up-to-date hashes in the *.signatures.json files
  • sudo make go-tidy-all and sudo make go-test-coverage pass
  • Documentation has been updated to match any changes to the build system
  • Ready to merge

Summary

What does the PR accomplish, why was it needed?

Change Log
Does this affect the toolchain?

YES/NO

Associated issues
  • N/A
Links to CVEs
Test Methodology

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@v-sushilsati

v-sushilsati commented Sep 25, 2026 •

Copy link
Copy Markdown

CVE-2026-96269 summary
Backport: yes (AI patch is not OK)
Scope / Affected Versions
• NVD lists GNU Emacs 28.1 through 31.1 as vulnerable.
• Emacs 29.4 is affected by CVE-2026-96269.
• The upstream reference is confirmed correct.
https://cgit.git.savannah.gnu.org/cgit/emacs.git/patch/?id=c1337758a6c00e22e2a685e0556068fd73fa9a54
• The upstream merge reference contains multiple commits, but the core security fix is a single commit: 7c7616e3.
https://cgit.git.savannah.gnu.org/cgit/emacs.git/patch/?id=7c7616e3f09c80723da7c766b6d188d717247ae3
The Vulnerability
• Fintern, Fintern_soft, and Funintern in src/lread.c called oblookup_considering_shorthand.
• This let an untrusted buffer-local read-symbol-shorthands value silently redirect symbol interning during automatic operations (file visit, VC status refresh, etc.), enabling arbitrary code execution.
The Fix
• Commit 7c7616e3 is the only commit that changes those three primitives to stop consulting read-symbol-shorthands.
Excluded Upstream Commits (correctly out of scope)
• 3f70cfde — adds shorthand-aware source navigation (find-function/xref). Not part of the CVE mitigation: it never touches Fintern/Fintern_soft/Funintern or any automatic code path (file visit, VC refresh) exploited by this CVE. It's a navigation-only convenience, not required to close the vulnerability.
• 4b23583f (doc/lispref/symbols.texi) and 201520c0 (etc/NEWS) — documentation-only, also correctly excluded from the local backport (and also excluded from the AI-generated patch).
• test/src/lread-tests.el changes — not included because the lread-unintern ERT test doesn't exist in Emacs 29.4's baseline lread-tests.el.
AI-Generated Patch— Critical Gaps
• Modifies only 4 Lisp files: lisp-mode.el, shorthands.el, minibuffer.el, elisp-mode.el.
• Completely omits src/lread.c — the file containing the actual vulnerable primitives.
• Also omits lisp/thingatpt.el.
What It Adds/Fixes Correctly
• Adds the missing src/lread.c fix (the actual security-critical change).
• Adds the missing lisp/thingatpt.el change.
• elisp-mode.el: adds the missing elisp--read-symbol-shorthands function and wires it into completion, correctly setting/reading the 'elisp--longhand property so shorthand-aware fboundp/boundp and type lookups work.
• src/lread.c: correctly keeps Emacs 29.4's pre-existing Vpurify_flag/Fpurecopy logic and only removes the shorthand-specific code — the version-appropriate fix for this codebase.

Local build is passed:
buddy build is passed :https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1210276&view=results
image
Patch are applied correctly:
image

POC
The PoC has a victim simply open an attacker-crafted Git file — no unusual interaction needed.
The file's Local Variables footer sets a malicious read-symbol-shorthands mapping, silently accepted as "safe."
A routine VC status check then calls intern on "vc-git-state", which the shorthand redirects to load.
On vulnerable Emacs, this loads and executes the attacker's file as Lisp, writing a proof-of-execution marker.
Tested against real built RPMs: unpatched 29.4-6.azl3 executed the payload as root; patched 29.4-7.azl3 failed safely with vc-not-supported.
This confirms the backported fix closes the actual exploit path.

image

@azurelinux-security Azure Linux Security Servicing Account (azurelinux-security) changed the title [AutoPR- Security] Patch emacs for CVE-2026-96269 [HIGH] [AutoPR- Security] Patch emacs for CVE-2026-96269, CVE-2026-96442 [HIGH] Sep 25, 2026
@v-sushilsati

v-sushilsati commented Sep 28, 2026 •

Copy link
Copy Markdown

CVE-2026-96442 summary
Backport: yes (AI patch is OK)
Scope / Affected Versions
• GNU Emacs versions prior to 31.2 are affected, so Emacs 29.4 is vulnerable.
• Emacs 29.4 is affected by CVE-2026-96442.
• The upstream reference is confirmed and correct.
github.com/emacs-mirror/emacs/commit/abc802ee2eb0b1663349ddf22a461f8e54a383fb.patch
. patch matches with upstream.
. The backport is functionally equivalent to the upstream fix, with context adjusted for Emacs 29.4.
Fix Summary
CVE-2026-96442 allows arbitrary code execution through Emacs Flymake. Flymake previously ran syntax-checking backends on untrusted files. The patch checks trusted-content-p before running a backend, permits explicitly marked flymake-always-safe backends, and disables unsafe backends for untrusted content.

Local build is passed:
Buddy build passed : Buddy Build URL

image

Patches are applied correctly:
image

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants