You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CVE-2026-96269 summary Backport: yes (AI patch is not OK) Scope / Affected Versions
• NVD lists GNU Emacs 28.1 through 31.1 as vulnerable.
• Emacs 29.4 is affected by CVE-2026-96269.
• The upstream reference is confirmed correct. https://cgit.git.savannah.gnu.org/cgit/emacs.git/patch/?id=c1337758a6c00e22e2a685e0556068fd73fa9a54
• The upstream merge reference contains multiple commits, but the core security fix is a single commit: 7c7616e3. https://cgit.git.savannah.gnu.org/cgit/emacs.git/patch/?id=7c7616e3f09c80723da7c766b6d188d717247ae3 The Vulnerability
• Fintern, Fintern_soft, and Funintern in src/lread.c called oblookup_considering_shorthand.
• This let an untrusted buffer-local read-symbol-shorthands value silently redirect symbol interning during automatic operations (file visit, VC status refresh, etc.), enabling arbitrary code execution. The Fix
• Commit 7c7616e3 is the only commit that changes those three primitives to stop consulting read-symbol-shorthands.
Excluded Upstream Commits (correctly out of scope)
• 3f70cfde — adds shorthand-aware source navigation (find-function/xref). Not part of the CVE mitigation: it never touches Fintern/Fintern_soft/Funintern or any automatic code path (file visit, VC refresh) exploited by this CVE. It's a navigation-only convenience, not required to close the vulnerability.
• 4b23583f (doc/lispref/symbols.texi) and 201520c0 (etc/NEWS) — documentation-only, also correctly excluded from the local backport (and also excluded from the AI-generated patch).
• test/src/lread-tests.el changes — not included because the lread-unintern ERT test doesn't exist in Emacs 29.4's baseline lread-tests.el. AI-Generated Patch— Critical Gaps
• Modifies only 4 Lisp files: lisp-mode.el, shorthands.el, minibuffer.el, elisp-mode.el.
• Completely omits src/lread.c — the file containing the actual vulnerable primitives.
• Also omits lisp/thingatpt.el. What It Adds/Fixes Correctly
• Adds the missing src/lread.c fix (the actual security-critical change).
• Adds the missing lisp/thingatpt.el change.
• elisp-mode.el: adds the missing elisp--read-symbol-shorthands function and wires it into completion, correctly setting/reading the 'elisp--longhand property so shorthand-aware fboundp/boundp and type lookups work.
• src/lread.c: correctly keeps Emacs 29.4's pre-existing Vpurify_flag/Fpurecopy logic and only removes the shorthand-specific code — the version-appropriate fix for this codebase.
POC
The PoC has a victim simply open an attacker-crafted Git file — no unusual interaction needed.
The file's Local Variables footer sets a malicious read-symbol-shorthands mapping, silently accepted as "safe."
A routine VC status check then calls intern on "vc-git-state", which the shorthand redirects to load.
On vulnerable Emacs, this loads and executes the attacker's file as Lisp, writing a proof-of-execution marker.
Tested against real built RPMs: unpatched 29.4-6.azl3 executed the payload as root; patched 29.4-7.azl3 failed safely with vc-not-supported.
This confirms the backported fix closes the actual exploit path.
CVE-2026-96442 summary Backport: yes (AI patch is OK) Scope / Affected Versions
• GNU Emacs versions prior to 31.2 are affected, so Emacs 29.4 is vulnerable.
• Emacs 29.4 is affected by CVE-2026-96442.
• The upstream reference is confirmed and correct. github.com/emacs-mirror/emacs/commit/abc802ee2eb0b1663349ddf22a461f8e54a383fb.patch
. patch matches with upstream.
. The backport is functionally equivalent to the upstream fix, with context adjusted for Emacs 29.4. Fix Summary CVE-2026-96442 allows arbitrary code execution through Emacs Flymake. Flymake previously ran syntax-checking backends on untrusted files. The patch checks trusted-content-p before running a backend, permits explicitly marked flymake-always-safe backends, and disables unsafe backends for untrusted content.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Auto Patch emacs for CVE-2026-96269, CVE-2026-96442.
Autosec pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1208673&view=results
Autosec pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1210608&view=results
CVE-2026-96269 : Single Patch Backporter Pipeline Run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1208689&view=results
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
What does the PR accomplish, why was it needed?
Change Log
Does this affect the toolchain?
YES/NO
Associated issues
Links to CVEs
Test Methodology