OS Command Injection in Emacs - CVE-2025-1244
Published: February 21, 2025 / Updated: March 12, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when handling custom "man" URI schemes. A remote attacker can trick the victim into clicking on a specially crafted URL and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Debian Linux
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
Gentoo Linux
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Anolis OS
SUSE Enterprise Storage
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Slackware Linux
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Ubuntu
Fedora
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
app-editors/emacs
emacs
emacs-common
emacs-nox
emacs-el
emacs-filesystem
emacs-terminal
emacs-x11
emacs-debuginfo
etags-debuginfo
emacs-nox-debuginfo
etags
emacs-x11-debuginfo
emacs-debugsource
emacs-info
emacs (Ubuntu package)
emacs (Red Hat package)
emacs-doc
emacs-lucid
emacs (Debian package)
emacs-devel
emacs-help
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
PowerProtect Data Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Virtualization
Juniper Secure Analytics (JSA)
How to mitigate CVE-2025-1244
IBM Cloud Pak for Multicloud Management - update to 2.3 FP11
Red Hat OpenShift Dev Spaces - update to 3.20.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.18.0
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.5.7, 4.6.0, 4.6.3
Red Hat OpenShift Container Platform - addressed in versions 4.12.74, 4.15.47, 4.16.38, 4.17.20, 4.18.4
OpenShift Virtualization - update to 4.16.7
OpenShift Logging - update to 5.8.18
Juniper Secure Analytics (JSA) - update to 7.5.0 UP11 IF03
PowerProtect Data Manager - update to 19.19.0-15
app-editors/emacs - update to 24.1-r1
emacs - addressed in versions 24.3-23, 27.2-11.0.1, 29.4-2
emacs-common - addressed in versions 24.3-23, 27.2-11.0.1, 29.4-2
emacs-nox - addressed in versions 24.3-23, 27.2-11.0.1, 29.4-2
emacs-el - update to 24.3-23
emacs-filesystem - addressed in versions 24.3-23, 27.2-11.0.1, 29.4-2
emacs-terminal - addressed in versions 24.3-23, 27.2-11.0.1, 29.4-2
emacs-x11 - addressed in versions 24.3-25.23.1, 25.3-150000.3.25.3, 27.2-150400.3.23.2
emacs-nox - addressed in versions 24.3-25.23.1, 25.3-150000.3.25.3, 27.2-150400.3.23.2
emacs-debuginfo - addressed in versions 24.3-25.23.1, 25.3-150000.3.25.3, 27.2-150400.3.23.2
etags-debuginfo - addressed in versions 24.3-25.23.1, 25.3-150000.3.25.3, 27.2-150400.3.23.2
emacs - addressed in versions 24.3-25.23.1, 25.3-150000.3.25.3, 27.2-150400.3.23.2
emacs-nox-debuginfo - addressed in versions 24.3-25.23.1, 25.3-150000.3.25.3, 27.2-150400.3.23.2
etags - addressed in versions 24.3-25.23.1, 25.3-150000.3.25.3, 27.2-150400.3.23.2
emacs-x11-debuginfo - addressed in versions 24.3-25.23.1, 25.3-150000.3.25.3, 27.2-150400.3.23.2
emacs-debugsource - addressed in versions 24.3-25.23.1, 25.3-150000.3.25.3, 27.2-150400.3.23.2
emacs-el - addressed in versions 24.3-25.23.1, 25.3-150000.3.25.3, 27.2-150400.3.23.2
emacs-info - addressed in versions 24.3-25.23.1, 25.3-150000.3.25.3, 27.2-150400.3.23.2
emacs (Ubuntu package) - addressed in versions 1:26.3+1-1ubuntu2+esm2, 1:27.1+1-3ubuntu5.2+esm1, 1:29.3+1-1ubuntu2+esm3
emacs (Red Hat package) - update to 27.2-10.el9_4.1
emacs-doc - addressed in versions 27.2-11.0.1, 29.4-2
emacs-lucid - addressed in versions 27.2-11.0.1, 29.4-2
emacs (Debian package) - update to 1:28.2+1-15+deb12u4
emacs-nox - update to 29.1-4
emacs - update to 29.1-4
emacs-common - update to 29.1-4
emacs-debuginfo - update to 29.1-4
emacs-debugsource - update to 29.1-4
emacs-devel - update to 29.1-4
emacs-lucid - update to 29.1-4
emacs-filesystem - update to 29.1-4
emacs-help - update to 29.1-4
emacs-terminal - update to 29.1-4
emacs-devel - update to 29.4-2
emacs - update to 30.1
emacs - update to 30.1-5.fc41
External References
Related Security Bulletins
- Remote code execution in GNU Emacs
- SUSE update for emacs
- SUSE update for emacs
- SUSE update for emacs
- openEuler update for emacs
- Slackware Linux update for emacs
- Debian update for emacs
- Red Hat Enterprise Linux 9 update for emacs
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.5
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.18
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.6
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.6
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Anolis OS update for emacs
- Anolis OS update for emacs
- Anolis OS update for emacs
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.20
- Multiple vulnerabilities in OpenShift Virtualization 4.16
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- Juniper Secure Analytics update for third-party components
- Fedora 41 update for emacs
- Gentoo update for Emacs
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- Ubuntu update for emacs