Off-by-one in Emacs - CVE-2026-6861

 

Off-by-one in Emacs - CVE-2026-6861

Published: April 29, 2026


Vulnerability identifier: #VU128469
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-6861
CWE-ID: CWE-193
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to an off-by-one error within the svg_load_image() function in src/image.c when processing SVG CSS. A remote attacker can supply a specially crafted SVG image to the application and crash it. 


Affected software

Emacs
Anolis OS
openEuler
Fedora
emacs-debuginfo
emacs-devel
emacs-lucid
emacs-nox
emacs-filesystem
emacs-help
emacs-terminal
emacs
emacs-common
emacs-debugsource
emacs-doc

How to mitigate CVE-2026-6861

Install updates from vendor's repository.

emacs-debuginfo - update to 29.1-8
emacs-devel - update to 29.1-8
emacs-lucid - update to 29.1-8
emacs-nox - update to 29.1-8
emacs-filesystem - update to 29.1-8
emacs-help - update to 29.1-8
emacs-terminal - update to 29.1-8
emacs - update to 29.1-8
emacs-common - update to 29.1-8
emacs-debugsource - update to 29.1-8
emacs-lucid - update to 29.4-6
emacs-nox - update to 29.4-6
emacs-terminal - update to 29.4-6
emacs-doc - update to 29.4-6
emacs-filesystem - update to 29.4-6
emacs-devel - update to 29.4-6
emacs-common - update to 29.4-6
emacs - update to 29.4-6
emacs - addressed in versions 30.2-2.fc42, 30.2-7.fc43, 30.2-23.fc44

External References

Related Security Bulletins