Use of Potentially Dangerous Function in Emacs - CVE-2024-39331
Published: June 24, 2024
Vulnerability identifier: #VU93118
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-39331
CWE-ID: CWE-676
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function. A remote attacker can execute arbitrary OS commands on the system.
Affected software
Emacs
Org Mode
Oracle Linux
Oracle Solaris
Gentoo Linux
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
Desktop Applications Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Cryostat
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift Logging
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
emacs25 (Ubuntu package)
org-mode (Ubuntu package)
elpa-org (Ubuntu package)
emacs (Ubuntu package)
emacs-bin-common (Ubuntu package)
emacs-common (Ubuntu package)
emacs-el (Ubuntu package)
emacs25-bin-common (Ubuntu package)
emacs25-common (Ubuntu package)
emacs25-el (Ubuntu package)
emacs24 (Ubuntu package)
emacs24-bin-common (Ubuntu package)
emacs24-common (Ubuntu package)
emacs24-el (Ubuntu package)
org-mode (Debian package)
app-editors/emacs
emacs
emacs-el
emacs-info
emacs-nox
emacs-debugsource
emacs-nox-debuginfo
etags
emacs-x11-debuginfo
emacs-debuginfo
etags-debuginfo
emacs-x11
emacs (Red Hat package)
emacs (Debian package)
emacs-common
emacs-lucid
emacs-filesystem
emacs-doc
emacs-terminal
emacs-help
emacs-devel
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
IBM QRadar Network Packet Capture
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Qradar SIEM
IBM Business Automation Manager Open Editions
Org Mode
Oracle Linux
Oracle Solaris
Gentoo Linux
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
Desktop Applications Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Cryostat
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift Logging
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
emacs25 (Ubuntu package)
org-mode (Ubuntu package)
elpa-org (Ubuntu package)
emacs (Ubuntu package)
emacs-bin-common (Ubuntu package)
emacs-common (Ubuntu package)
emacs-el (Ubuntu package)
emacs25-bin-common (Ubuntu package)
emacs25-common (Ubuntu package)
emacs25-el (Ubuntu package)
emacs24 (Ubuntu package)
emacs24-bin-common (Ubuntu package)
emacs24-common (Ubuntu package)
emacs24-el (Ubuntu package)
org-mode (Debian package)
app-editors/emacs
emacs
emacs-el
emacs-info
emacs-nox
emacs-debugsource
emacs-nox-debuginfo
etags
emacs-x11-debuginfo
emacs-debuginfo
etags-debuginfo
emacs-x11
emacs (Red Hat package)
emacs (Debian package)
emacs-common
emacs-lucid
emacs-filesystem
emacs-doc
emacs-terminal
emacs-help
emacs-devel
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
IBM QRadar Network Packet Capture
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Qradar SIEM
IBM Business Automation Manager Open Editions
How to mitigate CVE-2024-39331
Install updates from vendor's website.
Emacs - update to 29.4
Oracle Solaris - update to 11.4 SRU 71
Org Mode - update to 9.7.5
emacs25 (Ubuntu package) - update to Ubuntu Pro
org-mode (Ubuntu package) - update to Ubuntu Pro
elpa-org (Ubuntu package) - update to Ubuntu Pro
emacs (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-bin-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-el (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs25-bin-common (Ubuntu package) - update to Ubuntu Pro
emacs25-common (Ubuntu package) - update to Ubuntu Pro
emacs25-el (Ubuntu package) - update to Ubuntu Pro
emacs24 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs24-bin-common (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs24-common (Ubuntu package) - update to Ubuntu Pro
emacs24-el (Ubuntu package) - update to Ubuntu Pro
Migration Toolkit for Containers - addressed in versions 1.8.4, 1.8.5
Red Hat OpenShift GitOps - addressed in versions 1.12.6, 1.13.2
IBM Cloud Pak for Multicloud Management - update to 2.3 FP11
Multicluster Engine for Kubernetes - addressed in versions 2.3.8, 2.4.6
OpenShift Service Mesh - addressed in versions 2.5.5, 2.6.2
Red Hat OpenShift Dev Spaces - addressed in versions 3.16.0, 3.17.0
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.6, 4.5.3
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.7
Red Hat OpenShift Container Platform - addressed in versions 4.12.63, 4.13.52, 4.14.38, 4.15.35, 4.16.15, 4.17.0
OpenShift Virtualization - update to 4.13.11
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.13.12, 4.14.11, 4.16.3
OpenShift Logging - addressed in versions 5.6.24, 5.8.13
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF01
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 11
IBM Business Automation Manager Open Editions - update to 8.0.6
org-mode (Debian package) - update to 9.4.0+dfsg-1+deb11u3
app-editors/emacs - update to 9.7.5
emacs - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs-el - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs-info - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs-nox - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs-debugsource - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs-nox-debuginfo - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
etags - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs-x11-debuginfo - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs-debuginfo - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
etags-debuginfo - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs-x11 - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs (Red Hat package) - addressed in versions 26.1-7.el8_6.5, 27.2-10.el9_4
emacs (Debian package) - addressed in versions 1:27.1+1-3.1+deb11u5, 1:28.2+1-15+deb12u3
emacs - update to 27.2-9.0.3
emacs-common - update to 27.2-9.0.3
emacs-lucid - update to 27.2-9.0.3
emacs-nox - update to 27.2-9.0.3
emacs-filesystem - update to 27.2-9.0.3
emacs-doc - update to 27.2-9.0.3
emacs-terminal - update to 27.2-9.0.3
emacs-help - update to 27.2-14
emacs-filesystem - update to 27.2-14
emacs-nox - update to 27.2-14
emacs-lucid - update to 27.2-14
emacs-devel - update to 27.2-14
emacs-debugsource - update to 27.2-14
emacs-debuginfo - update to 27.2-14
emacs-common - update to 27.2-14
emacs - update to 27.2-14
emacs-terminal - update to 27.2-14
emacs - addressed in versions 29.4-1.fc39, 29.4-2.fc39, 29.4-3.fc40
Oracle Solaris - update to 11.4 SRU 71
Org Mode - update to 9.7.5
emacs25 (Ubuntu package) - update to Ubuntu Pro
org-mode (Ubuntu package) - update to Ubuntu Pro
elpa-org (Ubuntu package) - update to Ubuntu Pro
emacs (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-bin-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-el (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs25-bin-common (Ubuntu package) - update to Ubuntu Pro
emacs25-common (Ubuntu package) - update to Ubuntu Pro
emacs25-el (Ubuntu package) - update to Ubuntu Pro
emacs24 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs24-bin-common (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs24-common (Ubuntu package) - update to Ubuntu Pro
emacs24-el (Ubuntu package) - update to Ubuntu Pro
Migration Toolkit for Containers - addressed in versions 1.8.4, 1.8.5
Red Hat OpenShift GitOps - addressed in versions 1.12.6, 1.13.2
IBM Cloud Pak for Multicloud Management - update to 2.3 FP11
Multicluster Engine for Kubernetes - addressed in versions 2.3.8, 2.4.6
OpenShift Service Mesh - addressed in versions 2.5.5, 2.6.2
Red Hat OpenShift Dev Spaces - addressed in versions 3.16.0, 3.17.0
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.6, 4.5.3
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.7
Red Hat OpenShift Container Platform - addressed in versions 4.12.63, 4.13.52, 4.14.38, 4.15.35, 4.16.15, 4.17.0
OpenShift Virtualization - update to 4.13.11
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.13.12, 4.14.11, 4.16.3
OpenShift Logging - addressed in versions 5.6.24, 5.8.13
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF01
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 11
IBM Business Automation Manager Open Editions - update to 8.0.6
org-mode (Debian package) - update to 9.4.0+dfsg-1+deb11u3
app-editors/emacs - update to 9.7.5
emacs - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs-el - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs-info - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs-nox - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs-debugsource - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs-nox-debuginfo - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
etags - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs-x11-debuginfo - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs-debuginfo - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
etags-debuginfo - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs-x11 - addressed in versions 24.3-25.20.1, 25.3-150000.3.22.1, 27.2-150400.3.17.1
emacs (Red Hat package) - addressed in versions 26.1-7.el8_6.5, 27.2-10.el9_4
emacs (Debian package) - addressed in versions 1:27.1+1-3.1+deb11u5, 1:28.2+1-15+deb12u3
emacs - update to 27.2-9.0.3
emacs-common - update to 27.2-9.0.3
emacs-lucid - update to 27.2-9.0.3
emacs-nox - update to 27.2-9.0.3
emacs-filesystem - update to 27.2-9.0.3
emacs-doc - update to 27.2-9.0.3
emacs-terminal - update to 27.2-9.0.3
emacs-help - update to 27.2-14
emacs-filesystem - update to 27.2-14
emacs-nox - update to 27.2-14
emacs-lucid - update to 27.2-14
emacs-devel - update to 27.2-14
emacs-debugsource - update to 27.2-14
emacs-debuginfo - update to 27.2-14
emacs-common - update to 27.2-14
emacs - update to 27.2-14
emacs-terminal - update to 27.2-14
emacs - addressed in versions 29.4-1.fc39, 29.4-2.fc39, 29.4-3.fc40
External References
- https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29
- https://list.orgmode.org/87sex5gdqc.fsf%40localhost/
- https://lists.gnu.org/archive/html/info-gnu-emacs/2024-06/msg00000.html
- https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=f4cc61636947b5c2f0afc67174dd369fe3277aa8
- https://www.openwall.com/lists/oss-security/2024/06/23/1
- https://www.openwall.com/lists/oss-security/2024/06/23/2
- https://news.ycombinator.com/item?id=40768225
Related Security Bulletins
- Remote code execution in Emacs
- Remote code execution in Org Mode
- Fedora 40 update for emacs
- Fedora 39 update for emacs
- Fedora 39 update for emacs
- SUSE update for emacs
- SUSE update for emacs
- Debian update for org-mode
- Debian update for emacs
- SUSE update for emacs
- openEuler update for emacs
- Red Hat Enterprise Linux 8 update for emacs
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Oracle Solaris update for thrid-party components
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Red Hat Enterprise Linux 9 update for emacs
- Ubuntu update for emacs
- Gentoo update for Emacs, org-mode
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.5
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.14
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.13
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in OpenShift Service Mesh 2.6
- Multiple vulnerabilities in Red Hat build of Cryostat 3 on RHEL 8
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.16
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.4
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.13
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data update for GNU Emacs
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.4
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.3
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Multiple vulnerabilities in OpenShift Virtualization 4.13
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in IBM QRadar Network Packet Capture
- Ubuntu update for org-mode
- Anolis OS update for emacs
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management