Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 40: FEDORA-2024-a3fecfab32 Critical Emacs Code Execution Risk

fedora
Calendar Grey June 28, 2024
Dist Fedora Esm H88
The latest release of Emacs 29.4 brings vital security enhancements, promoting secure operations in the Fedora environment. More information is available.
Update to Emacs 29.4, fixing CVE-2024-39331.

Summary

Emacs is a powerful, customizable, self-documenting, modeless text

editor. Emacs contains special code editing features, a scripting

language (elisp), and the capability to read mail, news, and more

without leaving the editor.

This package provides an emacs binary with support for Wayland, using the

GTK toolkit.

Update Information:

Update to Emacs 29.4, fixing CVE-2024-39331.

Change Log

* Mon Jun 24 2024 Peter Oliver - 1:29.4-3 - Remember to commit key. * Sun Jun 23 2024 Peter Oliver - 1:29.4-2 - Emacs 29.4 tarball is signed by Stefan Kangas, not Eli Zaretskii. * Sun Jun 23 2024 Peter Oliver - 1:29.4-1 - Update to version 29.4.

References


[ 1 ] Bug #2293788 - emacs-29.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2293788 [ 2 ] Bug #2293944 - CVE-2024-39331 emacs: org-link-expand-abbrev: Do not evaluate arbitrary unsafe Elisp code [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2293944

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a3fecfab32' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: emacs
Product: Fedora 40
Version: 29.4
Release: 3.fc40
URL:
Summary: GNU Emacs text editor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here