Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Oracle Linux 9 ELSA-2023-2626 Critical: Emacs Command Injection Fixes

oracle
Calendar Grey May 18, 2023
Scroller Oracle
Crucial safety patch released for Oracle Linux 9, tackling numerous Emacs security flaws. Essential updates can be downloaded immediately.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Summary

[1:27.2-8.1] - Fix etags local command injection vulnerability (#2184369) - Fix htmlfontify.el command injection vulnerability (#2184368) - Fix ruby-mode.el local command injection vulnerability (#2184367) - Fix ob-latex.el command injection vulnerability (#2184377) [1:27.2-8] - Use a 64KB page size for pdump (#1979804) [1:27.2-7] - Fix ctags local command execute vulnerability (#2149387)

SRPMs

https://oss.oracle.com:443/ol9/SRPMS-updates//emacs-27.2-8.el9_2.1.src.rpm

x86_64

emacs-27.2-8.el9_2.1.x86_64.rpm emacs-common-27.2-8.el9_2.1.x86_64.rpm emacs-filesystem-27.2-8.el9_2.1.noarch.rpm emacs-lucid-27.2-8.el9_2.1.x86_64.rpm emacs-nox-27.2-8.el9_2.1.x86_64.rpm

aarch64

emacs-27.2-8.el9_2.1.aarch64.rpm emacs-common-27.2-8.el9_2.1.aarch64.rpm emacs-filesystem-27.2-8.el9_2.1.noarch.rpm emacs-lucid-27.2-8.el9_2.1.aarch64.rpm emacs-nox-27.2-8.el9_2.1.aarch64.rpm

Severity
critical
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2022-48337 CVE-2022-48338 CVE-2022-48339 CVE-2023-2491

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.