In elisp-mode.el in GNU Emacs through 30.0.92, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte . MGASA-2024-0397 - Updated emacs packages fix security vulnerability Publication date: 24 Dec 2024 URL: https://advisories.mageia.org/MGASA-2024-0397.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-53920 In elisp-mode.el in GNU Emacs through 30.0.92, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code). (CVE-2024-53920) References: - https://bugs.mageia.org/show_bug.cgi?id=33867 - - https://www.cve.org/CVERecord?id=CVE-2024-53920 SRPMS: - 9/core/emacs-29.4-1.2.mga9 . Updates to Emacs packages have been released to tackle critical security vulnerabilities that permit unregulated code execution via unsafe macro expansions.. CVE-2024-53920, Emacs, Mageia, security advisory, macro expansion. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.