CVE-2024-30202: Code Injection
Published Mar 25, 2024
·Updated
In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.
Affected Software
6 affected componentsFixes available
GNU Emacs<29.3
GNU Org mode<9.6.23
GNU Emacs<29.3
GNU Org Mode Gnu Emacs<9.6.23
debian/emacs
1:27.1+1-3.1+deb11u51:27.1+1-3.1+deb11u61:28.2+1-15+deb12u41:30.1+1-5
debian/org-mode<=9.5.2+dfsh-5
9.4.0+dfsg-1+deb11u39.7.27+dfsg-19.7.29+dfsg-1
Remediation
Event History
Mar 25, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Mar 27, 2025
Data Sourced
via Launchpad·02:40 AM
Description
Mar 31, 2025
Data Sourced
via Ubuntu·02:40 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30202?
CVE-2024-30202 has not been assigned a specific severity rating, but it allows for arbitrary code execution in vulnerable versions of Emacs and Org Mode.
2
How do I fix CVE-2024-30202?
To fix CVE-2024-30202, upgrade Emacs to version 29.3 or higher and Org Mode to version 9.6.23 or higher.
3
What versions are affected by CVE-2024-30202?
CVE-2024-30202 affects GNU Emacs versions before 29.3 and GNU Org Mode versions before 9.6.23.
4
What type of vulnerability is CVE-2024-30202?
CVE-2024-30202 is a code execution vulnerability caused by evaluating arbitrary Lisp code in Emacs when Org mode is enabled.
5
Who is impacted by CVE-2024-30202?
Users of GNU Emacs and Org Mode prior to the specified versions are at risk due to CVE-2024-30202.