CVE-2026-6861: Emacs: emacs: memory corruption vulnerability when processing svg css

Published Apr 21, 2026
·
Updated

A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a denial of service (DoS) or potentially information disclosure.

Other sources

Emacs: emacs: memory corruption vulnerability when processing svg css

Microsoft

Off-by-one heap buffer overflow and uninitialized heap read in GNU Emacs src/image.c svgloadimage() when processing SVG CSS. The null terminator is written one byte past the allocation. Affected: Emacs 28.1 through 30.2. Fixed upstream on emacs-30: commit 8f535370b9.

Public bug: https://debbugs.gnu.org/cgi/bugreport.cgi?bug=80851

Red Hat

Affected Software

4 affected componentsFixes available
GNU GNU Emacs>=28.1<=30.2
Microsoft azl3 emacs 29.4-3
GNU Emacs>=28.1<=30.2
Microsoft azl3 emacs 29.4-4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GNU Emacs to a version that resolves this vulnerability.

    Fixed in emacs-30Patch 8f535370b9
  2. Compensating control

    Mitigate exploitation by preventing users from opening untrusted/malicious SVG files in GNU Emacs (e.g., disable or block opening of externally sourced SVG content).

Event History

Apr 21, 2026
Data Sourced
via Red Hat·07:35 AM
DescriptionSeverityAffected Software
Apr 22, 2026
CVE Published
via MITRE·01:39 PM
Data Sourced
via MITRE·01:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Apr 29, 2026
Data Sourced
via Microsoft·08:09 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:09 AM
DescriptionSeverity
Updated
via Microsoft·08:09 AM
Affected Software
Sep 20, 58317
Event
via FIRST·09:15 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-6861?

CVE-2026-6861 has been classified with a severity rating that indicates it poses a significant security risk due to potential memory corruption.

2

How do I fix CVE-2026-6861?

To resolve CVE-2026-6861, users should update to the latest version of GNU Emacs that addresses this memory corruption vulnerability.

3

Who is affected by CVE-2026-6861?

CVE-2026-6861 affects local users of GNU Emacs versions between 28.1 and 30.2 who process specially crafted SVG CSS data.

4

What kind of vulnerability is CVE-2026-6861?

CVE-2026-6861 is a memory corruption vulnerability that occurs during the handling of SVG CSS in GNU Emacs.

5

Can CVE-2026-6861 be exploited remotely?

CVE-2026-6861 requires local exploitation, meaning an attacker needs access to the affected system to exploit this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203