REDHAT-BUG-2537347: High severity GNU Emacs vulnerability

Published Sep 21, 2026
·
Updated

Emacs upstream reports:

Bas Alberts of the GitHub Security Lab discovered that the fix for CVE-2024-53920, an arbitrary code execution flaw in Emacs, was incomplete. Viewing or editing untrusted text files in modes other than Emacs Lisp mode can also permit arbitrary code execution. For example:

#!/usr/bin/perl # -- mode: perl; mode: flymake -- BEGIN { system("touch uhoh.txt"); }

This problem affects all Emacs versions affected by CVE-2024-53920. This means Emacs 24 and newer, and possibly also older versions.

A minimal fix, attached, is queued up for release with Emacs 31.2. We (the Emacs upstream maintainers) don't expect to backport the fix to older Emacs releases ourselves.

Source: https://www.openwall.com/lists/oss-security/2026/09/14/1

Upstream commit - emacs-31 branch: https://github.com/emacs-mirror/emacs/commit/abc802ee2eb0b1663349ddf22a461f8e54a383fb

Upstream commit - master branch: https://github.com/emacs-mirror/emacs/commit/135e6f63f08fee3d374fa1a5187bce941a2d3e3c

Affected Software

1 affected component
GNU Emacs>=24

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Emacs to a version that resolves this vulnerability.

    Fixed in 31.2

Event History

Sep 21, 2026
Data Sourced
via Red Hat·09:47 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which Emacs installations should be considered exposed?

All Emacs versions affected by CVE-2024-53920 are affected, including Emacs 24 and newer. Older versions may also be affected, but this is not confirmed in the available information.

2

What does an attacker need to exploit this issue?

The attacker needs a target to view or edit an untrusted text file in a mode other than Emacs Lisp mode. A file can use mode declarations to trigger code execution, as illustrated by a Perl file that enables Flymake.

3

Is an upstream fix available for older Emacs releases?

A minimal upstream fix is queued for Emacs 31.2. Upstream maintainers do not expect to backport it to older Emacs releases.

4

What can be done before an update is available?

Avoid viewing or editing untrusted text files in Emacs, particularly files that can select non-Emacs-Lisp modes through file-local mode declarations. Treat such files as potentially capable of executing arbitrary code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203