CVE-2026-96442

NameCVE-2026-96442
DescriptionA code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends other than Lisp would execute arbitrary code from the edited file while performing syntax checking. Viewing or editing untrusted files using Emacs could lead to arbitrary code execution with the privileges of the user running Emacs.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1148177

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
emacs (PTS)bookworm, bookworm (security)1:28.2+1-15+deb12u4vulnerable
trixie (security), trixie1:30.1+1-6+deb13u1vulnerable
forky, sid1:30.2+1-11vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
emacssource(unstable)(unfixed)1148177

Notes

https://www.openwall.com/lists/oss-security/2026/09/14/1

Search for package or bug name: Reporting problems