Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-152088

emacs-29.4-9.el10 missing fix for CVE-2024-53920 (arbitrary code execution via Lisp macro expansion)

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Blocker Blocker
    • rhel-10.2
    • CentOS Stream 10
    • emacs
    • None
    • None
    • Important
    • rhel-base-utils-antfarm
    • 0
    • No
    • None
    • Approved Blocker
    • None
    • None
    • Unspecified Release Note Type - Unknown
    • x86_64
    • None

      What were you trying to do that didn't work?

      Verify that CVE-2024-53920 was remediated across all supported RHEL major versions. EL8 and EL9 have received patches (RHSA-2025:11030 and RHSA-2025:4787 respectively), but EL10 ships emacs-29.4-9.el10 with no fix applied.

      What is the impact of this issue to you?

      CentOS Stream 10 / RHEL 10 users running emacs are exposed to arbitrary code execution via Lisp macro expansion (CVSS 7.8) when opening untrusted .el files with code completion or on-the-fly byte compilation enabled. This is patched on older releases but not on the newest.

      Please provide the package NVR for which the bug is seen:

      emacs-29.4-9.el10.x86_64

      How reproducible is this bug?:

      Always — the vulnerable code path is present in all GNU Emacs versions before 30.1.

      Steps to reproduce

      1. Install emacs-29.4-9.el10 from CentOS Stream 10
      2. Open an untrusted .el file with Flymake or elisp-completion-at-point enabled
      3. Malicious macro expansion executes arbitrary code

      Expected results

      emacs on EL10 includes a backport of the CVE-2024-53920 fix, consistent with EL8 and EL9

      Actual results

      EL10 ships vulnerable emacs-29.4 with no patch applied

              jmigacz@redhat.com Jacek Migacz
              rh-ee-clusk Christopher Lusk
              Jacek Migacz Jacek Migacz
              RHEL SST CS base utils QE Bot RHEL SST CS base utils QE Bot
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: