Description
A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a denial of service (DoS) or potentially information disclosure.
Problem types
Product status
Timeline
| 2026-04-19: | Reported to Red Hat. |
| 2026-04-19: | Made public. |
Credits
Red Hat would like to thank Gaetano Zappulla (Tinexta Defence SpA) for reporting this issue.
References
access.redhat.com/security/cve/CVE-2026-6861
bugzilla.redhat.com/show_bug.cgi?id=2459992 (RHBZ#2459992)