A vulnerability has been discovered in GNU Emacs allowing arbitrary code execution.
| Package | app-editors/emacs on all architectures |
|---|---|
| Affected versions | < 27.2-r4 < 28.2-r22 < 29.4-r10 < 30.2-r6 |
| Unaffected versions | >= 27.2-r4 >= 28.2-r22 >= 29.4-r10 >= 30.2-r6 |
GNU Emacs is the extensible, customizable, self-documenting real-time display editor.
A vulnerability has been discovered in GNU Emacs. Please review the CVE identifier referenced below for details.
An attacker could achieve arbitrary code execution by tricking a user into opening a file or directory with a malicious filename via TRAMP.
There is no known workaround at this time.
All GNU Emacs 27 users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=app-editors/emacs-27.2-r4:27"
All GNU Emacs 28 users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=app-editors/emacs-28.2-r22:28"
All GNU Emacs 29 users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=app-editors/emacs-29.4-r10:29"
All GNU Emacs 30 users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=app-editors/emacs-30.2-r6:30"
Release date
August 24, 2026
Latest revision
August 24, 2026: 1
Severity
high
Exploitable
local and remote
Bugzilla entries