public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
* [rpms/emacs] f43: Remember to include patch.
@ 2026-08-07 12:31 Peter Oliver
  0 siblings, 0 replies; only message in thread
From: Peter Oliver @ 2026-08-07 12:31 UTC (permalink / raw)
  To: git-commits

A new commit has been pushed.

Repo   : rpms/emacs
Branch : f43
Commit : 31d960abb1de76dfd30b00203bb6f8a8e873ea62
Author : Peter Oliver <git@mavit.org.uk>
Date   : 2026-08-07T13:30:57+01:00
Stats  : +60/-0 in 1 file(s)
URL    : https://src.fedoraproject.org/rpms/emacs/c/31d960abb1de76dfd30b00203bb6f8a8e873ea62?branch=f43

Log:
Remember to include patch.

---
diff --git a/0001-Mitigate-arbitrary-code-execution-vulnerability.patch b/0001-Mitigate-arbitrary-code-execution-vulnerability.patch
new file mode 100644
index 0000000..65af2f8
--- /dev/null
+++ b/0001-Mitigate-arbitrary-code-execution-vulnerability.patch
@@ -0,0 +1,60 @@
+From 8466eb44991707d128110bdc549fad14c8e1d61e Mon Sep 17 00:00:00 2001
+From: Eshel Yaron <me@eshelyaron.com>
+Date: Wed, 5 Aug 2026 19:58:32 +0200
+Subject: [PATCH] Mitigate arbitrary code execution vulnerability
+
+This mitigates a vulnerability that allowed a specially
+crafted file to trigger execution of attacker-controlled
+arbitrary Emacs Lisp code immediately when the file is
+visited in Emacs (before the file's malicious contents are
+even displayed).  See demonstration in bug#80574.
+
+* lisp/progmodes/cc-fonts.el (c-compose-keywords-list):
+* lisp/vc/vc-hooks.el (vc-find-backend-function):
+Nullify 'read-symbol-shorthands' around risky 'intern' calls.
+Do not merge to master.
+---
+ lisp/progmodes/cc-fonts.el | 10 +++++++---
+ lisp/vc/vc-hooks.el        |  5 ++++-
+ 2 files changed, 11 insertions(+), 4 deletions(-)
+
+diff --git a/lisp/progmodes/cc-fonts.el b/lisp/progmodes/cc-fonts.el
+index 9103787df7a..49346f81dfb 100644
+--- a/lisp/progmodes/cc-fonts.el
++++ b/lisp/progmodes/cc-fonts.el
+@@ -2585,9 +2585,13 @@ c-compose-keywords-list
+   (let* ((doc-keywords (c-get-doc-comment-style))
+ 	 (list (nconc (c--mapcan
+ 		       (lambda (doc-style)
+-			 (let ((sym (intern
+-				     (concat (symbol-name doc-style)
+-					     "-font-lock-keywords"))))
++			 (let ((sym
++				;; Guard `intern' from potentially
++				;; malicious shorthands.
++				(let (read-symbol-shorthands)
++				  (intern
++				   (concat (symbol-name doc-style)
++					   "-font-lock-keywords")))))
+ 			   (cond ((fboundp sym)
+ 				  (funcall sym))
+ 				 ((boundp sym)
+diff --git a/lisp/vc/vc-hooks.el b/lisp/vc/vc-hooks.el
+index 132b9211f88..5775983fd91 100644
+--- a/lisp/vc/vc-hooks.el
++++ b/lisp/vc/vc-hooks.el
+@@ -299,7 +299,10 @@ vc-find-backend-function
+   "Return BACKEND-specific implementation of FUN.
+ If there is no such implementation, return the default implementation;
+ if that doesn't exist either, return nil."
+-  (let ((f (vc-make-backend-sym backend fun)))
++  ;; Nullify `read-symbol-shorthands' to guard the `intern' calls below
++  ;; and in `vc-make-backend-sym' from potentially malicious shorthands.
++  (let* ((read-symbol-shorthands nil)
++         (f (vc-make-backend-sym backend fun)))
+     (if (fboundp f) f
+       ;; Load vc-BACKEND.el if needed.
+       (require (intern (concat "vc-" (downcase (symbol-name backend)))))
+-- 
+2.55.0
+

^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-07 12:31 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-07 12:31 [rpms/emacs] f43: Remember to include patch Peter Oliver

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox