OVERCLOCK.news
security

Emacs arbitrary code execution flaw

Sean Whitton has announced that the original fix for an arbitrary code execution flaw in Emacs ( CVE-2024-53920 ) was incomplete.

BlueskyXRedditMail
Why am I seeing this Single-sourced — only LWN has this

Only LWN has this. It is here on that single source, so read it as one outlet's reporting until somebody else confirms it.

Single-sourced. No second organisation has confirmed it yet.

Link-outLink-out, because only one organisation carries it and no first-party source is on it. Link-out means we point at the publisher and say nothing of our own.

Blended score 0.260 — every figure below is computed, none of it is editorial.
FactorWeightScore ContributionWhere it came from
Corroborationleads 0.35 0.39 +0.135 52% 1 independent org on the story. Tier-3 aggregators never corroborate — they can show something is circulating, never that it is true.
Source trust 0.25 0.49 +0.124 48% LWN is the highest-trust source on this story. Trust is taken from the best source, not averaged.
Pickup rate 0.20 0.00 +0.000 0% One counted organisation, so there is no spread to measure — nothing has picked this up to set a rate.
Freshness 0.20 0.00 +0.001 0% Halves every 10 hours from the newest item on the story. This is the only factor that rewards a story for nothing more than being recent.

Corroboration counts distinct organisations, once each, and only from tiers 1 and 2. Freshness halves every 10 hours, so this ranking is a snapshot and will differ at the next build.

Kuzux · CC BY-SA 2.5 · Wikimedia Commons · illustrative
Read the full article at Lwn →

What happened

Sean Whitton has announced that the original fix for an arbitrary code execution flaw in Emacs ( CVE-2024-53920 ) was incomplete. Bas Alberts discovered that viewing or editing untrusted files in modes other than Emacs's Lisp mode can also result in arbitrary code execution. This problem affects all Emacs versions affected by CVE-2024-53920. This means Emacs 24 and newer, and possibly also older versions. A minimal fix, attached, is queued up for release with Emacs 31.2. We (the Emacs upstream maintainers) don't expect to backport the fix to older Emacs releases ourselves. LWN covered the original vulnerability in December 2024.

1independent orgs
26story score
0velocity
50source trust
36passes seen

How this story arrived

Ordered by when each source was first observed, which is what the velocity figure is computed from. Publishers backdate; observed order does not.

  1. 01 Lwn first seen Emacs arbitrary code execution flaw

Overclock clusters coverage from independent sources and grades it automatically. The figures above are computed, not editorial. This page summarises and links to reporting by the outlets named — follow the links for the original work.