What is CVE-2026-71391?
This vulnerability is an off-by-one error in the gvar table parser within the `src/sfnt.c` file of GNU Emacs for Android. The boundary check for the shared-coordinate index uses an incorrect comparison operator, which could allow memory corruption via a crafted TrueType variable font. Users should avoid opening untrusted font files in Emacs until a patch is available.
Azərbaycanca: Bu boşluq GNU Emacs-in Android versiyasında `src/sfnt.c` faylındakı gvar cədvəli parserində 'off-by-one' xətasıdır. Sərhəd yoxlamasında səhv müqayisə operatoru istifadə edildiyi üçün xüsusi hazırlanmış TrueType şriftləri vasitəsilə potensial yaddaş korrupsiyası baş verə bilər. İstifadəçilərə rəsmi yamaq çıxana qədər etibarsız mənbələrdən gələn şrift fayllarını Emacs ilə açmamaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
In which component of GNU Emacs does CVE-2026-71391 exist?
The vulnerability exists in the gvar table parser within the `src/sfnt.c` file of GNU Emacs for Android.
What is the attack vector for exploiting CVE-2026-71391?
The attack vector involves using a crafted TrueType variable font file to cause memory corruption.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.