What is CVE-2026-71393?
A vulnerability in GNU Emacs for Android involving an integer overflow in sfnt_read_name_table() in src/sfnt.c allows crafted TrueType font files to cause wrapping of allocation size calculations on 32-bit targets. This could potentially lead to memory corruption or other security issues. Users are advised to update to the latest patched version.
Azərbaycanca: GNU Emacs-ın Android versiyasında, sfnt_read_name_table() funksiyasında tam ədəd daşması (integer overflow) zəifliyi aşkarlanıb. 32-bit hədəflərdə, xüsusi hazırlanmış TrueType şrift faylı vasitəsilə yaddaş ayrılması zamanı hesablama səhvinə səbəb ola bilər. İstifadəçilərə proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-190; shared vendor: GNU
FAQ2
On which platform and in which function was CVE-2026-71393 discovered in GNU Emacs?
The vulnerability was discovered as an integer overflow in the `sfnt_read_name_table()` function of the Android version of GNU Emacs.
How can this vulnerability be exploited on 32-bit targets?
It can be exploited via a crafted TrueType font file, causing wrapping of allocation size calculations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.