CVE-2023-27986
published 2023-03-09CVE-2023-27986: emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote…
PriorityP434high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.48%
38.0th percentile
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | emacs | < emacs 1:28.2+1-13 (bookworm) | emacs 1:28.2+1-13 (bookworm) |
| gnu | emacs | >= 0 < 1:28.2+1-13 | 1:28.2+1-13 |
| gnu | emacs | >= 0 < 1:28.2+1-13 | 1:28.2+1-13 |
| gnu | emacs | >= 0 < 1:28.2+1-13 | 1:28.2+1-13 |
| gnu | emacs | 28.1 – 28.2 | — |
| msrc | cbl2_emacs_28.2-4_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: scsi: core: Remove the /proc/scsi/${proc_name} directory earlier
vendor_redhat·2025-05-02·CVSS 5.5
CVE-2023-53140 [MEDIUM] kernel: scsi: core: Remove the /proc/scsi/${proc_name} directory earlier
kernel: scsi: core: Remove the /proc/scsi/${proc_name} directory earlier
In the Linux kernel, the following vulnerability has been resolved:
scsi: core: Remove the /proc/scsi/${proc_name} directory earlier
Remove the /proc/scsi/${proc_name} directory earlier to fix a race
condition between unloading and reloading kernel modules. This fixes a bug
introduced in 2009 by commit 77c019768f06 ("[SCSI] fix /proc memory leak in
the SCSI core").
Fix the following kernel warning:
proc_dir_entry 'scsi/scsi_debug' already registered
WARNING: CPU: 19 PID: 27986 at fs/proc/generic.c:376 proc_register+0x27d/0x2e0
Call Trace:
proc_mkdir+0xb5/0xe0
scsi_proc_hostdir_add+0xb5/0x170
scsi_host_alloc+0x683/0x6c0
sdebug_driver_probe+0x6b/0x2d0 [scsi_debug]
really_probe+0x159/0x540
__driver_probe_device+0xdc/0x2
Microsoft
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.
vendor_msrc·2023-03-14·CVSS 7.8
CVE-2023-27986 [HIGH] CWE-94 emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to ref
Red Hat
emacs: Emacs Lisp code injection via a crafted mailto URI
vendor_redhat·2023-03-08·CVSS 7.8
CVE-2023-27986 [HIGH] CWE-77 emacs: Emacs Lisp code injection via a crafted mailto URI
emacs: Emacs Lisp code injection via a crafted mailto URI
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.
A flaw was found in the Emacs text editor. A crafted mailto URI, when opened with emacsclient-mail.desktop, can result in Emacs Lisp code injection.
Statement: The emacsclient-mail.desktop file is not distributed in Red Hat Enterprise Linux 6, 7, 8 and 9. Therefore, Red Hat Enterprise Linux is not affected by this flaw.
Package: emacs (Red Hat Enterprise Linux 6) - Not affected
Package: emacs (Red Hat Enterprise Linux 7) - Not affected
Package: emacs (Red Hat Enterprise Linux 8) - Not affected
Package: emacs (Red Hat Enterprise Linux 9) -
Debian
CVE-2023-27986: emacs - emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp ...
vendor_debian·2023·CVSS 7.8
CVE-2023-27986 [HIGH] CVE-2023-27986: emacs - emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp ...
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.
Scope: local
bookworm: resolved (fixed in 1:28.2+1-13)
bullseye: resolved
forky: resolved (fixed in 1:28.2+1-13)
sid: resolved (fixed in 1:28.2+1-13)
trixie: resolved (fixed in 1:28.2+1-13)
GHSA
GHSA-whwp-m746-hx6w: emacsclient-mail
ghsa_unreviewed·2023-03-09
CVE-2023-27986 [CRITICAL] CWE-94 GHSA-whwp-m746-hx6w: emacsclient-mail
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters.
OSV
CVE-2023-27986: emacsclient-mail
osv·2023-03-09·CVSS 7.8
CVE-2023-27986 [HIGH] CVE-2023-27986: emacsclient-mail
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.
No detection rules found.
No public exploits indexed.
http://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=3c1693d08b0a71d40a77e7b40c0ebc42dca2d2cchttp://www.openwall.com/lists/oss-security/2023/03/09/1https://www.gabriel.urdhr.fr/2023/06/08/emacsclient-mail-shell-elisp-injections/https://www.openwall.com/lists/oss-security/2023/03/08/2http://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=3c1693d08b0a71d40a77e7b40c0ebc42dca2d2cchttp://www.openwall.com/lists/oss-security/2023/03/09/1https://www.gabriel.urdhr.fr/2023/06/08/emacsclient-mail-shell-elisp-injections/https://www.openwall.com/lists/oss-security/2023/03/08/2
2023-03-09
Published