CVE-2026-6861
published 2026-04-22CVE-2026-6861: A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS…
PriorityP428high7.1CVSS 3.1
AVLACLPRNUIRSUCHINAH
EPSS
0.11%
1.4th percentile
A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a denial of service (DoS) or potentially information disclosure.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | emacs | — | — |
| gnu | emacs | 28.1 – 30.2 | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w658-hxq6-43mx: A flaw was found in GNU Emacs
ghsa_unreviewed·2026-04-22
CVE-2026-6861 [MEDIUM] CWE-193 GHSA-w658-hxq6-43mx: A flaw was found in GNU Emacs
A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a denial of service (DoS) or potentially information disclosure.
Red Hat
emacs: Emacs: Memory corruption vulnerability when processing SVG CSS
vendor_redhat·2026-04-19·CVSS 6.1
CVE-2026-6861 [MEDIUM] CWE-193 emacs: Emacs: Memory corruption vulnerability when processing SVG CSS
emacs: Emacs: Memory corruption vulnerability when processing SVG CSS
A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a denial of service (DoS) or potentially information disclosure.
Statement: This Moderate impact vulnerability in Emacs affects Red Hat Enterprise Linux 8, 9, and 10. The flaw, an off-by-one heap buffer overflow and uninitialized read, occurs when processing specially crafted SVG CSS. Exploitation requires a user to open a malicious SVG CSS file with Emacs.
Mitigation: Mitigation for this issue is either not available or the curre
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6861 emacs: Emacs: Memory corruption vulnerability when processing SVG CSS [fedora-all]
bugzilla·2026-04-22·CVSS 6.1
CVE-2026-6861 [MEDIUM] CVE-2026-6861 emacs: Emacs: Memory corruption vulnerability when processing SVG CSS [fedora-all]
CVE-2026-6861 emacs: Emacs: Memory corruption vulnerability when processing SVG CSS [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-49b8ca7981 (emacs-30.2-23.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-49b8ca7981
---
FEDORA-2026-49b8ca7981 has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-49b8ca7981`
You can provide feedback for this update here: https://bodhi.fedora
Bugzilla
CVE-2026-6861 emacs: Emacs: Memory corruption vulnerability when processing SVG CSS [fedora-42]
bugzilla·2026-04-22·CVSS 6.1
CVE-2026-6861 [MEDIUM] CVE-2026-6861 emacs: Emacs: Memory corruption vulnerability when processing SVG CSS [fedora-42]
CVE-2026-6861 emacs: Emacs: Memory corruption vulnerability when processing SVG CSS [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-52dad6273a (emacs-30.2-2.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-52dad6273a
Bugzilla
CVE-2026-6861 emacs: Emacs: Memory corruption vulnerability when processing SVG CSS [fedora-43]
bugzilla·2026-04-22·CVSS 6.1
CVE-2026-6861 [MEDIUM] CVE-2026-6861 emacs: Emacs: Memory corruption vulnerability when processing SVG CSS [fedora-43]
CVE-2026-6861 emacs: Emacs: Memory corruption vulnerability when processing SVG CSS [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-290753da75 (emacs-30.2-7.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-290753da75
---
FEDORA-2026-290753da75 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-290753da75`
You can provide feedback for this update here: https://bodhi.fedorapr
Bugzilla
CVE-2026-6861 emacs: Emacs: Memory corruption vulnerability when processing SVG CSS
bugzilla·2026-04-21·CVSS 6.1
CVE-2026-6861 [MEDIUM] CVE-2026-6861 emacs: Emacs: Memory corruption vulnerability when processing SVG CSS
CVE-2026-6861 emacs: Emacs: Memory corruption vulnerability when processing SVG CSS
Off-by-one heap buffer overflow and uninitialized heap read in GNU Emacs src/image.c svg_load_image() when processing SVG CSS. The null terminator is written one byte past the allocation. Affected: Emacs 28.1 through 30.2. Fixed upstream on emacs-30: commit 8f535370b9.
Public bug: https://debbugs.gnu.org/cgi/bugreport.cgi?bug=80851
2026-04-22
Published