CVE-2026-77219
published 2026-08-21CVE-2026-77219: GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a…
PriorityP432high7.1CVSS 3.1
AVLACLPRNUIRSUCHINAH
EPSS
0.13%
2.8th percentile
GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image loader multiplies image dimensions and channel count using signed integer arithmetic; for sufficiently large values, the result wraps to a negative number, bypassing the bounds check and causing the pixel reader to access heap memory past the end of the allocated buffer. The over-read contents are interpreted as pixel color values and rendered on screen.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | emacs | < 31.0.91 | 31.0.91 |
| gnu | emacs | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GNU Emacs up to 31.0.90 Image Loader integer overflow
vuldb·2026-08-21·CVSS 7.1
CVE-2026-77219 [HIGH] GNU Emacs up to 31.0.90 Image Loader integer overflow
A vulnerability labeled as problematic has been found in GNU Emacs up to 31.0.90. Affected by this issue is some unknown functionality of the component Image Loader. Such manipulation leads to integer overflow.
This vulnerability is listed as CVE-2026-77219. The attack must be carried out locally. There is no available exploit.
The affected component should be upgraded.
GHSA
GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an ele
ghsa_unreviewed·2026-08-21
CVE-2026-77219 [MEDIUM] CWE-125 GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an ele
GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image loader multiplies image dimensions and channel count using signed integer arithmetic; for sufficiently large values, the result wraps to a negative number, bypassing the bounds check and causing the pixel reader to access heap memory past the end of the allocated buffer. The over-read contents are interpreted as pixel color values and rendered on screen.
Red Hat
emacs: GNU Emacs: Heap over-read leading to information disclosure via crafted image
vendor_redhat·2026-08-21·CVSS 7.1
CVE-2026-77219 [HIGH] CWE-125 emacs: GNU Emacs: Heap over-read leading to information disclosure via crafted image
emacs: GNU Emacs: Heap over-read leading to information disclosure via crafted image
GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image loader multiplies image dimensions and channel count using signed integer arithmetic; for sufficiently large values, the result wraps to a negative number, bypassing the bounds check and causing the pixel reader to access heap memory past the end of the allocated buffer. The over-read contents are interpreted as pixel color values and rendered on screen.
A flaw was found in GNU Emacs. An integer overflow in the PBM/PPM/PGM image loader allows a remote attacker to leak heap me
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-77219 emacs: GNU Emacs: Heap over-read leading to information disclosure via crafted image [fedora-all]
bugzilla·2026-08-25·CVSS 7.1
CVE-2026-77219 [HIGH] CVE-2026-77219 emacs: GNU Emacs: Heap over-read leading to information disclosure via crafted image [fedora-all]
CVE-2026-77219 emacs: GNU Emacs: Heap over-read leading to information disclosure via crafted image [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image loader multiplies image dimensions and channel count using signed integer arithmetic; for sufficiently large values, the result wraps to a negative number, bypassing the bounds check and causing the pixel reader to access heap m
Bugzilla
CVE-2026-77219 emacs: GNU Emacs: Heap over-read leading to information disclosure via crafted image
bugzilla·2026-08-21·CVSS 7.1
CVE-2026-77219 [HIGH] CVE-2026-77219 emacs: GNU Emacs: Heap over-read leading to information disclosure via crafted image
CVE-2026-77219 emacs: GNU Emacs: Heap over-read leading to information disclosure via crafted image
GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image loader multiplies image dimensions and channel count using signed integer arithmetic; for sufficiently large values, the result wraps to a negative number, bypassing the bounds check and causing the pixel reader to access heap memory past the end of the allocated buffer. The over-read contents are interpreted as pixel color values and rendered on screen.
2026-08-21
Published