Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gnu
Gnu emacs |
|
| Vendors & Products |
Gnu
Gnu emacs |
Fri, 21 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image loader multiplies image dimensions and channel count using signed integer arithmetic; for sufficiently large values, the result wraps to a negative number, bypassing the bounds check and causing the pixel reader to access heap memory past the end of the allocated buffer. The over-read contents are interpreted as pixel color values and rendered on screen. | |
| Title | GNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image Loader | |
| Weaknesses | CWE-125 CWE-190 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-21T21:42:58.824Z
Reserved: 2026-08-20T18:25:46.943Z
Link: CVE-2026-77219
Updated: 2026-08-21T21:32:46.866Z
Status : Received
Published: 2026-08-21T21:17:06.590
Modified: 2026-08-21T22:16:45.797
Link: CVE-2026-77219
No data.
OpenCVE Enrichment
Updated: 2026-08-21T22:30:17Z