Skip to content
VulniPulse
Advisory severityLow3.3Red Hat Linux

Low [CVE-2026-71391] off-by-one error via a malicious font file

This low-severity Red Hat Linux advisory covers CVE-2026-71391.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-71391 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxUnclassified
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c.

The shared-coordinate index boundary check in sfnt_vary_simple_glyph() and sfnt_vary_compound_glyph() uses a strict greater-than comparison instead of greater-than-or-equal, allowing a crafted TrueType variable font to bypass the check and trigger a heap-based out-of-bounds read via memcpy.

An attacker can deliver a malicious font file via email, EWW (Emacs Web Wowser), or documents with custom faces, causing Emacs to load it. This exposes heap memory contents which can be later used to defeat ASLR.

This issue was fixed in commit 95ab9ef627b212d74d321c5bbb5b56a1be7b9fbe An off-by-one error can occur when a specially crafted font file is processed due to an improper bounds check. This can cause a heap-based buffer over-read, exposing heap memory contents.

To exploit this flaw, a user needs to load a malicious font file or a document with custom faces, limiting its exposure. The only security impact of this issue is an information disclosure of heap memory contents.

For these reasons, this vulnerability has been rated with a low severity. Red Hat severity: Low — CVSS 3.3 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).

Weakness: CWE-193.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 25 days ago·verify at source

Fixed versions

No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.

Official advisory · high-confidence parse· fetched 25 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Do not load untrusted font files or open unverified documents with custom faces.

Official advisory · high-confidence parse· fetched 25 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.