CVE-2026-71392 | GNU Emacs up to 30.2 TrueType Font Processing src/sfnt.c sfnt_read_cmap_format_12 integer overflow (WID-SEC-2026-2721)
A vulnerability was found in GNU Emacs up to 30.2. It has been classified as critical. This impacts the function sfnt_read_cmap_format_12 of the file src/sfnt.c of the component TrueType Font Processing. This manipulation causes integer overflow.
This vulnerability is registered as CVE-2026-71392. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to install a patch to address this issue.