-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 21 Aug 2026 12:24:00 -0500
Source: emacs
Architecture: source
Version: 1:30.1+1-6+deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Rob Browning <[email protected]>
Changed-By: Rob Browning <[email protected]>
Closes: 1129189 1134692
Changes:
 emacs (1:30.1+1-6+deb13u1) trixie-security; urgency=high
 .
   * Mark esh-proc-test/kill-pipeline as unstable for now.  Skip it since
     it fails sporadically on at least s390x.  Add
     0024-Mark-esh-proc-test-kill-pipeline-as-unstable-for-now.patch to
     address the issue.
 .
   * Fix an SVG-related vulnerability (CVE-2026-6861).  Add
     0025-src-image.c-svg_load_image-Fix-off-by-one-mistake-bu.patch which
     includes the upstream patch to fix the problem.  Thanks to Salvatore
     Bonaccorso for reporting the issue. (Closes: 1134692)
 .
   * Don't run bytecomp-tests--dest-mountpoint where bwrap doesn't work.
     Add 0026-bytecomp-tests-dest-mountpoint-only-run-test-if-bwra.patch to
     address the issue.  Thanks to Santiago Vila for reporting the
     issue. (Closes: 1129189)
 .
   * Skip two more proced-tests in debian that are skipped on darwin to
     avoid hanging during the tests.  Add
     0025-Skip-some-proced-tests-that-appear-to-be-hanging.patch to address
     the issue.
 .
   * Mitigate a risk of executing arbitrary code when opening a file.  The
     vulnerability that has been mitigated could allow a specially crafted
     file to trigger execution of arbitrary Emacs Lisp code immediately
     upon visiting it in Emacs.  The broader issue is described here:
     https://debbugs.gnu.org/80574
 .
     Add 0030-Mitigate-arbitrary-code-execution-vulnerability.patch to
     include the upstream patch addressing the problem.  Thanks to Nicholas
     D Steeves for reporting the issue.
Checksums-Sha1:
 c64632e8c68bcff295a1b1e99d47b11570c9cb29 3034 emacs_30.1+1-6+deb13u1.dsc
 09c8a2c6420edf1c0eafbe02c108fdaaf9d3a105 31081984 emacs_30.1+1.orig.tar.xz
 afae8da17db46d7b01589479f86447ad4394ebba 73200 
emacs_30.1+1-6+deb13u1.debian.tar.xz
 a1c9ee09dc24bf4529ecadf8f5ace5ea95990cf1 22624 
emacs_30.1+1-6+deb13u1_amd64.buildinfo
Checksums-Sha256:
 6c2ab24ed510f5a291e78d5e204b14206cbef3a32ec9285f0b28c8f6d2263726 3034 
emacs_30.1+1-6+deb13u1.dsc
 902fe6e82528f9bc89b0f57227488a08f5bc07126c2c47eb6b5e8a368582324c 31081984 
emacs_30.1+1.orig.tar.xz
 2969a2f1421b01545545d5b2e62570608f7eaf6fd5a52b96863ccec98af2d1a2 73200 
emacs_30.1+1-6+deb13u1.debian.tar.xz
 d0681fd2e48d42145df25b2c2240e0d6cb7163f4465c8d7dae5157525a08584a 22624 
emacs_30.1+1-6+deb13u1_amd64.buildinfo
Files:
 91648f7095f94e1e9357cc05827791ab 3034 editors optional 
emacs_30.1+1-6+deb13u1.dsc
 09b123423ed0e3aba5ae618afbed30ec 31081984 editors optional 
emacs_30.1+1.orig.tar.xz
 43b159b100f53abab51b19d11e579143 73200 editors optional 
emacs_30.1+1-6+deb13u1.debian.tar.xz
 e912f1bed2d6567e658901aa04f2918b 22624 editors optional 
emacs_30.1+1-6+deb13u1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJJBAEBCgAzFiEEPTFSABe5ruOuhW+97vEWxVpaQvEFAmqLWB0VHHJsYkBkZWZh
dWx0dmFsdWUub3JnAAoJEO7xFsVaWkLx2bQP/iQHgGuUq4KNsIxZvn9UG4afNYwg
uaqN8bUwVfo+5goyxJE2tTzwAlpKRZw7b3kzfVIgWavrASGTFGPcDu+y/Y29UpoB
/RkaE6HsYRG3l4cqeQW3az71kA2pZxPKpoQD7lRsZcSbUD/Bzq/nR6BRtpTFJjAN
Hie0r6WitVaejP/PcbpbE4d+RYsG94Gzg8AHoDfqIavQj1Tq2xFqwP98a/ukAbbZ
+/FCFlxdv7BnRJTR8pHOOETZ9UHbJgmcH4AT69lFXBkAYcsARwWcclvunDk3vC24
AfgXjivKXVd6dGzBBSNUnR9ctg0fZ5NSYRFD7FUcCDd2BYzZtCo3mvaoQT3ES/vk
2FqGOXv7nPLT8E5cbB+zPub1Jbb2AuMQvWK5brq0Yr8fMoMIaxdSaJiwv+cRfTry
05jsDIa7JxbfRoR1t5gm+jwDBpygci+kKpEU78yjlD9mYAzWwOAymRzMdGiN1T52
/E0PoNgitJJTo+34oncPGox/9mMUvsbFBrx/kEj5tMocgAdKAfzgLMrPhynXf4kD
1xEEMltYhtqPPGZ4VnUt/a7ZDa2vaab2zOFGu82LvqQ8fSDVGdDAzgjOQp7cbdeI
2mlrGl3Y0dNsmQgN5GADVbC3KDKCIZMWFy3GWoHQC6ZAimbQBbsNPhu5xbQ9dYao
59BHD5eIJ9lVHxob
=uDua
-----END PGP SIGNATURE-----

Attachment: pgpJ0TMm283zg.pgp
Description: PGP signature

Reply via email to