{"id":"CVE-2026-77219","summary":"GNU Emacs \u003c 31.0.91 Heap Over-Read via PBM/PPM/PGM Image Loader","details":"GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image loader multiplies image dimensions and channel count using signed integer arithmetic; for sufficiently large values, the result wraps to a negative number, bypassing the bounds check and causing the pixel reader to access heap memory past the end of the allocated buffer. The over-read contents are interpreted as pixel color values and rendered on screen.","modified":"2026-08-24T03:59:17.846561Z","published":"2026-08-21T20:20:45.314Z","database_specific":{"cwe_ids":["CWE-125","CWE-190"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77219.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77219.json"},{"type":"ADVISORY","url":"https://github.com/emacs-mirror/emacs/releases/tag/emacs-31.0.91"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77219"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/gnu-emacs-heap-over-read-via-pbm-ppm-pgm-image-loader"},{"type":"REPORT","url":"https://debbugs.gnu.org/cgi/bugreport.cgi?bug=81344"},{"type":"FIX","url":"https://github.com/emacs-mirror/emacs/commit/b07e634e4cf45162ae0178e32092b040587f2c6c"},{"type":"PACKAGE","url":"https://github.com/emacs-mirror/emacs"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/emacs-mirror/emacs","events":[{"introduced":"0"},{"fixed":"57581b8bc2f73229d1f03dd5655aabb4a6de6183"},{"fixed":"b07e634e4cf45162ae0178e32092b040587f2c6c"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"31.0.91"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["emacs-31.0.90","emacs-pretest-23.1.92","emacs-pretest-23.1.91","emacs-pretest-23.1.90","emacs-pretest-23.0.95","mh-e-8.2","mh-e-doc-8.2","emacs-pretest-23.0.94","emacs-pretest-23.0.93","emacs-pretest-23.0.92","emacs-pretest-23.0.91","emacs-pretest-23.0.90","mh-e-doc-8.1","mh-e-8.1","emacs-pretest-22.0.98","emacs-pretest-22.0.97","emacs-pretest-22.0.96","emacs-pretest-22.0.95","emacs-pretest-22.0.94","emacs-pretest-22.0.93","emacs-pretest-22.0.92","emacs-pretest-22.0.91","mh-e-8.0.3","mh-e-doc-8.0.3","emacs-pretest-22.0.90","mh-e-8.0.2","mh-e-doc-8.0.1","mh-e-8.0.1","mh-e-doc-8.0","mh-e-8.0","ttn-vms-21-2-B4","emacs-pretest-21.0.106","emacs-pretest-21.0.105","emacs-pretest-21.0.104","emacs-pretest-21.0.103","emacs-pretest-21.0.102","emacs-pretest-21.0.101","emacs-pretest-21.0.100","emacs-pretest-21.0.99","emacs-pretest-21.0.98","emacs-pretest-21.0.97","emacs-pretest-21.0.96","emacs-pretest-21.0.95","emacs-pretest-21.0.93","emacs-pretest-21.0.92","emacs-pretest-21.0.91","emacs-pretest-21.0.90","emacs-20.4","emacs-20.3","emacs-20.2","emacs-20.1","emacs-19.34"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77219.json","vanir_signatures_modified":"2026-08-24T03:59:17Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/emacs-mirror/emacs/commit/b07e634e4cf45162ae0178e32092b040587f2c6c","target":{"file":"src/image.c","function":"pbm_load"},"deprecated":false,"digest":{"function_hash":"258673638944095828071566080484646474381","length":4506},"id":"CVE-2026-77219-c667c86f","signature_type":"Function"},{"source":"https://github.com/emacs-mirror/emacs/commit/b07e634e4cf45162ae0178e32092b040587f2c6c","target":{"file":"src/image.c"},"deprecated":false,"digest":{"line_hashes":["195389056970384225465457360733826923154","30743957392029437298895236527953516614","111340952189053751276040701366772383005","191098332935111733868625331608384229249","138792707373502694081969352469803653663","153138648923648074605034718771059639440","65634003212636966256027357271456261512","310229738444058907868078119131101498351","164932963844408134274952941465718873097","124303929148704238738091731722928157762","120583420899258265332683383904982012131","272595218324774214439785912951772159062","105183179690217016208969693874981039260","58673321751195478723877138963568116108","309138827984967736707121349168452132665"],"threshold":0.9},"id":"CVE-2026-77219-e8dc267d","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N"}]}