Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package emacs for openSUSE:Factory checked in at 2026-09-28 10:37:04 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/emacs (Old) and /work/SRC/openSUSE:Factory/.emacs.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "emacs" Mon Sep 28 10:37:04 2026 rev:225 rq:1380658 version:31.1 Changes: -------- --- /work/SRC/openSUSE:Factory/emacs/emacs.changes 2026-09-04 12:37:24.005241087 +0200 +++ /work/SRC/openSUSE:Factory/.emacs.new.383539/emacs.changes 2026-09-28 10:38:07.041004004 +0200 @@ -1,0 +2,8 @@ +Thu Sep 24 09:28:46 UTC 2026 - Dr. Werner Fink <[email protected]> + +- Add patch bsc1282390.patch + * Fix bsc#1282390 (CVE-2026-96442): arbitrary code execution when + viewing or editing untrusted text files in modes other than + Emacs Lisp mode due to incomplete fix for older CVE + +------------------------------------------------------------------- New: ---- bsc1282390.patch ----------(New B)---------- New: - Add patch bsc1282390.patch * Fix bsc#1282390 (CVE-2026-96442): arbitrary code execution when ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ emacs.spec ++++++ --- /var/tmp/diff_new_pack.RZ1Jsd/_old 2026-09-28 10:38:09.319099266 +0200 +++ /var/tmp/diff_new_pack.RZ1Jsd/_new 2026-09-28 10:38:09.322099391 +0200 @@ -259,6 +259,7 @@ Patch55: 0015-Change-native-comp-async-jobs-number-default-to-1.patch Patch56: 0016-Change-native-comp-async-report-warnings-errors-to-s.patch Patch57: emacs-30.2-fix-zoom.patch +Patch58: bsc1282390.patch BuildRoot: %{_tmppath}/%{name}-%{version}-build %{expand: %%global include_info %(test -s /usr/share/info/info.info* && echo 0 || echo 1)} @@ -433,6 +434,7 @@ %patch -P55 -p1 %patch -P56 -p1 %patch -P57 -p1 +%patch -P58 -p1 %patch -P1 -p0 -b .xauth %if %{with memmmap} %patch -P2 -p0 -b .glibc ++++++ bsc1282390.patch ++++++ >From abc802ee2eb0b1663349ddf22a461f8e54a383fb Mon Sep 17 00:00:00 2001 From: Stefan Monnier <[email protected]> Date: Mon, 14 Sep 2026 11:30:39 +0100 Subject: [PATCH] flymake.el: Generalize trusted-content-p check to all backends Minimal safe backport of this change: Author: Stefan Monnier <[email protected]> AuthorDate: Fri Sep 11 21:48:55 2026 -0400 flymake.el: Generalize trusted-content-p check to all backends Rather than have each and every backend check 'trusted-content-p' if it feels necessary, implement the check once and forall in flymake.el and provide a wat for backends to skip that test, so we replace an "opt-in" with an "opt-out" that's a bit more secure by design. * lisp/progmodes/elisp-mode.el (elisp-flymake-byte-compile): Move 'trusted-content-p' to flymake.el. * lisp/progmodes/flymake.el (flymake--run-backend): Move 'trusted-content-p' from elisp-mode.el. * lisp/progmodes/eglot.el (eglot-flymake-backend): Mark as safe. * lisp/progmodes/flymake.el (flymake--run-backend): Copy trusted-content-p check from elisp-mode.el. Do not merge to master. --- lisp/progmodes/flymake.el | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) --- a/lisp/progmodes/flymake.el +++ b/lisp/progmodes/flymake.el 2026-09-24 09:25:30.062549983 +0000 @@ -1271,8 +1271,13 @@ with a report function." (flymake--state-disabled state) nil (flymake--state-reported-p state) nil)) (condition-case-unless-debug err - (apply backend (flymake-make-report-fn backend run-token) - args) + (if (or (trusted-content-p) (function-get backend 'flymake-always-safe)) + (apply backend (flymake-make-report-fn backend run-token) + args) + (message "Disabling %S in %s (untrusted content)" + backend (buffer-name)) + (user-error "Disabling %S in %s (untrusted content)" + backend (buffer-name))) (error (flymake--disable-backend backend err))))) --- a/test/lisp/progmodes/flymake-tests.el +++ b/test/lisp/progmodes/flymake-tests.el 2026-09-24 10:50:17.188047553 +0000 @@ -71,6 +71,7 @@ SEVERITY-PREDICATE is used to setup (warning-minimum-log-level :error)) (unwind-protect (with-current-buffer buffer + (setq-local trusted-content :all) (save-excursion (when sev-pred-supplied-p (setq-local flymake-proc-diagnostic-type-pred severity-predicate)) @@ -236,6 +237,7 @@ SEVERITY-PREDICATE is used to setup "Test many different kinds of backends." (let ((debug-on-error nil)) (with-temp-buffer + (setq-local trusted-content :all) (cl-letf (((symbol-function 'error-backend) (lambda (report-fn) @@ -318,6 +320,7 @@ SEVERITY-PREDICATE is used to setup (ert-deftest recurrent-backend () "Test a backend that calls REPORT-FN multiple times." (with-temp-buffer + (setq-local trusted-content :all) (let (tick) (cl-letf (((symbol-function 'eager-backend)
