Skip to content
Red HatCVE-2026-79992

Red Hat Emacs TRAMP. A local attacker: code execution

High7.8CVE-2026-79992 · Published Aug 25, 2026 · updated Aug 28, 2026

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Enterprise Linux: type confusion
Medium5.7Aug 25
Red Hat Enterprise Linux: stack buffer overflow
High7.6Aug 25
Red Hat file-xwd plugin: out-of-bounds read
Medium4.4Aug 25
An algorithmic complexity flaw exists in libsoup's HTTP Range header processing
Medium5.3Aug 25
Red Hat Ansible Automation Platform 2: server-side request forgery
Medium6.4Aug 25
Red Hat sos clean: path traversal
High7.8Aug 25

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.