CVE-2024-30204
Emacs vulnerability analysis and mitigation

Overview

CVE-2024-30204 affects Emacs versions before 29.3, where LaTeX preview is enabled by default for e-mail attachments. The vulnerability was discovered in March 2024 and affects various versions of the Emacs text editor (NVD, Debian LTS).

Technical details

The vulnerability stems from LaTeX preview being enabled by default for email attachments with specific text/x-org mime type. The issue specifically affects GNUS and MUA clients re-using gnus libs (including notmuch and mu4e), but not rmail. The vulnerability has been assigned a CVSS 3.1 Base Score of 2.8 (LOW) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L (NVD).

Impact

When exploited, the vulnerability could allow specially designed LaTeX code to generate huge PDF or log files that may exhaust disk space, leading to a denial of service condition (Emacs Commit).

Mitigation and workarounds

The vulnerability has been fixed in Emacs 29.3 by introducing a new variable 'org--latex-preview-when-risky' that controls LaTeX preview behavior for content from untrusted sources. As a workaround for systems that cannot be upgraded, users can disable LaTeX previews by setting 'org-preview-latex-default-process' to 'verbatim' (OSS Security).

Community reactions

The security community has discussed the nature of this vulnerability extensively, with some debate about whether it should be considered separate from CVE-2024-30203. Several developers have suggested that the CVE assignments could be merged as they address related issues (OSS Security).

Additional resources


SourceThis report was generated using AI

Related Emacs vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-39331CRITICAL9.8
  • EmacsEmacs
  • emacs-common
NoYesJun 23, 2024
CVE-2025-1244HIGH8.8
  • EmacsEmacs
  • emacs-common
NoYesFeb 12, 2025
CVE-2024-53920HIGH7.8
  • EmacsEmacs
  • emacs-nox
NoYesNov 27, 2024
CVE-2024-30205HIGH7.1
  • EmacsEmacs
  • app-editors/emacs
NoYesMar 25, 2024
CVE-2024-30204LOW2.8
  • EmacsEmacs
  • emacs-doc
NoYesMar 25, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management