This contains two CVE fixes, see https://www.openwall.com/lists/oss-security/2025/02/26/2
Excerpts:
** Fix shell injection vulnerability in man.el (CVE-2025-1244).
CVE-2024-53920 is further described in https://eshelyaron.com/posts/2024-11-27-emacs-aritrary-code-execution-and-how-to-avoid-it.html which offers this "TL;DR" summary:
Viewing or editing Emacs Lisp code in Emacs can run arbitrary code.
Metadata Update from @salimma: - Issue assigned to salimma - Issue tagged with: type:security
https://cbs.centos.org/koji/buildinfo?buildID=59127 https://cbs.centos.org/koji/buildinfo?buildID=59128
Metadata Update from @salimma: - Issue close_status updated to: Fixed - Issue status updated to: Closed (was: Open)
Actually fixed by -7 for el9 - the previous release was not installable as Emacs needs a newer tree-sitter
https://cbs.centos.org/koji/buildinfo?buildID=59143
See #385