Version in base suite: 30.1+1-6 Base version: emacs_30.1+1-6 Target version: emacs_30.1+1-6+deb13u1 Base file: /srv/ftp-master.debian.org/ftp/pool/main/e/emacs/emacs_30.1+1-6.dsc Target file: /srv/ftp-master.debian.org/policy/pool/main/e/emacs/emacs_30.1+1-6+deb13u1.dsc .git-dpm | 4 .gitignore | 95 -------- changelog | 34 ++ patches/0022-Mark-esh-proc-test-kill-pipeline-as-unstable-for-now.patch | 114 ++++++++++ patches/0023-src-image.c-svg_load_image-Fix-off-by-one-mistake-bu.patch | 32 ++ patches/0024-bytecomp-tests-dest-mountpoint-only-run-test-if-bwra.patch | 30 ++ patches/0025-Skip-some-proced-tests-that-appear-to-be-hanging.patch | 77 ++++++ patches/0026-Mitigate-arbitrary-code-execution-vulnerability.patch | 66 +++++ patches/series | 5 9 files changed, 360 insertions(+), 97 deletions(-) dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmpo1r3j5rb/emacs_30.1+1-6.dsc: no acceptable signature found dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmpo1r3j5rb/emacs_30.1+1-6+deb13u1.dsc: no acceptable signature found diff -Nru emacs-30.1+1/debian/.git-dpm emacs-30.1+1/debian/.git-dpm --- emacs-30.1+1/debian/.git-dpm 2025-07-18 08:58:11.000000000 +0000 +++ emacs-30.1+1/debian/.git-dpm 2026-08-21 17:22:52.000000000 +0000 @@ -1,6 +1,6 @@ # see git-dpm(1) from git-dpm package -22d6e7ad34d947c1154358cd3a59789f539a9cf5 -22d6e7ad34d947c1154358cd3a59789f539a9cf5 +78aa6b3d7ac596730066f1cc8d4c5d56925f05ac +78aa6b3d7ac596730066f1cc8d4c5d56925f05ac c512c0fa6ab117d10b0602d2b2d1fe5880695944 c512c0fa6ab117d10b0602d2b2d1fe5880695944 emacs_30.1+1.orig.tar.xz diff -Nru emacs-30.1+1/debian/.gitignore emacs-30.1+1/debian/.gitignore --- emacs-30.1+1/debian/.gitignore 2025-07-18 08:58:11.000000000 +0000 +++ emacs-30.1+1/debian/.gitignore 1970-01-01 00:00:00.000000000 +0000 @@ -1,95 +0,0 @@ -*~ -.\#* -/*-stamp -/.debhelper/ -/build-gtk/ -/build-pgtk/ -/build-lucid/ -/build-nox/ -/build-src/ -/build-x/ -/elgz-canary -/elgz-info -/emacs -/emacs-bin-common -/emacs-bin-common.README.Debian -/emacs-bin-common.debhelper.log -/emacs-bin-common.lintian-overrides -/emacs-bin-common.postinst -/emacs-bin-common.postrm -/emacs-bin-common.prerm -/emacs-bin-common.substvars -/emacs-common -/emacs-common.README.00 -/emacs-common.README.01 -/emacs-common.README.Debian -/emacs-common.debhelper.log -/emacs-common.docs -/emacs-common.links -/emacs-common.lintian-overrides -/emacs-common.postinst -/emacs-common.postinst.debhelper -/emacs-common.postrm.debhelper -/emacs-common.prerm -/emacs-common.prerm.debhelper -/emacs-common.substvars -/emacs-el -/emacs-el.debhelper.log -/emacs-el.prerm -/emacs-el.substvars -/emacs-gtk -/emacs-gtk.README.Debian -/emacs-gtk.debhelper.log -/emacs-gtk.desktop -/emacs-gtk.links -/emacs-gtk.lintian-overrides -/emacs-gtk.menu -/emacs-gtk.postinst -/emacs-gtk.postinst.debhelper -/emacs-gtk.postrm -/emacs-gtk.postrm.debhelper -/emacs-gtk.prerm -/emacs-gtk.substvars -/emacs-pgtk -/emacs-pgtk.README.Debian -/emacs-pgtk.debhelper.log -/emacs-pgtk.desktop -/emacs-pgtk.links -/emacs-pgtk.lintian-overrides -/emacs-pgtk.menu -/emacs-pgtk.postinst -/emacs-pgtk.postinst.debhelper -/emacs-pgtk.postrm -/emacs-pgtk.postrm.debhelper -/emacs-pgtk.prerm -/emacs-pgtk.substvars -/emacs-lucid -/emacs-lucid.README.Debian -/emacs-lucid.debhelper.log -/emacs-lucid.desktop -/emacs-lucid.lintian-overrides -/emacs-lucid.menu -/emacs-lucid.postinst -/emacs-lucid.postinst.debhelper -/emacs-lucid.postrm.debhelper -/emacs-lucid.prerm -/emacs-lucid.substvars -/emacs-nox -/emacs-nox.README.Debian -/emacs-nox.debhelper.log -/emacs-nox.desktop -/emacs-nox.links -/emacs-nox.lintian-overrides -/emacs-nox.menu -/emacs-nox.postinst -/emacs-nox.postinst.debhelper -/emacs-nox.postrm -/emacs-nox.postrm.debhelper -/emacs-nox.prerm -/emacs-nox.substvars -/emacs.debhelper.log -/emacs.substvars -/files -/stamp-configured -/tmp-alt-list -\#*\# diff -Nru emacs-30.1+1/debian/changelog emacs-30.1+1/debian/changelog --- emacs-30.1+1/debian/changelog 2025-07-18 08:58:11.000000000 +0000 +++ emacs-30.1+1/debian/changelog 2026-08-21 17:24:00.000000000 +0000 @@ -1,3 +1,37 @@ +emacs (1:30.1+1-6+deb13u1) trixie-security; urgency=high + + * Mark esh-proc-test/kill-pipeline as unstable for now. Skip it since + it fails sporadically on at least s390x. Add + 0024-Mark-esh-proc-test-kill-pipeline-as-unstable-for-now.patch to + address the issue. + + * Fix an SVG-related vulnerability (CVE-2026-6861). Add + 0025-src-image.c-svg_load_image-Fix-off-by-one-mistake-bu.patch which + includes the upstream patch to fix the problem. Thanks to Salvatore + Bonaccorso for reporting the issue. (Closes: 1134692) + + * Don't run bytecomp-tests--dest-mountpoint where bwrap doesn't work. + Add 0026-bytecomp-tests-dest-mountpoint-only-run-test-if-bwra.patch to + address the issue. Thanks to Santiago Vila for reporting the + issue. (Closes: 1129189) + + * Skip two more proced-tests in debian that are skipped on darwin to + avoid hanging during the tests. Add + 0025-Skip-some-proced-tests-that-appear-to-be-hanging.patch to address + the issue. + + * Mitigate a risk of executing arbitrary code when opening a file. The + vulnerability that has been mitigated could allow a specially crafted + file to trigger execution of arbitrary Emacs Lisp code immediately + upon visiting it in Emacs. The broader issue is described here: + https://debbugs.gnu.org/80574 + + Add 0030-Mitigate-arbitrary-code-execution-vulnerability.patch to + include the upstream patch addressing the problem. Thanks to Nicholas + D Steeves for reporting the issue. + + -- Rob Browning Fri, 21 Aug 2026 12:24:00 -0500 + emacs (1:30.1+1-6) unstable; urgency=medium * Add Breaks/Replaces/Provides for builtin packages in this release. diff -Nru emacs-30.1+1/debian/patches/0022-Mark-esh-proc-test-kill-pipeline-as-unstable-for-now.patch emacs-30.1+1/debian/patches/0022-Mark-esh-proc-test-kill-pipeline-as-unstable-for-now.patch --- emacs-30.1+1/debian/patches/0022-Mark-esh-proc-test-kill-pipeline-as-unstable-for-now.patch 1970-01-01 00:00:00.000000000 +0000 +++ emacs-30.1+1/debian/patches/0022-Mark-esh-proc-test-kill-pipeline-as-unstable-for-now.patch 2026-08-21 17:22:51.000000000 +0000 @@ -0,0 +1,114 @@ +From cbc6d9a13882ff9fb96a970d7ae51f28b837487f Mon Sep 17 00:00:00 2001 +From: Rob Browning +Date: Mon, 10 Nov 2025 12:20:23 -0600 +Subject: Mark esh-proc-test/kill-pipeline as unstable for now + +Currently fails on at least s390x from time to time. It doesn't take +long to reproduce via + + (set -ex; while true; do make lisp/eshell/esh-proc-tests EMACS_TEST_VERBOSE=true; done) + +from debian/build-lucid/test/. The failure looks like this: + + passed 3/24 esh-proc-test/exit-status/with-stderr-pipe (0.101971 sec) + Test esh-proc-test/kill-pipeline backtrace: + signal(ert-test-failed (((should (string-match-p (rx bos (32 (or "in + ert-fail(((should (string-match-p (rx bos (32 (or "interrupt" (seq " + (if (unwind-protect (setq value-154 (apply fn-152 args-153)) (setq f + (let (form-description-156) (if (unwind-protect (setq value-154 (app + (let ((value-154 'ert-form-evaluation-aborted-155)) (let (form-descr + (let* ((fn-152 #'string-match-p) (args-153 (condition-case err (list + (let ((output-start (eshell-beginning-of-output))) (eshell-kill-proc + (let ((ert--infos (cons (cons "Command logs: " #'eshell-get-debug-lo + (save-current-buffer (set-buffer eshell-buffer) (let ((ert--infos (c + (unwind-protect (save-current-buffer (set-buffer eshell-buffer) (let + (let ((eshell-buffer (eshell t))) (unwind-protect (save-current-buff + (let ((process-environment (cons "HISTFILE" process-environment)) (e + (progn (let ((process-environment (cons "HISTFILE" process-environme + (unwind-protect (progn (let ((process-environment (cons "HISTFILE" p + (let* ((coding-system-for-write nil) (temp-file (file-name-as-direct + (save-current-buffer (let* ((coding-system-for-write nil) (temp-file + #f(lambda () [t] (let ((value-145 (gensym "ert-form-evaluation-abort + #f(compiled-function () #)() + handler-bind-1(#f(compiled-function () # + ert--run-test-internal(#s(ert--test-execution-info :test #s(ert-test + ert-run-test(#s(ert-test :name esh-proc-test/kill-pipeline :document + ert-run-or-rerun-test(#s(ert--stats :selector ... :tests ... :test-m + ert-run-tests((not (or (tag :unstable) (tag :nativecomp))) #f(compil + ert-run-tests-batch((not (or (tag :unstable) (tag :nativecomp)))) + ert-run-tests-batch-and-exit((not (or (tag :unstable) (tag :nativeco + eval((ert-run-tests-batch-and-exit '(not (or (tag :unstable) (tag :n + command-line-1(("-L" ":/home/rlb/emacs/debian/build-src/test" "-l" " + command-line() + normal-top-level() + Test esh-proc-test/kill-pipeline condition: + Command logs: command: "sh -c 'while true; do echo y; sleep 1; done' | sh -c 'while true; do read NAME; done'" + + ---------------------------------------- + [process] started external process `sh' + + /usr/bin/sh -c while\ true\;\ do\ read\ NAME\;\ done + ---------------------------------------- + [process] started external process `sh<1>' + + /usr/bin/sh -c while\ true\;\ do\ echo\ y\;\ sleep\ 1\;\ done + ---------------------------------------- + [process] received output from process `sh<1>' + + y + + ---------------------------------------- + [process] forwarding output from process `sh<1>' + + y + + ---------------------------------------- + [process] sentinel for external process `sh<1>': "killed + " + ---------------------------------------- + [process] i/o busy for process `sh<1>' + ---------------------------------------- + [process] sentinel for external process `sh-stderr': "finished + " + ---------------------------------------- + [process] finished external process `sh-stderr' + ---------------------------------------- + [process] sentinel for external process `sh': "killed + " + ---------------------------------------- + [process] finished external process `sh' + (ert-test-failed + ((should + (string-match-p (rx bos ... eos) + (buffer-substring-no-properties output-start ...))) + :form + (string-match-p "\\`\\(?:\\(?:interrupt\\|killed.*\\)\n\\)?\\'" + "/home/rlb/emacs/debian/build-lucid/test $ sh -c 'while true; do echo y; sleep 1; done' | sh -c 'while true; do read NAME; done'\n") + :value nil)) + FAILED 4/24 esh-proc-test/kill-pipeline (0.003864 sec) at ../../build-src/test/lisp/eshell/esh-proc-tests.el:300 + Error running timer: (error "Selecting deleted buffer") + passed 5/24 esh-proc-test/kill-pipeline-head (0.102912 sec) + passed 6/24 esh-proc-test/kill-process/background-prompt (0.001595 sec) + [sleep]+ Done (/usr/bin/sleep 100) + passed 7/24 esh-proc-test/kill-process/foreground-only (0.203248 sec) + passed 8/24 esh-proc-test/kill-process/redirect-message (0.001616 sec) + passed 9/24 esh-proc-test/output/remote-redirect (0.160153 sec) +--- + test/lisp/eshell/esh-proc-tests.el | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/test/lisp/eshell/esh-proc-tests.el b/test/lisp/eshell/esh-proc-tests.el +index 06a3433cb45..7fadba77f53 100644 +--- a/test/lisp/eshell/esh-proc-tests.el ++++ b/test/lisp/eshell/esh-proc-tests.el +@@ -300,6 +300,10 @@ esh-proc-test/kill-process/redirect-message + (ert-deftest esh-proc-test/kill-pipeline () + "Test that killing a pipeline of processes only emits a single + prompt. See bug#54136." ++ :tags '(:unstable) ++ ;; Sporadically fails on at least s390x. Fairly easy to see via ++ ;; (set -ex; while true; do make lisp/eshell/esh-proc-tests EMACS_TEST_VERBOSE=true; done) ++ ;; run from test/. + (skip-unless (and (executable-find "sh") + (executable-find "echo") + (executable-find "sleep"))) diff -Nru emacs-30.1+1/debian/patches/0023-src-image.c-svg_load_image-Fix-off-by-one-mistake-bu.patch emacs-30.1+1/debian/patches/0023-src-image.c-svg_load_image-Fix-off-by-one-mistake-bu.patch --- emacs-30.1+1/debian/patches/0023-src-image.c-svg_load_image-Fix-off-by-one-mistake-bu.patch 1970-01-01 00:00:00.000000000 +0000 +++ emacs-30.1+1/debian/patches/0023-src-image.c-svg_load_image-Fix-off-by-one-mistake-bu.patch 2026-08-21 17:22:51.000000000 +0000 @@ -0,0 +1,32 @@ +From 12cc80a7d1a1666195d938cf4415915a4105ea8d Mon Sep 17 00:00:00 2001 +From: Eli Zaretskii +Date: Sat, 18 Apr 2026 10:35:05 +0300 +Subject: * src/image.c (svg_load_image): Fix off-by-one mistake (bug#80851). + +Origin: upstream, commit: 8f535370b9efbc91673b20c6987a5cae4f6dc562 +Added-by: Rob Browning +Bug: https://debbugs.gnu.org/80851 +Bug-Debian: https://bugs.debian.org/1134692 +README-Debian: An SVG-related security vulnerability has been fixed (CVE-2026-6861) + This vulnerability, a memory corruption issue, could occur when Emacs + processed specially crafted SVG (Scalable Vector Graphics) + CSS (Cascading Style Sheets) data. A local user could exploit this by + convincing a victim to open a malicious SVG file, which might lead to a + denial of service (DoS) or potentially information disclosure. +--- + src/image.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/image.c b/src/image.c +index b5b7de3351f..d98c63f06c6 100644 +--- a/src/image.c ++++ b/src/image.c +@@ -12052,7 +12052,7 @@ svg_load_image (struct frame *f, struct image *img, char *contents, + { + css = xmalloc (SBYTES (lcss) + 1); + strncpy (css, SSDATA (lcss), SBYTES (lcss)); +- *(css + SBYTES (lcss) + 1) = 0; ++ *(css + SBYTES (lcss)) = 0; + } + #endif + diff -Nru emacs-30.1+1/debian/patches/0024-bytecomp-tests-dest-mountpoint-only-run-test-if-bwra.patch emacs-30.1+1/debian/patches/0024-bytecomp-tests-dest-mountpoint-only-run-test-if-bwra.patch --- emacs-30.1+1/debian/patches/0024-bytecomp-tests-dest-mountpoint-only-run-test-if-bwra.patch 1970-01-01 00:00:00.000000000 +0000 +++ emacs-30.1+1/debian/patches/0024-bytecomp-tests-dest-mountpoint-only-run-test-if-bwra.patch 2026-08-21 17:22:51.000000000 +0000 @@ -0,0 +1,30 @@ +From 1804647e0d6a9664be85ee9386c93d7e5dd9bb8e Mon Sep 17 00:00:00 2001 +From: Rob Browning +Date: Mon, 4 May 2026 18:13:34 -0500 +Subject: bytecomp-tests--dest-mountpoint: only run test if bwrap works + +Bug-Debian: https://bugs.debian.org/1129189 +Added-by: Rob Browning +README-Debian: The bytecomp-tests--dest-mountpoint should now only run + where bwrap works. + . + It doesn't, in some environments, like a Debian sbuild unshare. +--- + test/lisp/emacs-lisp/bytecomp-tests.el | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/test/lisp/emacs-lisp/bytecomp-tests.el b/test/lisp/emacs-lisp/bytecomp-tests.el +index 2bc096ff2df..20eb0022bc4 100644 +--- a/test/lisp/emacs-lisp/bytecomp-tests.el ++++ b/test/lisp/emacs-lisp/bytecomp-tests.el +@@ -1715,6 +1715,10 @@ bytecomp-tests--dest-mountpoint + (let ((bwrap (executable-find "bwrap")) + (emacs (expand-file-name invocation-name invocation-directory))) + (skip-unless bwrap) ++ ;; Check that bwrap works in the current environment. It does not ++ ;; in a debian sbuild unshare, for example. ++ (skip-unless (zerop (call-process bwrap nil t nil "--ro-bind" "/" "/" ++ "true"))) + (skip-unless (file-executable-p bwrap)) + (skip-unless (not (file-remote-p bwrap))) + (skip-unless (file-executable-p emacs)) diff -Nru emacs-30.1+1/debian/patches/0025-Skip-some-proced-tests-that-appear-to-be-hanging.patch emacs-30.1+1/debian/patches/0025-Skip-some-proced-tests-that-appear-to-be-hanging.patch --- emacs-30.1+1/debian/patches/0025-Skip-some-proced-tests-that-appear-to-be-hanging.patch 1970-01-01 00:00:00.000000000 +0000 +++ emacs-30.1+1/debian/patches/0025-Skip-some-proced-tests-that-appear-to-be-hanging.patch 2026-08-21 17:22:51.000000000 +0000 @@ -0,0 +1,77 @@ +From 275538190ff0b0a971fb302bff88e99efd4fc337 Mon Sep 17 00:00:00 2001 +From: Stefan Kangas +Date: Tue, 11 Mar 2025 01:01:33 +0100 +Subject: Skip some proced-tests that appear to be hanging + +Skip the same proced-tests that are now skipped upstream because they +were hanging on darwin, since proced-tests has been intermittently been +hanging on Debian too. Just change the skip-when criteria in the +upstream commit from 'darwin to t. + +Also skip the two tests that were already being skipped on darwin, since +proced-tests was still hanging with those enabled in Debian. + +Orign: upstream, commit: 8ea65ac642c5ae29610ef6a14f852953821dee45) +Added-by: Rob Browning +Bug: https://debbugs.gnu.org/76898 +README-Debian: Some of the proced-tests are now skipped + They were hanging on the buildds and locally, so as with darwin + upstream, we now skip them too. +--- + test/lisp/proced-tests.el | 8 ++++++-- + 1 file changed, 6 insertions(+), 2 deletions(-) + +diff --git a/test/lisp/proced-tests.el b/test/lisp/proced-tests.el +index ecf23c5d037..a6f6a1c2a62 100644 +--- a/test/lisp/proced-tests.el ++++ b/test/lisp/proced-tests.el +@@ -87,6 +87,7 @@ proced--assert-process-valid-cpu-refinement-explainer + #'proced--assert-process-valid-cpu-refinement-explainer) + + (ert-deftest proced-format-test () ++ (skip-when t) ; Bug#76898 + (dolist (format '(short medium long verbose)) + (proced--within-buffer + format +@@ -94,6 +95,7 @@ proced-format-test + (proced--assert-emacs-pid-in-buffer)))) + + (ert-deftest proced-update-test () ++ (skip-when t) ; Bug#76898 + (proced--within-buffer + 'short + 'user +@@ -101,6 +103,7 @@ proced-update-test + (proced--assert-emacs-pid-in-buffer))) + + (ert-deftest proced-revert-test () ++ (skip-when t) ; Bug#76898 + (proced--within-buffer + 'short + 'user +@@ -108,6 +111,7 @@ proced-revert-test + (proced--assert-emacs-pid-in-buffer))) + + (ert-deftest proced-color-test () ++ (skip-when t) ; Bug#76898 + (let ((proced-enable-color-flag t)) + (proced--within-buffer + 'short +@@ -116,7 +120,7 @@ proced-color-test + + (ert-deftest proced-refine-test () + ;; %CPU is not implemented on macOS +- (skip-when (eq system-type 'darwin)) ++ (skip-when t) + (proced--within-buffer + 'verbose + 'user +@@ -130,7 +134,7 @@ proced-refine-test + (forward-line))))) + + (ert-deftest proced-refine-with-update-test () +- (skip-when (eq system-type 'darwin)) ++ (skip-when t) + (proced--within-buffer + 'verbose + 'user diff -Nru emacs-30.1+1/debian/patches/0026-Mitigate-arbitrary-code-execution-vulnerability.patch emacs-30.1+1/debian/patches/0026-Mitigate-arbitrary-code-execution-vulnerability.patch --- emacs-30.1+1/debian/patches/0026-Mitigate-arbitrary-code-execution-vulnerability.patch 1970-01-01 00:00:00.000000000 +0000 +++ emacs-30.1+1/debian/patches/0026-Mitigate-arbitrary-code-execution-vulnerability.patch 2026-08-21 17:22:52.000000000 +0000 @@ -0,0 +1,66 @@ +From 78aa6b3d7ac596730066f1cc8d4c5d56925f05ac Mon Sep 17 00:00:00 2001 +From: Eshel Yaron +Date: Wed, 5 Aug 2026 19:58:32 +0200 +Subject: Mitigate arbitrary code execution vulnerability + +This mitigates a vulnerability that allowed a specially +crafted file to trigger execution of attacker-controlled +arbitrary Emacs Lisp code immediately when the file is +visited in Emacs (before the file's malicious contents are +even displayed). See demonstration in bug#80574. + +* lisp/progmodes/cc-fonts.el (c-compose-keywords-list): +* lisp/vc/vc-hooks.el (vc-find-backend-function): +Nullify 'read-symbol-shorthands' around risky 'intern' calls. +Do not merge to master. + +Orign: upstream, commit: 8466eb44991707d128110bdc549fad14c8e1d61e +Added-by: Rob Browning +Bug: https://debbugs.gnu.org/80574 +README-Debian: Opening a file should have less risk of executing arbirary code + The vulnerability that has been mitigated could allow a specially + crafted file to trigger execution of attacker-controlled arbitrary + Emacs Lisp code immediately when the file is visited in Emacs. The + broader issue is described here: https://debbugs.gnu.org/80574 +--- + lisp/progmodes/cc-fonts.el | 10 +++++++--- + lisp/vc/vc-hooks.el | 5 ++++- + 2 files changed, 11 insertions(+), 4 deletions(-) + +diff --git a/lisp/progmodes/cc-fonts.el b/lisp/progmodes/cc-fonts.el +index 7426a348fe7..145290c281a 100644 +--- a/lisp/progmodes/cc-fonts.el ++++ b/lisp/progmodes/cc-fonts.el +@@ -2566,9 +2566,13 @@ c-compose-keywords-list + (let* ((doc-keywords (c-get-doc-comment-style)) + (list (nconc (c--mapcan + (lambda (doc-style) +- (let ((sym (intern +- (concat (symbol-name doc-style) +- "-font-lock-keywords")))) ++ (let ((sym ++ ;; Guard `intern' from potentially ++ ;; malicious shorthands. ++ (let (read-symbol-shorthands) ++ (intern ++ (concat (symbol-name doc-style) ++ "-font-lock-keywords"))))) + (cond ((fboundp sym) + (funcall sym)) + ((boundp sym) +diff --git a/lisp/vc/vc-hooks.el b/lisp/vc/vc-hooks.el +index a453980ca6e..3434c689441 100644 +--- a/lisp/vc/vc-hooks.el ++++ b/lisp/vc/vc-hooks.el +@@ -234,7 +234,10 @@ vc-find-backend-function + "Return BACKEND-specific implementation of FUN. + If there is no such implementation, return the default implementation; + if that doesn't exist either, return nil." +- (let ((f (vc-make-backend-sym backend fun))) ++ ;; Nullify `read-symbol-shorthands' to guard the `intern' calls below ++ ;; and in `vc-make-backend-sym' from potentially malicious shorthands. ++ (let* ((read-symbol-shorthands nil) ++ (f (vc-make-backend-sym backend fun))) + (if (fboundp f) f + ;; Load vc-BACKEND.el if needed. + (require (intern (concat "vc-" (downcase (symbol-name backend))))) diff -Nru emacs-30.1+1/debian/patches/series emacs-30.1+1/debian/patches/series --- emacs-30.1+1/debian/patches/series 2025-07-18 08:58:11.000000000 +0000 +++ emacs-30.1+1/debian/patches/series 2026-08-21 17:22:52.000000000 +0000 @@ -19,3 +19,8 @@ 0019-Boost-BASE_PURESIZE-in-attempt-to-fix-build-on-32-bi.patch 0020-Disable-server-tests-server-force-stop-keeps-frames-.patch 0021-Disable-emacs-module-tests.el.patch +0022-Mark-esh-proc-test-kill-pipeline-as-unstable-for-now.patch +0023-src-image.c-svg_load_image-Fix-off-by-one-mistake-bu.patch +0024-bytecomp-tests-dest-mountpoint-only-run-test-if-bwra.patch +0025-Skip-some-proced-tests-that-appear-to-be-hanging.patch +0026-Mitigate-arbitrary-code-execution-vulnerability.patch