A vulnerability was found in GNU Emacs up to 30.2. It has been rated as critical. Affected by this vulnerability is the function sfnt_read_table_directory of the file src/sfnt.c of the component Font Parser. Performing a manipulation results in uninitialized pointer.

This vulnerability is reported as CVE-2026-71394. The attack is possible to be carried out remotely. No exploit exists.

To fix this issue, it is recommended to deploy a patch.