Impact
A flaw has been reported in the Trusted Domain Project OpenDMARC up to version 1.4.2. The vulnerability resides in the function opendmarc_spf_ipv6_explode within the SPF Parser component. The function manipulates the argument cp without proper null‑pointer checks, which leads to a dereference of a null pointer. The effect of this error is that an attacker who can supply crafted input may cause unintended code paths or system crashes, providing an opportunity for remote code execution or denial of service. The weakness is a classic null‑pointer dereference (CWE‑476) as well as an improper resource cleanup (CWE‑404).
Affected Systems
The affected product is Trusted Domain Project OpenDMARC, specifically any release up to and including 1.4.2. Systems running these versions of OpenDMARC that process SPF records—common in mail server stacks such as Postfix, Exim, or Microsoft Exchange when using OpenDMARC for DMARC/SPF checks—are vulnerable. The exact CPE string for the product is cpe:2.3:a:trusted_domain_project:opendmarc:*:*:*:*:*:*:*.*
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity vulnerability. The EPSS score is not available, so the likelihood of exploitation cannot be quantified from the public data. However, the advisory notes that an exploit has been published and is likely deployable, so the risk to exposed systems is significant. No listing in the CISA KEV catalog does not reduce the importance of applying a patch. The attack vector is inferred to be remote, as the description states the flaw can be triggered remotely through malformed SPF input. The typical exploitation path would involve an attacker crafting a malicious SPF query that causes the OpenDMARC library to dereference a null pointer within the SPF IPv6 handling routine.
OpenCVE Enrichment