Description
A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files.
Published: 2026-10-01
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service and potential memory leakage
Action: Apply Patch
AI Analysis

Impact

The bug resides in tnef's get_rtf_data_from_buf function. When an attacker supplies a specially crafted RTF payload, the function reads past the allocated buffer. This out‑of‑bounds read can cause the program to crash, triggering a denial of service, or expose sensitive memory content in the output file.

Affected Systems

The affected component is the tnef utility used to extract or consume Microsoft Exchange MPF attachments. No specific version range is listed in the advisory, so all releases that still include the vulnerable code are potentially impacted. Systems that use tnef as part of email processing or archival should confirm their installed version.

Risk and Exploitability

The CVSS score of 5.4 points to moderate severity. The EPSS score is currently unavailable, and the vulnerability is not listed in CISA's KEV catalog. An attacker must provide a malicious RTF file that the vulnerable process consumes; if the application runs as a privileged user, the memory leak could reveal confidential data. Because the flaw is an out‑of‑bounds read, the impact is limited to denial of service or data leakage and does not allow arbitrary code execution.

Generated by OpenCVE AI on October 1, 2026 at 12:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a fixed version of tnef that includes bounds checking for RTF data.
  • If a vendor update is not yet available, restrict the size of RTF files processed or validate the buffer length before invoking get_rtf_data_from_buf().
  • Run the attachment handling component in a sandboxed environment so that a crash or memory leak cannot compromise the host system.

Generated by OpenCVE AI on October 1, 2026 at 12:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files.
Title Tnef: heap out-of-bounds read in get_rtf_data_from_buf() via uncompressed rtf mapi value
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-10-01T11:34:48.652Z

Reserved: 2026-10-01T09:06:43.922Z

Link: CVE-2026-103678

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T12:17:15.557

Modified: 2026-10-01T12:17:15.557

Link: CVE-2026-103678

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T12:30:07Z

Weaknesses