Description
A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing multiple message bodies. During extraction, improper memory management triggers a use-after-free and double-free condition, causing the application to crash and resulting in a Denial of Service (DoS).
Published: 2026-10-01
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Update Software
AI Analysis

Impact

The flaw lies in the TNEF parsing routine get_body_files(), where improper memory management leads to a use‑after‑free and double‑free when multiple message bodies are extracted. A specially crafted TNEF file allows a remote attacker to trigger this bug, causing the application to crash and resulting in a denial of service. The vulnerability highlights a classic unsafe dereference (CWE‑416).

Affected Systems

This issue affects the tnef utility used to process TNEF files. No vendor or product version details are supplied in the advisory, so any system running an unpatched copy of tnef may be vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity attack. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation is not yet reported. Nonetheless, because the flaw can be triggered by an unauthenticated remote user providing a crafted file, the risk remains for systems that accept TNEF data from untrusted sources.

Generated by OpenCVE AI on October 1, 2026 at 12:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the tnef package to the latest version released by the vendor, which fixes the memory management issue.
  • If an update is not currently available, temporarily disable TNEF parsing or refuse TNEF attachments from untrusted sources.
  • Implement network filtering or application hardening to block or quarantine malformed TNEF files before they reach the parsing engine.

Generated by OpenCVE AI on October 1, 2026 at 12:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing multiple message bodies. During extraction, improper memory management triggers a use-after-free and double-free condition, causing the application to crash and resulting in a Denial of Service (DoS).
Title Tnef: use-after-free and double-free in get_body_files() via multi-value body extraction
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-10-01T11:34:50.120Z

Reserved: 2026-10-01T09:06:43.923Z

Link: CVE-2026-103679

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T12:17:15.683

Modified: 2026-10-01T12:17:15.683

Link: CVE-2026-103679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T12:30:07Z

Weaknesses