Heap-Based Buffer Overflow in TNEF Affecting Red Hat Products
CVE-2026-103680

3.1LOW

Key Information:

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103680?

A vulnerability has been identified in the TNEF product associated with a heap-based buffer overflow in the find_free_number() function. When number backup suffixes are enabled and file overwriting is disabled, an attacker can exploit this flaw by sending a specially crafted TNEF file containing an excessive number of colliding attachment filenames. This could lead to the numeric counter writing past the allocated buffer, resulting in application crashes that may cause Denial of Service and potential arbitrary code execution.

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Julien Ahrens (RCE Security GmbH) for reporting this issue.
.