Heap-Based Buffer Overflow in TNEF Affecting Red Hat Products
CVE-2026-103680
3.1LOW
What is CVE-2026-103680?
A vulnerability has been identified in the TNEF product associated with a heap-based buffer overflow in the find_free_number() function. When number backup suffixes are enabled and file overwriting is disabled, an attacker can exploit this flaw by sending a specially crafted TNEF file containing an excessive number of colliding attachment filenames. This could lead to the numeric counter writing past the allocated buffer, resulting in application crashes that may cause Denial of Service and potential arbitrary code execution.
References
CVSS V3.1
Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Julien Ahrens (RCE Security GmbH) for reporting this issue.
