CVE-2026-103678
Awaiting Analysis Awaiting Analysis - Queue

Heap-based Buffer Overflow in tnef

Vulnerability report for CVE-2026-103678, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Fedora Project

Description

A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-103678 is a vulnerability in the tnef application where an attacker can exploit a flaw by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. The issue occurs because the application fails to properly validate input buffer boundaries before copying data in the function get_rtf_data_from_buf(), leading to a heap out-of-bounds read.

Detection Guidance

Monitor for crashes in tnef when processing RTF data. Use AddressSanitizer or similar tools to detect heap out-of-bounds reads during file processing. Check logs for application failures after handling TNEF attachments.

Impact Analysis

This vulnerability can cause the application to crash, leading to a Denial of Service (DoS). It may also leak sensitive memory contents into extracted output files, potentially exposing secret values like cryptographic keys or memory addresses. If the --save-body option is enabled, the over-read memory is written into the extracted RTF output file.

Compliance Impact

This vulnerability primarily impacts confidentiality and availability by potentially exposing sensitive memory contents or crashing the application. While not explicitly linked to GDPR or HIPAA in the provided context, such flaws could lead to unauthorized data exposure or service disruptions, which may violate compliance requirements for handling personal or health data.

Mitigation Strategies

Avoid processing untrusted TNEF files. Update tnef to the latest patched version if available. Disable the --save-body option if enabled to prevent memory leaks in output files. Implement input validation for all incoming email attachments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103678. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart