CVE-2026-103679
Awaiting Analysis Awaiting Analysis - Queue

Memory Corruption in tnef via Malformed TNEF Files

Vulnerability report for CVE-2026-103679, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Fedora Project

Description

A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing multiple message bodies. During extraction, improper memory management triggers a use-after-free and double-free condition, causing the application to crash and resulting in a Denial of Service (DoS).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a use-after-free and double-free flaw in the tnef tool. A remote attacker can exploit it by sending a specially crafted TNEF file with multiple message bodies. During extraction, improper memory handling causes the application to crash, leading to a Denial of Service (DoS).

Detection Guidance

Detecting this vulnerability requires monitoring for crashes in the tnef tool when processing TNEF files. Use tools like AddressSanitizer to identify use-after-free or double-free conditions during file extraction. Check logs for application crashes after processing TNEF files with multiple message bodies.

Impact Analysis

If exploited, this vulnerability could cause the tnef application to crash, disrupting services that rely on it. While no code execution has been demonstrated, memory corruption or information leaks are possible under specific conditions.

Compliance Impact

This vulnerability causes a Denial of Service (DoS) by crashing the tnef application through memory corruption. It does not directly lead to data breaches or unauthorized access, which are primary concerns for GDPR and HIPAA compliance. However, a DoS condition could disrupt services handling sensitive data, potentially impacting availability requirements under these regulations.

Mitigation Strategies

Immediately update the tnef tool to the latest patched version. Avoid opening or processing TNEF files from untrusted sources. Implement network-level filtering to block suspicious TNEF attachments. Monitor system logs for crashes or unusual activity related to tnef processing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103679. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart