CVE-2026-103680
Awaiting Analysis Awaiting Analysis - Queue

Heap-based Buffer Overflow in tnef

Vulnerability report for CVE-2026-103680, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Fedora Project

Description

A flaw was found in tnef. A heap-based buffer overflow can occur in the find_free_number() function when generating numbered backup suffixes for duplicate filenames. When numbered backups are enabled and file overwriting is disabled, an attacker can supply a specially crafted Transport Neutral Encapsulation Format (TNEF) file with an excessive number of colliding attachment filenames, causing the numeric counter to write past the allocated memory buffer. This issue may result in an application crash, leading to a Denial of Service (DoS), or potentially arbitrary code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a heap-based buffer overflow in the tnef utility's find_free_number() function. It occurs when numbered backups are enabled and file overwriting is disabled. An attacker can exploit it by providing a specially crafted TNEF file with many duplicate filenames, causing the numeric counter to exceed the allocated buffer and write past it. This may crash the application or potentially allow arbitrary code execution.

Detection Guidance

To detect this vulnerability, check if the tnef utility is installed and if the --number-backups option is enabled in your system. Examine logs for crashes or unusual behavior when processing TNEF files with duplicate attachments. No specific commands are provided in the resources, but monitoring for application crashes during TNEF processing may indicate exploitation.

Impact Analysis

The impact includes application crashes leading to Denial of Service (DoS) or potential arbitrary code execution. Exploitation requires specific non-default settings and a large malicious input, making it less likely in typical environments.

Compliance Impact

This vulnerability primarily causes application crashes or potential arbitrary code execution, which could lead to data corruption or loss. However, the provided context does not specify direct impacts on compliance with GDPR or HIPAA. The vulnerability requires specific non-default settings and large malicious input to exploit, reducing the likelihood of real-world compliance violations.

Mitigation Strategies

Disable the --number-backups option in tnef if enabled. Avoid processing untrusted TNEF files. Update tnef to the latest patched version if available. Since Red Hat states this does not affect supported products, focus on updating or removing vulnerable installations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103680. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart