Bug 2457781 (CVE-2026-32178)
| Summary: | CVE-2026-32178 dotnet: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | security-response-team |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the .NET runtime (System.Net.Mail) in how email address data is parsed. Improper neutralization of special characters, specifically carriage return and line feed (CR/LF) sequences, may allow specially crafted email address input to be interpreted incorrectly. An attacker could exploit this issue to perform email spoofing by injecting additional headers or altering how the email address is processed during SMTP operations
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2458418, 2458419, 2458420, 2458421 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-04-13 08:10:36 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:8470 https://access.redhat.com/errata/RHSA-2026:8470 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:8472 https://access.redhat.com/errata/RHSA-2026:8472 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:8468 https://access.redhat.com/errata/RHSA-2026:8468 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:8467 https://access.redhat.com/errata/RHSA-2026:8467 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:8469 https://access.redhat.com/errata/RHSA-2026:8469 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:8475 https://access.redhat.com/errata/RHSA-2026:8475 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:8473 https://access.redhat.com/errata/RHSA-2026:8473 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:8471 https://access.redhat.com/errata/RHSA-2026:8471 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:8474 https://access.redhat.com/errata/RHSA-2026:8474 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:13281 https://access.redhat.com/errata/RHSA-2026:13281 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:13280 https://access.redhat.com/errata/RHSA-2026:13280 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:13283 https://access.redhat.com/errata/RHSA-2026:13283 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:13282 https://access.redhat.com/errata/RHSA-2026:13282 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:13693 https://access.redhat.com/errata/RHSA-2026:13693 |