Bug 2537395 (CVE-2026-94184)

Summary: CVE-2026-94184 fetchmail: fetchmail: stack-based buffer overflow in NTLM authentication (fetchmail-SA-2026-01)
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: rhel-process-autobot, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-21 13:46:58 UTC
A flaw was found in fetchmail. A stack-based buffer overflow exists in the NTLM client authentication code (ntlm_helper() / buildSmbNtlmAuthResponse() in smbutil.c) when fetchmail is built with --enable-NTLM. The AddBytes macro copies data from a server-supplied NTLM Type 2 challenge into a fixed 1024-byte stack buffer without validating remaining capacity. A malicious or compromised mail server that advertises NTLM can overwrite a few dozen bytes past the buffer. Depending on compiler stack-frame layout, this may allow remote code execution; otherwise the practical impact is authentication failure or process abort under stack hardening. Affects fetchmail 5.0.8 through 6.6.6. Fixed in 6.6.7 (commit cb5be5c38471eec19e519ace0bc569176317ea92). Red Hat Enterprise Linux builds enable NTLM and ship affected versions.