Bug 2542375 (CVE-2026-101016)

Summary: CVE-2026-101016 opendmarc: OpenDMARC: Improper policy enforcement via malformed DMARC record tags
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in OpenDMARC. An improper error-handling issue in the policy parser allows a remote attacker to cause incorrect policy evaluation or a denial of service (DoS). By supplying a crafted Domain-based Message Authentication, Reporting, and Conformance (DMARC) record containing malformed policy tags, an attacker can trigger unhandled parsing conditions. This failure can cause intended email authentication policies to be dropped or improperly enforced during email verification.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2542406, 2542408    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-28 09:01:33 UTC
A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_policy_parse_dmarc in the library libopendmarc/opendmarc_policy.c. The manipulation of the argument fo/rf/ri/pct/sp/adkim/aspf/rua/ruf leads to handling of exceptional conditions. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.