Bug 2542887 (CVE-2026-101277)

Summary: CVE-2026-101277 opendkim: Trusted Domain Project OpenDKIM Tag Tokenizer dkim.c dkim_process_set less trusted source
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in OpenDKIM. A remote attacker can exploit this vulnerability by sending manipulated email authentication tags to the tag tokenizer, specifically affecting the dkim_process_set function. This flaw causes the application to rely on a less trusted source during processing, potentially compromising message verification integrity or causing a denial of service (DoS).
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2542998, 2542999    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-28 23:51:30 UTC
A security flaw has been discovered in Trusted Domain Project OpenDKIM up to 2.11.0. The impacted element is the function dkim_process_set of the file dkim.c of the component Tag Tokenizer. Performing a manipulation results in use of less trusted source. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.