Bug 2544476 (CVE-2026-103678) - CVE-2026-103678 tnef: Heap out-of-bounds read in get_rtf_data_from_buf() via uncompressed RTF MAPI value
Summary: CVE-2026-103678 tnef: Heap out-of-bounds read in get_rtf_data_from_buf() via ...
Keywords:
Status: NEW
Alias: CVE-2026-103678
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2544594
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-01 09:13 UTC by OSIDB Bzimport
Modified: 2026-10-01 11:42 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-01 09:13:12 UTC
A flaw was found in tnef. The TNEF uncompressed-RTF value handler in get_rtf_data_from_buf() copies an attacker-controlled uncompr_size number of bytes from the input buffer without validating that the buffer actually contains that much data beyond the 16-byte value header, resulting in a heap out-of-bounds read. The issue was confirmed under AddressSanitizer and can crash the process; when body extraction (--save-body) is enabled, the over-read memory is written into the extracted RTF output file.


Note You need to log in before you can comment on or make changes to this bug.