Vulnerability DatabaseCVE-2026-103678

CVE-2026-103678: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-103678 is a heap out-of-bounds read vulnerability in the tnef utility, a tool for unpacking Microsoft TNEF (Transport Neutral Encapsulation Format) email attachments. The flaw exists in the get_rtf_data_from_buf() function, which fails to validate input buffer boundaries when processing uncompressed Rich Text Format (RTF) data embedded in TNEF files. All versions up to and including tnef 1.4.18 are affected. The vulnerability was published on October 1, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) (Red Hat CVE, GitHub Advisory).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read). Specifically, the TNEF uncompressed-RTF value handler in get_rtf_data_from_buf() copies an attacker-controlled uncompr_size number of bytes from the input buffer without first verifying that the buffer actually contains that much data beyond the 16-byte value header, resulting in a heap out-of-bounds read (Red Hat Bugzilla). An attacker exploits this by crafting a malicious TNEF file with a manipulated uncompr_size field and delivering it to a victim who processes it with tnef. The issue was confirmed under AddressSanitizer; when body extraction (--save-body) is enabled, the over-read heap memory is written directly into the extracted RTF output file, enabling memory disclosure (Red Hat Bugzilla). The vulnerability requires user interaction (opening/processing the crafted file) but no authentication or special privileges (GitHub Advisory).

Impact

Successful exploitation can result in two primary outcomes: a Denial of Service (DoS) via application crash due to a segmentation fault triggered by the out-of-bounds memory read, or disclosure of sensitive heap memory contents written into extracted RTF output files when the --save-body option is used (Red Hat CVE). Leaked memory may contain cryptographic keys, personally identifiable information (PII), memory addresses useful for bypassing ASLR, or other sensitive data that could facilitate further attacks (Red Hat CVE). Integrity is not directly impacted, and there is no evidence of lateral movement potential from this vulnerability alone.

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date (Red Hat Bugzilla). The NVD SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable, requiring user interaction to trigger (Feedly). The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term, and the CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported by Julien Ahrens of RCE Security GmbH (Red Hat CVE).

Exploitation steps

  1. Craft malicious TNEF file: Create a TNEF attachment containing an uncompressed RTF MAPI value where the uncompr_size field is set to a value larger than the actual data present in the buffer beyond the 16-byte value header.
  2. Deliver the file: Send the crafted TNEF file as an email attachment (MIME type application/ms-tnef) to a target user whose mail processing pipeline uses the tnef utility for attachment extraction.
  3. Trigger processing: The victim or an automated mail processing system invokes tnef to unpack the attachment, e.g., tnef --save-body output.rtf malicious.tnef.
  4. Achieve impact: The get_rtf_data_from_buf() function reads uncompr_size bytes from the heap buffer without bounds checking, causing either a crash (DoS) or — if --save-body is active — writing over-read heap memory contents into the output RTF file, potentially exposing sensitive data (Red Hat Bugzilla, Red Hat CVE).

Indicators of compromise

  • Process: Unexpected crash or segmentation fault of the tnef process when processing email attachments; AddressSanitizer reports of heap-buffer-overflow in get_rtf_data_from_buf().
  • File System: Extracted RTF output files (e.g., from --save-body) that are unexpectedly large or contain binary/non-RTF data beyond the expected content, potentially including heap memory artifacts.
  • Logs: Mail server or mail processing logs showing tnef exiting with a non-zero status or signal (e.g., SIGSEGV) when handling specific TNEF attachments; repeated processing failures for the same attachment.
  • Network: Inbound email messages carrying application/ms-tnef attachments with anomalously structured or oversized RTF MAPI values.

Mitigation and workarounds

Red Hat has confirmed that this vulnerability does not affect any currently supported Red Hat products (Red Hat CVE). Users running tnef version 1.4.18 or earlier should monitor the tnef GitHub repository for a patched release and upgrade as soon as one becomes available. As an interim workaround, avoid using the --save-body option to prevent over-read memory from being written to output files, and consider restricting or sandboxing tnef processing of untrusted TNEF attachments. Organizations can also implement email gateway filtering to quarantine or strip application/ms-tnef attachments from untrusted senders.

Community reactions

Red Hat Product Security acknowledged the vulnerability but confirmed it does not affect any currently supported Red Hat products, noting the assessment may evolve with further analysis (Red Hat CVE). The vulnerability was reported by Julien Ahrens of RCE Security GmbH, a researcher known for responsible disclosure of memory safety issues (Red Hat CVE). No significant broader community or social media discussion has been observed at this time.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management