
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-103678 is a heap out-of-bounds read vulnerability in the tnef utility, a tool for unpacking Microsoft TNEF (Transport Neutral Encapsulation Format) email attachments. The flaw exists in the get_rtf_data_from_buf() function, which fails to validate input buffer boundaries when processing uncompressed Rich Text Format (RTF) data embedded in TNEF files. All versions up to and including tnef 1.4.18 are affected. The vulnerability was published on October 1, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) (Red Hat CVE, GitHub Advisory).
The root cause is classified as CWE-125 (Out-of-bounds Read). Specifically, the TNEF uncompressed-RTF value handler in get_rtf_data_from_buf() copies an attacker-controlled uncompr_size number of bytes from the input buffer without first verifying that the buffer actually contains that much data beyond the 16-byte value header, resulting in a heap out-of-bounds read (Red Hat Bugzilla). An attacker exploits this by crafting a malicious TNEF file with a manipulated uncompr_size field and delivering it to a victim who processes it with tnef. The issue was confirmed under AddressSanitizer; when body extraction (--save-body) is enabled, the over-read heap memory is written directly into the extracted RTF output file, enabling memory disclosure (Red Hat Bugzilla). The vulnerability requires user interaction (opening/processing the crafted file) but no authentication or special privileges (GitHub Advisory).
Successful exploitation can result in two primary outcomes: a Denial of Service (DoS) via application crash due to a segmentation fault triggered by the out-of-bounds memory read, or disclosure of sensitive heap memory contents written into extracted RTF output files when the --save-body option is used (Red Hat CVE). Leaked memory may contain cryptographic keys, personally identifiable information (PII), memory addresses useful for bypassing ASLR, or other sensitive data that could facilitate further attacks (Red Hat CVE). Integrity is not directly impacted, and there is no evidence of lateral movement potential from this vulnerability alone.
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date (Red Hat Bugzilla). The NVD SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable, requiring user interaction to trigger (Feedly). The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term, and the CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported by Julien Ahrens of RCE Security GmbH (Red Hat CVE).
uncompr_size field is set to a value larger than the actual data present in the buffer beyond the 16-byte value header.application/ms-tnef) to a target user whose mail processing pipeline uses the tnef utility for attachment extraction.tnef --save-body output.rtf malicious.tnef.get_rtf_data_from_buf() function reads uncompr_size bytes from the heap buffer without bounds checking, causing either a crash (DoS) or — if --save-body is active — writing over-read heap memory contents into the output RTF file, potentially exposing sensitive data (Red Hat Bugzilla, Red Hat CVE).tnef process when processing email attachments; AddressSanitizer reports of heap-buffer-overflow in get_rtf_data_from_buf().--save-body) that are unexpectedly large or contain binary/non-RTF data beyond the expected content, potentially including heap memory artifacts.application/ms-tnef attachments with anomalously structured or oversized RTF MAPI values.Red Hat has confirmed that this vulnerability does not affect any currently supported Red Hat products (Red Hat CVE). Users running tnef version 1.4.18 or earlier should monitor the tnef GitHub repository for a patched release and upgrade as soon as one becomes available. As an interim workaround, avoid using the --save-body option to prevent over-read memory from being written to output files, and consider restricting or sandboxing tnef processing of untrusted TNEF attachments. Organizations can also implement email gateway filtering to quarantine or strip application/ms-tnef attachments from untrusted senders.
Red Hat Product Security acknowledged the vulnerability but confirmed it does not affect any currently supported Red Hat products, noting the assessment may evolve with further analysis (Red Hat CVE). The vulnerability was reported by Julien Ahrens of RCE Security GmbH, a researcher known for responsible disclosure of memory safety issues (Red Hat CVE). No significant broader community or social media discussion has been observed at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."