Vulnerability DatabaseCVE-2026-103680

CVE-2026-103680: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-103680 is a heap-based buffer overflow vulnerability in the find_free_number() function of the tnef (Transport Neutral Encapsulation Format) utility, affecting versions up to and including 1.4.18. The flaw occurs when generating numbered backup suffixes for duplicate filenames: the function allocates a fixed-size buffer sized for a 5-digit numeric suffix but uses an unbounded sprintf(), allowing a crafted TNEF file with ~100,000 colliding attachment filenames to overflow the heap buffer. It was disclosed on October 1, 2026, and carries a CVSS v3.1 base score of 3.1 (Low) (Red Hat CVE, Github Advisory). The vulnerability was reported by Julien Ahrens of RCE Security GmbH (Red Hat CVE).

Technical details

The root cause is an out-of-bounds write (CWE-787) in find_free_number() within the tnef source code. The function allocates a heap buffer sized for a 5-digit numeric suffix (up to 99,999) but formats the counter using an unbounded sprintf() call; when the counter reaches six digits (≥100,000), it writes past the end of the allocated buffer. Exploitation requires two non-default conditions to be met simultaneously: the --number-backups option must be enabled and file overwriting must be disabled. An attacker must supply a specially crafted TNEF file containing an excessive number of attachments sharing the same filename to force the counter overflow (Red Hat Bugzilla, Red Hat CVE).

Impact

Successful exploitation can result in an application crash causing a Denial of Service (DoS), or potentially arbitrary code execution if an attacker can control heap layout sufficiently to redirect execution flow. Confidentiality and integrity impacts are rated as none in the current CVSS assessment, with availability impact rated low, reflecting that the most likely outcome is a crash rather than full system compromise. The scope is limited to the tnef process itself, with no lateral movement potential inherent to the vulnerability (Red Hat CVE, Github Advisory).

Exploitability

As of the disclosure date, there are no known public proof-of-concept exploits, no evidence of in-the-wild exploitation, and no threat actor attribution (Red Hat CVE). The EPSS score is 0.0, indicating a very low probability of exploitation in the near term (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is further constrained by the requirement for non-default command-line options (--number-backups with overwrite disabled) and a large, specially crafted input file (Red Hat Bugzilla).

Exploitation steps

  1. Reconnaissance: Identify systems or automated pipelines (e.g., email gateways, mail clients) that process TNEF attachments using the tnef utility version ≤ 1.4.18 with the --number-backups flag enabled and overwrite disabled.
  2. Craft malicious TNEF file: Construct a TNEF archive containing approximately 100,000 or more attachments that all share the same filename, forcing the find_free_number() counter to exceed five digits.
  3. Deliver the file: Send the crafted TNEF file as an email attachment (MIME type application/ms-tnef) to a target whose mail processing pipeline invokes tnef with the vulnerable options.
  4. Trigger the overflow: When tnef processes the file, find_free_number() attempts to generate a six-digit backup suffix, writing past the end of the fixed-size heap buffer, causing a crash (DoS) or potentially corrupting heap metadata for code execution (Red Hat Bugzilla, Red Hat CVE).

Indicators of compromise

  • Process: Unexpected crash or segmentation fault of the tnef process, particularly when processing email attachments with many identically named files.
  • Logs: System logs (e.g., /var/log/syslog, /var/log/mail.log) showing tnef process termination with signals such as SIGSEGV or SIGABRT during TNEF file extraction.
  • File System: Presence of a large number of numbered backup files (e.g., attachment.1, attachment.2, ...) in the tnef extraction directory, potentially reaching or exceeding 99,999 copies of the same filename.
  • Network: Receipt of unusually large TNEF email attachments (application/ms-tnef) containing an abnormally high number of embedded files with identical names.

Mitigation and workarounds

Users should avoid invoking tnef with the --number-backups option when processing untrusted TNEF files, as this non-default option is required to trigger the vulnerability. As a configuration-level workaround, ensure that automated mail processing pipelines do not use the --number-backups flag. A patch has been tracked via Red Hat Bugzilla (Bug 2544478); users should monitor the upstream tnef repository at github.com/verdammelt/tnef for a fixed release beyond version 1.4.18 and apply it when available. Red Hat has confirmed this vulnerability does not affect any currently supported Red Hat products (Red Hat CVE, Red Hat Bugzilla).

Community reactions

Red Hat Product Security confirmed that this vulnerability does not affect any currently supported Red Hat product, though they maintain a record of the CVE for transparency (Red Hat CVE). The vulnerability was reported by Julien Ahrens of RCE Security GmbH, credited in the Red Hat advisory. No significant broader community discussion or media coverage has been identified at this time.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management