
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-103680 is a heap-based buffer overflow vulnerability in the find_free_number() function of the tnef (Transport Neutral Encapsulation Format) utility, affecting versions up to and including 1.4.18. The flaw occurs when generating numbered backup suffixes for duplicate filenames: the function allocates a fixed-size buffer sized for a 5-digit numeric suffix but uses an unbounded sprintf(), allowing a crafted TNEF file with ~100,000 colliding attachment filenames to overflow the heap buffer. It was disclosed on October 1, 2026, and carries a CVSS v3.1 base score of 3.1 (Low) (Red Hat CVE, Github Advisory). The vulnerability was reported by Julien Ahrens of RCE Security GmbH (Red Hat CVE).
The root cause is an out-of-bounds write (CWE-787) in find_free_number() within the tnef source code. The function allocates a heap buffer sized for a 5-digit numeric suffix (up to 99,999) but formats the counter using an unbounded sprintf() call; when the counter reaches six digits (≥100,000), it writes past the end of the allocated buffer. Exploitation requires two non-default conditions to be met simultaneously: the --number-backups option must be enabled and file overwriting must be disabled. An attacker must supply a specially crafted TNEF file containing an excessive number of attachments sharing the same filename to force the counter overflow (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation can result in an application crash causing a Denial of Service (DoS), or potentially arbitrary code execution if an attacker can control heap layout sufficiently to redirect execution flow. Confidentiality and integrity impacts are rated as none in the current CVSS assessment, with availability impact rated low, reflecting that the most likely outcome is a crash rather than full system compromise. The scope is limited to the tnef process itself, with no lateral movement potential inherent to the vulnerability (Red Hat CVE, Github Advisory).
As of the disclosure date, there are no known public proof-of-concept exploits, no evidence of in-the-wild exploitation, and no threat actor attribution (Red Hat CVE). The EPSS score is 0.0, indicating a very low probability of exploitation in the near term (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is further constrained by the requirement for non-default command-line options (--number-backups with overwrite disabled) and a large, specially crafted input file (Red Hat Bugzilla).
--number-backups flag enabled and overwrite disabled.find_free_number() counter to exceed five digits.application/ms-tnef) to a target whose mail processing pipeline invokes tnef with the vulnerable options.find_free_number() attempts to generate a six-digit backup suffix, writing past the end of the fixed-size heap buffer, causing a crash (DoS) or potentially corrupting heap metadata for code execution (Red Hat Bugzilla, Red Hat CVE).tnef process, particularly when processing email attachments with many identically named files./var/log/syslog, /var/log/mail.log) showing tnef process termination with signals such as SIGSEGV or SIGABRT during TNEF file extraction.attachment.1, attachment.2, ...) in the tnef extraction directory, potentially reaching or exceeding 99,999 copies of the same filename.application/ms-tnef) containing an abnormally high number of embedded files with identical names.Users should avoid invoking tnef with the --number-backups option when processing untrusted TNEF files, as this non-default option is required to trigger the vulnerability. As a configuration-level workaround, ensure that automated mail processing pipelines do not use the --number-backups flag. A patch has been tracked via Red Hat Bugzilla (Bug 2544478); users should monitor the upstream tnef repository at github.com/verdammelt/tnef for a fixed release beyond version 1.4.18 and apply it when available. Red Hat has confirmed this vulnerability does not affect any currently supported Red Hat products (Red Hat CVE, Red Hat Bugzilla).
Red Hat Product Security confirmed that this vulnerability does not affect any currently supported Red Hat product, though they maintain a record of the CVE for transparency (Red Hat CVE). The vulnerability was reported by Julien Ahrens of RCE Security GmbH, credited in the Red Hat advisory. No significant broader community discussion or media coverage has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."