#1148731 fetchmal: CVE-2026-94184

Package:
src:fetchmail
Source:
src:fetchmail
Submitter:
Salvatore Bonaccorso
Date:
2026-09-23 20:41:02 UTC
Severity:
normal
Tags:
#1148731#5
Date:
2026-09-22 18:42:45 UTC
From:
To:
Hi,

The following vulnerability was published for fetchmail.

CVE-2026-94184[0]:
| A stack-based buffer overflow flaw was found in fetchmail when built
| with NTLM support. A malicious or compromised mail server
| advertising NTLM authentication can send a crafted Type 2 challenge
| that causes fetchmail to write past a fixed stack buffer while
| building the NTLM authenticate response. This may lead to remote
| code execution depending on stack-frame layout, or to authentication
| failure or process termination under memory hardening.  Affects
| v5.0.8 through v6.6.6.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-94184
https://www.cve.org/CVERecord?id=CVE-2026-94184
[1] https://www.fetchmail.info/fetchmail-SA-2026-01.txt
[2] https://gitlab.com/fetchmail/fetchmail/-/commit/cb5be5c38471eec19e519ace0bc569176317ea92

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1148731#10
Date:
2026-09-23 00:48:08 UTC
From:
To:
title 1148731 fetchmail: CVE-2026-94184 fixes NTLM authentication
found 1148731 6.6.6
fixed 1148731 6.6.8
thanks

I had already released fetchmail 6.6.7 to fix this bug but its shipping
text files "NEWS" and "fetchmail-SA-2026-01.txt" are misleading in that
version.
* Please skip 6.6.7
* upgrade to 6.6.8, which also adds the sr translation to the install
and adds a new zh_TW translation, too.
* to assist sizeof(long)==4 aka 32-bit platforms, you may also want to
cherry-pick
https://gitlab.com/fetchmail/fetchmail/-/commit/d2480f3d5698c2fc891070554650514097194b4d
to fix two minor glitches, one of them can however crash a self-test.

Am 22.09.26 um 20:42 schrieb Salvatore Bonaccorso:

#1148731#23
Date:
2026-09-23 19:35:10 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
fetchmail, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1148731@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Laszlo Boszormenyi (GCS) <gcs@debian.org> (supplier of updated fetchmail package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 23 Sep 2026 20:31:01 +0200
Source: fetchmail
Architecture: source
Version: 6.6.8-1
Distribution: unstable
Urgency: high
Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Changed-By: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Closes: 1148731
Changes:
 fetchmail (6.6.8-1) unstable; urgency=high
 .
   * New upstream release:
     - fix CVE-2026-94184: stack-based buffer overflow when built with NTLM
       support (closes: #1148731).
   * Update watch file.
Checksums-Sha1:
 88b6292cdac9962055405381d3a33e6cf2825885 2180 fetchmail_6.6.8-1.dsc
 9f3bef8a31342a2a62ff8e3f587ffdefb9315174 1130232 fetchmail_6.6.8.orig.tar.xz
 752bf693adb2d2da38411b8e3f048b0389f9059f 833 fetchmail_6.6.8.orig.tar.xz.asc
 463afa8835fe49b3472bdd9ec8d12273a6e673c9 52024 fetchmail_6.6.8-1.debian.tar.xz
Checksums-Sha256:
 3e76de9077a8024ff424972c6640dc98216924b5b8bb5e6bbcd21c1eec320cbb 2180 fetchmail_6.6.8-1.dsc
 fff279d7ffbf4d9449110f715c0deb5ff5a2b13b317914b6f2c810ea12a0b7e1 1130232 fetchmail_6.6.8.orig.tar.xz
 decb25dbfda9365f3af9e998305a1966561f82b807eecf264142f1172cc66d1c 833 fetchmail_6.6.8.orig.tar.xz.asc
 d054d99989fb94fdaca377f76f7fadac97f0ce72e5223ac91453120a3ea954dc 52024 fetchmail_6.6.8-1.debian.tar.xz
Files:
 c42c5b2ed7af904ffb792c7cd601fb4b 2180 mail optional fetchmail_6.6.8-1.dsc
 56f950f2b82e471895423afee50b326a 1130232 mail optional fetchmail_6.6.8.orig.tar.xz
 aebf5189b102b291a924f648e12dc984 833 mail optional fetchmail_6.6.8.orig.tar.xz.asc
 eff8115047f7c5486a121a9996e8c7b1 52024 mail optional fetchmail_6.6.8-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAmq0IqQACgkQ3OMQ54ZM
yL8H/RAAjYcWv8l6Qb221cyjs8iqKk7d85h62vx0nvv5ztn37K7LIylRYavMFOgI
axzMKxAzyTM65bct4sclyythsIOEkTV+xFIBaQvpBfmPZvAXS88fE0Ulimu6+jHl
TRbg8MMk5S+Md+KiP43ZromDf8LlfdAl2v3u4jlHKlByV1WMqIY0oQak9NcUp/CG
1X7C21PH3EizKOadJ9MnnU4lfnlkZz5cSqjkOlYOpKnZ9PAnyWm+2gSPxIseCz3k
Gy86i4e8sbvCm/3DCj7wpZuYMU5T6yxxHStiPqKOW3xDDpqYX7Eu6eHKV25iDa4x
koXDbJV6pJM0uIlgwOeKIrkNiLDxGwu6B3yxbIy1LmqZzoGO6BAP6jtEq1D/iHXz
xW8pvGSJdzOVhNPGKx14PFZ4ooEMe1bkw6oZYuEF6lgQyOjNvk0dh5TPjU6wRJGm
VjedA+Q0nyw8+Gs7PYWgMbbyCqLjv4mHtLgmAjvj3QK16w8VuL4vr9qOQkGoI6YN
JAkAWnDZV/5M0i4thoRynaB18vC1sNRveLJ3cXAdbl5V0mg6DoAZ5+/WJZ6cCcgJ
SXBaspxZqWe+A3wGKhhOgsAp7PjXEnl3R/OWS06Gj77CH29CIQYGO6+uygEAk5xa
kguTEfdQTT4vr+oGLn/laus+TxHs6DgsbtkyRnNNCdPDKqHQQ3c=
=Jkom
-----END PGP SIGNATURE-----