#1149710 tnef: CVE-2026-103678 CVE-2026-103679 CVE-2026-103680

Package:
src:tnef
Source:
src:tnef
Submitter:
Salvatore Bonaccorso
Date:
2026-10-02 15:01:05 UTC
Severity:
normal
Tags:
#1149710#5
Date:
2026-10-02 14:46:00 UTC
From:
To:
Hi,

The following vulnerabilities were published for tnef.

CVE-2026-103678[0]:
| A flaw was found in tnef. An attacker can exploit this vulnerability
| by providing a specially crafted file containing uncompressed Rich
| Text Format (RTF) data. Because the application fails to properly
| validate input buffer boundaries before copying data in
| get_rtf_data_from_buf(), reading beyond the allocated memory occurs.
| This flaw can cause the application to crash, leading to a Denial of
| Service (DoS), or leak sensitive memory contents into extracted
| output files.


CVE-2026-103679[1]:
| A flaw was found in tnef. A remote attacker could exploit this
| vulnerability by providing a specially crafted Transport Neutral
| Encapsulation Format (TNEF) file containing multiple message bodies.
| During extraction, improper memory management triggers a use-after-
| free and double-free condition, causing the application to crash and
| resulting in a Denial of Service (DoS).


CVE-2026-103680[2]:
| A flaw was found in tnef. A heap-based buffer overflow can occur in
| the find_free_number() function when generating numbered backup
| suffixes for duplicate filenames. When numbered backups are enabled
| and file overwriting is disabled, an attacker can supply a specially
| crafted Transport Neutral Encapsulation Format (TNEF) file with an
| excessive number of colliding attachment filenames, causing the
| numeric counter to write past the allocated memory buffer. This
| issue may result in an application crash, leading to a Denial of
| Service (DoS), or potentially arbitrary code execution.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-103678
https://www.cve.org/CVERecord?id=CVE-2026-103678
[1] https://security-tracker.debian.org/tracker/CVE-2026-103679
https://www.cve.org/CVERecord?id=CVE-2026-103679
[2] https://security-tracker.debian.org/tracker/CVE-2026-103680
https://www.cve.org/CVERecord?id=CVE-2026-103680

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore