Hi,
The following vulnerabilities were published for opendkim.
CVE-2026-100888[0]:
| A weakness has been identified in Trusted Domain Project OpenDKIM up
| to 2.11.0. This affects the function dkim_canon_selecthdrs of the
| file libopendkim/dkim-canon.c of the component DKIM Signature Header
| Selection. Executing a manipulation of the argument h can lead to
| out-of-bounds write. The attack can be executed remotely. The
| exploit has been made available to the public and could be used for
| attacks. The vendor was contacted early about this disclosure but
| did not respond in any way.
CVE-2026-100889[1]:
| A vulnerability was detected in Trusted Domain Project OpenDKIM up
| to 2.11.0. Affected is the function dkim_qp_decode of the file
| util.c of the component Decoder. The manipulation results in off-by-
| one. The attack may be performed from remote. The exploit is now
| public and may be used. The vendor was contacted early about this
| disclosure but did not respond in any way.
CVE-2026-101277[2]:
| A security flaw has been discovered in Trusted Domain Project
| OpenDKIM up to 2.11.0. The impacted element is the function
| dkim_process_set of the file dkim.c of the component Tag Tokenizer.
| Performing a manipulation results in use of less trusted source. The
| attack may be initiated remotely. The exploit has been released to
| the public and may be used for attacks. The vendor was contacted
| early about this disclosure but did not respond in any way.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-100888
https://www.cve.org/CVERecord?id=CVE-2026-100888
[1] https://security-tracker.debian.org/tracker/CVE-2026-100889
https://www.cve.org/CVERecord?id=CVE-2026-100889
[2] https://security-tracker.debian.org/tracker/CVE-2026-101277
https://www.cve.org/CVERecord?id=CVE-2026-101277
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore