Sceawere

Vulnerability Detail

CVE-2026-100888UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenDKIM Out-of-Bounds Write Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
8h ago
Vendor
Trusted Domain Project
Product
OpenDKIM
Attack Type
Out-of-bounds Write
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature Header Selection. Executing a manipulation of the argument h can lead to out-of-bounds write. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-09-28T00:16:32.473Z",
  "pubdate": "2026-09-28T00:16:32.473Z",
  "executiveSummary": "A critical out-of-bounds write vulnerability exists in Trusted Domain Project OpenDKIM up to version 2.11.0. The flaw resides within the dkim_canon_selecthdrs function located in libopendkim/dkim-canon.c, which handles DKIM signature header selection.\nThis vulnerability is classified as an out-of-bounds write, potentially allowing for remote code execution or application crashes. The vulnerability is triggered by malicious manipulation of the 'h' argument during the canonicalization process.\nThe issue poses significant risk as the exploit is publicly available, allowing unauthenticated remote attackers to target systems running affected versions of OpenDKIM. The vendor has not provided a response or a patch for this disclosure, leaving affected installations exposed to potential exploitation.\nImpact includes the compromise of integrity, availability, and potentially confidentiality, as an out-of-bounds write can lead to heap corruption or the overwriting of critical memory structures.",
  "technicalDetails": "The vulnerability is located in the libopendkim/dkim-canon.c file within the function dkim_canon_selecthdrs. This component is responsible for selecting the headers that must be included in the DKIM signature process, a critical step in verifying email authenticity. The flaw originates from improper input validation of the 'h' argument (the header list), which defines how headers are processed and canonicalized.\nThe root cause is an out-of-bounds write condition where the application fails to adequately bounds-check the input 'h' argument before performing memory operations. When a specially crafted 'h' argument is supplied, the internal logic in dkim_canon_selecthdrs potentially accesses memory outside the intended buffer boundaries. This occurs because the function does not properly validate the length or structure of the headers against the allocated heap space.\nThe attack flow begins with a remote actor transmitting an email containing a maliciously crafted DKIM header field or a sequence that interacts with the dkim_canon_selecthdrs function. Upon receipt, the OpenDKIM library attempts to canonicalize the headers according to the instructions provided in the 'h' tag. During this execution, the logic error allows for a buffer overflow or an arbitrary write to memory.\nBecause the function is reached during the standard DKIM verification pipeline, no special authentication is required for an attacker to trigger the vulnerability. The attack is executable remotely, as the library processes incoming email traffic. Successful exploitation results in memory corruption, which can be leveraged to divert program execution flow by overwriting return addresses or function pointers stored on the heap or stack.\nThe vulnerable component remains the header selection logic, which is a core feature of the library. Given that OpenDKIM is widely utilized in mail transfer agents (MTAs) such as Sendmail and Postfix to implement DomainKeys Identified Mail, the impact extends to the security of the mail infrastructure itself. An attacker could potentially achieve remote code execution (RCE) with the privileges of the user running the mail service, leading to full system compromise or unauthorized interception and modification of electronic communications.\nPost-exploitation, an attacker could maintain persistence within the mail server environment, bypass signature validation mechanisms, or intercept sensitive communications. Because the vendor has provided no response, manual memory protections, rigorous monitoring, and ingress filtering are currently the only available defense vectors."
}
CVE-2026-100888: OpenDKIM Out-of-Bounds Write Vulnerability (HIGH Severity, CVSS: 7.3) | Sceawere