Sceawere

Vulnerability Detail

CVE-2026-100889UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenDKIM Off-by-One Memory Corruption

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
8h ago
Vendor
Trusted Domain Project
Product
OpenDKIM
Attack Type
Off-by-One
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-09-28T00:16:32.647Z",
  "pubdate": "2026-09-28T00:16:32.647Z",
  "executiveSummary": "A critical off-by-one vulnerability exists within the dkim_qp_decode function of the Trusted Domain Project OpenDKIM library, affecting all versions up to 2.11.0.\nThe vulnerability resides in the component responsible for decoding Quoted-Printable (QP) encoded data, specifically within the util.c source file.\nThis memory corruption flaw is remotely exploitable and allows an attacker to trigger an out-of-bounds write operation, potentially leading to unauthorized memory modification or process instability.\nGiven that OpenDKIM is widely utilized for verifying DomainKeys Identified Mail (DKIM) signatures in email infrastructure, this vulnerability carries significant risk by potentially allowing attackers to bypass security checks or execute arbitrary code if exploitation primitives are stabilized.\nThe vulnerability does not require prior authentication, and since the exploit is publicly available, the risk of active exploitation is elevated.\nThe vendor has been notified but failed to provide a response or official resolution to address this security defect.",
  "technicalDetails": "The vulnerability manifests as an off-by-one error during the processing of Quoted-Printable (QP) encoded data within the dkim_qp_decode function located in util.c.\nQuoted-Printable encoding uses the '=' character as an escape sequence, followed by two hexadecimal digits representing the character's ASCII value. The dkim_qp_decode function iterates through input buffers to normalize these sequences into raw octets.\nThe root cause of the flaw is an improper bounds check on the target destination buffer or the input stream pointer during the decoding cycle. When the function processes specific malicious sequences, it fails to account for the termination condition or buffer size boundaries, resulting in a write operation that exceeds the allocated memory segment by exactly one byte.\nIn terms of attack flow, an attacker provides a crafted email message containing a malicious QP-encoded header or body segment. As the OpenDKIM library parses the incoming mail stream to perform DKIM verification, the dkim_qp_decode function is invoked. Upon reaching the specifically crafted sequence, the function performs an out-of-bounds write to the heap or stack, depending on the memory allocation context of the buffer.\nThis off-by-one write can be utilized to overwrite adjacent metadata or pointers stored in memory. By carefully manipulating the content preceding the buffer overflow, an attacker may achieve memory corruption that facilitates controlled redirection of execution flow or modification of critical program state variables.\nThe vulnerability is remotely exploitable because OpenDKIM processes untrusted data from external SMTP traffic. No authentication is required to initiate the attack, as the processing occurs during the standard verification phase of incoming mail. The exploit payload relies on standard SMTP delivery mechanisms, allowing for widespread remote delivery to affected mail servers.\nSuccessful exploitation depends on the underlying memory layout of the host system. While an off-by-one error is often considered a primitive for denial-of-service, in advanced exploit scenarios, it can lead to heap grooming techniques that stabilize exploitation into remote code execution. Given the public nature of the exploit, the barrier to entry for attackers is significantly lowered, necessitating immediate attention to system configuration and defense-in-depth measures."
}
CVE-2026-100889: OpenDKIM Off-by-One Memory Corruption (HIGH Severity, CVSS: 7.3) | Sceawere