Sceawere

Vulnerability Detail

CVE-2026-100890UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenDMARC Null Pointer Dereference

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
7h ago
Vendor
Trusted Domain Project
Product
OpenDMARC
Attack Type
NULL Pointer Dereference
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the component SPF Parser. This manipulation of the argument cp causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-28T01:16:28.047Z",
  "pubdate": "2026-09-28T01:16:28.047Z",
  "executiveSummary": "A critical vulnerability has been identified in the Trusted Domain Project OpenDMARC library, specifically within the SPF parsing logic. This vulnerability is classified as a null pointer dereference, occurring within the opendmarc_spf_ipv6_explode function located in libopendmarc/opendmarc_spf.c.\nThe flaw affects all versions of OpenDMARC up to and including 1.4.2. Successful exploitation allows a remote, unauthenticated attacker to trigger a crash in the affected process, leading to a Denial of Service (DoS) condition.\nGiven that OpenDMARC is commonly deployed as a mail filter or MTA plugin, exploiting this vulnerability can disrupt legitimate email processing services for the entire mail server, effectively silencing DMARC validation for incoming traffic. As exploit code is publicly available and the vendor has remained unresponsive, the risk to production environments is elevated. No specific privileges or authentication are required to trigger the crash, as the vulnerability is exposed through the processing of maliciously crafted SPF records.",
  "technicalDetails": "The vulnerability resides in the opendmarc_spf_ipv6_explode function within libopendmarc/opendmarc_spf.c. The root cause of this issue is an improper handling of input data provided to the argument 'cp'. Specifically, the function fails to perform adequate validation or null-pointer checks before attempting to dereference the pointer provided during the parsing of IPv6-related SPF components.\nThe attack flow begins when an attacker sends an email or triggers a network event that forces the OpenDMARC parser to evaluate a specifically crafted SPF record. When the SPF parser component processes this record, it invokes opendmarc_spf_ipv6_explode. Due to the lack of input sanitization or validation of the 'cp' pointer, the function attempts to access memory at a null address. This results in an immediate segmentation fault, terminating the process responsible for mail filtering.\nThe vulnerable component is the SPF parser logic embedded within the libopendmarc library. Because the parsing of SPF records is a routine task for MTAs (Mail Transfer Agents) utilizing OpenDMARC to verify sender identity, an attacker can trigger this flaw by simply initiating an SMTP transaction that causes an SPF lookup. The vulnerability is remotely exploitable, requiring no prior authentication or administrative privileges to execute the payload. The 'payload' in this context is the malicious SPF record itself, which does not need to be complex; it merely needs to be structured in a way that leads the function to receive an uninitialized or unexpected null pointer via the 'cp' parameter.\nThe impact of a successful exploitation is a service disruption. Since the mail server's filter process crashes upon encountering the malformed record, it renders the system unable to process subsequent emails until the service is manually restarted or recovered by an automated monitor. In high-traffic environments, this represents a significant availability risk. Post-exploitation, the service remains unstable until the offending SPF record is either removed from the source DNS or the library is updated to handle the invalid pointer safely. The public disclosure of the exploit code exacerbates this risk, as it lowers the barrier to entry for potential attackers looking to disrupt email infrastructure."
}
CVE-2026-100890: OpenDMARC Null Pointer Dereference (MEDIUM Severity, CVSS: 5.3) | Sceawere