Sceawere
Vulnerability Detail
CVE-2026-101014UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
OpenDMARC Off-By-One Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 2h ago
- Vendor
- Trusted Domain Project
- Product
- OpenDMARC
- Attack Type
- Off-by-One
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely. The exploit is now public and may be used. The patch is named b3b1da9264bc80324094a27c71e7369bdedc62ae. To fix this issue, it is recommended to deploy a patch.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-28T09:17:03.893Z",
"pubdate": "2026-09-28T09:17:03.893Z",
"executiveSummary": "A critical off-by-one vulnerability exists in the Trusted Domain Project OpenDMARC library (versions up to 1.4.2). The flaw originates within the opendmarc_util_cleanup function of the DMARC Record Parser component. This memory corruption vulnerability allows a remote, unauthenticated attacker to trigger an off-by-one error during record parsing.\nThe vulnerability poses significant risk, potentially leading to memory corruption, service instability (denial of service), or arbitrary code execution depending on the heap layout and application context. Because the exploit is public and the attack can be initiated remotely without specific user interaction or authentication, the attack surface is highly accessible to malicious actors. Organizations utilizing affected versions of OpenDMARC are strongly advised to apply the specified security patch to prevent potential exploitation of this memory safety flaw.",
"technicalDetails": "The vulnerability is identified as an off-by-one memory error located in the opendmarc_util_cleanup function within libopendmarc/opendmarc_util.c. The flaw occurs during the process of cleaning or parsing DMARC records, where the internal logic fails to correctly account for string termination or array indexing, resulting in a write operation that extends one byte beyond the allocated memory buffer.\nRoot Cause Analysis: The off-by-one condition typically manifests when the function performs a bounds check or a copy operation that permits the inclusion of a null terminator or character into an adjacent memory address. In libopendmarc, this vulnerability is triggered when the DMARC record parser processes specific malformed or crafted DMARC inputs. If the internal state tracking or buffer allocation does not strictly adhere to the constraints of the data being processed, the pointer or index offset increments beyond the safe boundary of the destination buffer.\nExploitation Flow: An attacker can remotely trigger this vulnerability by sending a malicious DMARC record, likely via an email environment configured to use OpenDMARC for policy enforcement. As the parser consumes the crafted data, the opendmarc_util_cleanup function executes. When the logic error is triggered, the program performs an out-of-bounds write. Depending on the memory management implementation of the hosting environment, this can result in the corruption of critical heap metadata or adjacent control structures.\nImpact: The exploitation of this off-by-one error can lead to a range of severe outcomes. If the corruption target is a function pointer or a return address on the stack, an attacker could potentially achieve remote code execution (RCE). Alternatively, even if RCE is not immediately feasible, the corruption of memory management headers will inevitably lead to an application crash, facilitating a Denial of Service (DoS) attack against the email infrastructure relying on OpenDMARC. Because the vulnerability is reachable through external inputs, it does not require prior authentication or elevated privileges, making it a high-priority concern for systems handling external untrusted email records."
}