Sceawere
Vulnerability Detail
CVE-2026-101279UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
OpenDMARC pct Integer Overflow
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 6h ago
- Vendor
- Trusted Domain Project
- Product
- OpenDMARC
- Attack Type
- Integer Overflow
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown function of the file libopendmarc/opendmarc_policy.c of the component DMARC Parser. The manipulation of the argument pct leads to integer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-29T01:16:43.997Z",
"pubdate": "2026-09-29T01:16:43.997Z",
"executiveSummary": "A critical integer overflow vulnerability has been identified in the Trusted Domain Project OpenDMARC parser, specifically within libopendmarc/opendmarc_policy.c. The vulnerability resides in the processing of the 'pct' (percentage) parameter found in DMARC DNS records. This flaw allows a remote attacker to trigger an integer overflow condition by submitting maliciously crafted DMARC policy data.\nThe vulnerability affects all versions of OpenDMARC up to and including 1.4.2. Successful exploitation may lead to undefined behavior within the policy engine, potentially resulting in memory corruption, application crashes, or the subversion of DMARC policy enforcement. Because the vulnerability is remotely exploitable, it poses a significant risk to mail transfer agents (MTAs) and security gateways utilizing the library to validate incoming email authentication. The vendor has not provided an official patch at this time. The public disclosure of exploit techniques necessitates immediate attention from administrators to mitigate potential unauthorized policy bypasses or denial-of-service conditions.",
"technicalDetails": "The vulnerability is localized within the DMARC parser component, specifically in libopendmarc/opendmarc_policy.c. The root cause is an insecure handling of the 'pct' tag, which specifies the percentage of messages to which the DMARC policy is to be applied. During the parsing process, the input string provided in the DNS TXT record is converted and stored into an internal integer representation. Improper validation of this numeric input allows an attacker to supply a value that exceeds the expected boundaries of the allocated data type, resulting in an integer overflow.\nThe attack flow initiates when an attacker controls a domain for which they can publish DMARC DNS records. By crafting a TXT record containing a 'pct' value specifically chosen to cause an arithmetic overflow during policy evaluation, the attacker triggers the vulnerability when a victim's mail server queries the DNS for DMARC records and passes the data to the OpenDMARC library.\nThe integer overflow can lead to a critical failure in the policy evaluation logic. If the overflow results in an unexpectedly small or large value, the internal checks for DMARC compliance may be bypassed or behave erroneously. In scenarios where policy results are used to make filtering decisions, the integrity of the DMARC check is compromised. Furthermore, depending on how the overflowed value is subsequently utilized for memory allocation or loop counters within libopendmarc, there exists the potential for heap-based or stack-based memory corruption. This could lead to a crash of the service (Denial of Service) or, in sophisticated scenarios, arbitrary code execution within the context of the mail processing daemon.\nThe vulnerability is exploitable remotely, requiring no authentication or local access. The attack is triggered as part of the standard DMARC lookup process, meaning that any mail server performing automated DMARC validation against a malicious domain is inherently exposed. The lack of proper boundary checking on the 'pct' input in opendmarc_policy.c is the primary failure point. Without rigorous validation to ensure that the parsed value resides within the legitimate 0-100 range before arithmetic operations are performed, the application remains susceptible to manipulation of its control flow through integer-based errors."
}