Sceawere

Vulnerability Detail

CVE-2026-101279UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenDMARC pct Integer Overflow

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
6h ago
Vendor
Trusted Domain Project
Product
OpenDMARC
Attack Type
Integer Overflow
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown function of the file libopendmarc/opendmarc_policy.c of the component DMARC Parser. The manipulation of the argument pct leads to integer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-29T01:16:43.997Z",
  "pubdate": "2026-09-29T01:16:43.997Z",
  "executiveSummary": "A critical integer overflow vulnerability has been identified in the Trusted Domain Project OpenDMARC parser, specifically within libopendmarc/opendmarc_policy.c. The vulnerability resides in the processing of the 'pct' (percentage) parameter found in DMARC DNS records. This flaw allows a remote attacker to trigger an integer overflow condition by submitting maliciously crafted DMARC policy data.\nThe vulnerability affects all versions of OpenDMARC up to and including 1.4.2. Successful exploitation may lead to undefined behavior within the policy engine, potentially resulting in memory corruption, application crashes, or the subversion of DMARC policy enforcement. Because the vulnerability is remotely exploitable, it poses a significant risk to mail transfer agents (MTAs) and security gateways utilizing the library to validate incoming email authentication. The vendor has not provided an official patch at this time. The public disclosure of exploit techniques necessitates immediate attention from administrators to mitigate potential unauthorized policy bypasses or denial-of-service conditions.",
  "technicalDetails": "The vulnerability is localized within the DMARC parser component, specifically in libopendmarc/opendmarc_policy.c. The root cause is an insecure handling of the 'pct' tag, which specifies the percentage of messages to which the DMARC policy is to be applied. During the parsing process, the input string provided in the DNS TXT record is converted and stored into an internal integer representation. Improper validation of this numeric input allows an attacker to supply a value that exceeds the expected boundaries of the allocated data type, resulting in an integer overflow.\nThe attack flow initiates when an attacker controls a domain for which they can publish DMARC DNS records. By crafting a TXT record containing a 'pct' value specifically chosen to cause an arithmetic overflow during policy evaluation, the attacker triggers the vulnerability when a victim's mail server queries the DNS for DMARC records and passes the data to the OpenDMARC library.\nThe integer overflow can lead to a critical failure in the policy evaluation logic. If the overflow results in an unexpectedly small or large value, the internal checks for DMARC compliance may be bypassed or behave erroneously. In scenarios where policy results are used to make filtering decisions, the integrity of the DMARC check is compromised. Furthermore, depending on how the overflowed value is subsequently utilized for memory allocation or loop counters within libopendmarc, there exists the potential for heap-based or stack-based memory corruption. This could lead to a crash of the service (Denial of Service) or, in sophisticated scenarios, arbitrary code execution within the context of the mail processing daemon.\nThe vulnerability is exploitable remotely, requiring no authentication or local access. The attack is triggered as part of the standard DMARC lookup process, meaning that any mail server performing automated DMARC validation against a malicious domain is inherently exposed. The lack of proper boundary checking on the 'pct' input in opendmarc_policy.c is the primary failure point. Without rigorous validation to ensure that the parsed value resides within the legitimate 0-100 range before arithmetic operations are performed, the application remains susceptible to manipulation of its control flow through integer-based errors."
}
CVE-2026-101279: OpenDMARC pct Integer Overflow (MEDIUM Severity, CVSS: 6.5) | Sceawere