CVE-2026-103678: Tnef: heap out-of-bounds read in get_rtf_data_from_buf() via uncompressed rtf mapi value
A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in getrtfdatafrombuf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files.
Other sources
A flaw was found in tnef. The TNEF uncompressed-RTF value handler in getrtfdatafrombuf() copies an attacker-controlled uncomprsize number of bytes from the input buffer without validating that the buffer actually contains that much data beyond the 16-byte value header, resulting in a heap out-of-bounds read. The issue was confirmed under AddressSanitizer and can crash the process; when body extraction (--save-body) is enabled, the over-read memory is written into the extracted RTF output file.
— Red Hat