CVE-2026-103680: Tnef: heap buffer overflow in find_free_number() via numbered-backup suffix generation
A flaw was found in tnef. A heap-based buffer overflow can occur in the findfreenumber() function when generating numbered backup suffixes for duplicate filenames. When numbered backups are enabled and file overwriting is disabled, an attacker can supply a specially crafted Transport Neutral Encapsulation Format (TNEF) file with an excessive number of colliding attachment filenames, causing the numeric counter to write past the allocated memory buffer. This issue may result in an application crash, leading to a Denial of Service (DoS), or potentially arbitrary code execution.
Other sources
A flaw was found in tnef. findfreenumber() allocates a fixed-size buffer sized for a 5-digit numeric backup suffix, but formats the counter with an unbounded sprintf(). When the --number-backups option is enabled and overwrite is disabled, a crafted TNEF stream that forces roughly 100,000 colliding candidate filenames for a single extracted attachment causes the counter to require six digits, writing past the end of the allocated heap buffer. The issue requires a non-default command-line option and a large, specially crafted input to trigger.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
The issue affects tnef when it is run with numbered backups enabled and file overwriting disabled. The vulnerable condition requires a non-default command-line option, so deployments that do not enable numbered backups are not exposed through this path.
What must an attacker provide to trigger the overflow?
An attacker must supply a specially crafted TNEF file containing enough colliding attachment filenames to force roughly 100,000 candidate backup names for one extracted attachment. This makes the backup counter exceed five digits and write beyond the fixed-size heap buffer.
What can happen if exploitation succeeds?
The documented impact includes an application crash resulting in denial of service. The flaw may also potentially allow arbitrary code execution.
What can be done if an update is not immediately available?
Avoid using the --number-backups option when processing untrusted TNEF files, particularly when overwrite is disabled. Limit processing of large or untrusted TNEF inputs until the issue is remediated.