CVE-2026-107570: Use of Out-of-range Pointer Offset in mutt
heap OOB write in convertfilefromto() via a crafted Content-Type header allows attacker to OOB write when email is used as a template.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
muttto a version that resolves this vulnerability.Fixed in 2.4.3
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of Mutt are exposed when an email is used as a template and contains a crafted Content-Type header.
What does exploitation require?
An attacker needs to provide a crafted Content-Type header in an email that is subsequently used as a template. The vector is local, exploitation has high attack complexity, and user interaction is required.
What is the impact of successful exploitation?
Successful exploitation can cause an out-of-bounds heap write in convert_file_from_to(). The provided severity vector indicates integrity impact only, with no stated confidentiality or availability impact.