REDHAT-BUG-2544476: Medium severity tnef vulnerability

Published Oct 1, 2026
·
Updated

A flaw was found in tnef. The TNEF uncompressed-RTF value handler in getrtfdatafrombuf() copies an attacker-controlled uncomprsize number of bytes from the input buffer without validating that the buffer actually contains that much data beyond the 16-byte value header, resulting in a heap out-of-bounds read. The issue was confirmed under AddressSanitizer and can crash the process; when body extraction (--save-body) is enabled, the over-read memory is written into the extracted RTF output file.

Affected Software

1 affected component
tnef

Event History

Oct 1, 2026
Data Sourced
via Red Hat·09:13 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What does an attacker need to provide to trigger this issue?

An attacker needs to supply a TNEF input containing an uncompressed RTF value whose attacker-controlled uncompr_size exceeds the data available after the 16-byte value header.

2

What is the practical impact when processing a malicious file?

The flaw causes a heap out-of-bounds read and can crash the tnef process. If body extraction is enabled with --save-body, memory read beyond the input buffer is written to the extracted RTF output file.

3

How can I determine whether extracted output may be affected?

Check whether tnef was run with the --save-body option on untrusted TNEF files. In that configuration, a malformed uncompressed RTF value can cause over-read memory to be included in the generated RTF file.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203