REDHAT-BUG-2544477: Use After Free

Published Oct 1, 2026
·
Updated

A flaw was found in tnef. When a TNEF stream contains more than one MAPI RTF or HTML body value, getbodyfiles() allocates a single filename buffer and a single MIME-type buffer and assigns the same pointers to every generated output file, instead of a separate copy per file. Each of these files is later freed independently, producing a use-after-free followed by a double-free on the second and subsequent files. The issue was confirmed under AddressSanitizer and crashes the process when extracting a crafted TNEF stream with multiple body values; no code-execution primitive has been demonstrated.

Affected Software

1 affected component
tnef

Event History

Oct 1, 2026
Data Sourced
via Red Hat·09:17 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What input is required to trigger the crash?

An attacker would need to supply a crafted TNEF stream containing more than one MAPI RTF or HTML body value and have it processed for extraction.

2

What is the observed impact?

The flaw causes a use-after-free followed by a double-free when the generated body files are freed independently. It has been confirmed to crash the process under AddressSanitizer; no code-execution primitive has been demonstrated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203