CVE-2026-100888

Summary

A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature Header Selection. Executing a manipulation of the argument h can lead to out-of-bounds write. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

VendorProductVersion RangeStatus
Trusted Domain ProjectOpenDKIM2.0affected
Trusted Domain ProjectOpenDKIM2.1affected
Trusted Domain ProjectOpenDKIM2.2affected
Trusted Domain ProjectOpenDKIM2.3affected
Trusted Domain ProjectOpenDKIM2.4affected
Trusted Domain ProjectOpenDKIM2.5affected
Trusted Domain ProjectOpenDKIM2.6affected
Trusted Domain ProjectOpenDKIM2.7affected
Trusted Domain ProjectOpenDKIM2.8affected
Trusted Domain ProjectOpenDKIM2.9affected
Trusted Domain ProjectOpenDKIM2.10affected
Trusted Domain ProjectOpenDKIM2.11.0affected

Weaknesses

  • CWE-787: Out-of-bounds Write
  • CWE-119: Memory Corruption

References