天下漏洞,尽知其名
HIGH

CVE-2026-101014 OpenDMARC 越界写入漏洞

影响攻击者可远程触发越界写入,可能导致拒绝服务或代码执行

AI 研判

OpenDMARC 1.4.2 及之前版本中,DMARC 记录解析组件 libopendmarc/opendmarc_util.c 的 opendmarc_util_cleanup 函数存在 off-by-one(差一)漏洞。攻击者可远程利用该缺陷,且漏洞利用代码已公开。

影响范围

OpenDMARC

Trusted Domain Project OpenDMARC 至 1.4.2 版本(含)受影响,更高版本是否受影响暂无公开信息。

漏洞详情

该漏洞属于 off-by-one 类型,成因是 opendmarc_util_cleanup 函数在处理 DMARC 记录解析相关数据时,边界计算存在偏差,导致写入或访问超出预期范围一个字节。攻击者可远程构造恶意输入触发该缺陷,进而可能造成内存破坏。

利用条件与风险

攻击可远程发起,无需本地访问权限,且利用代码已公开,实战风险较高;具体是否需要认证等前置条件暂无公开信息。

修复建议

官方已发布补丁(commit b3b1da9264bc80324094a27c71e7369bdedc62ae),建议尽快升级或部署该补丁;临时缓解措施暂无公开信息。

原始情报

A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely. The exploit is now public and may be used. The patch is named b3b1da9264bc80324094a27c71e7369bdedc62ae. To fix this issue, it is recommended to deploy a patch.