CVE-2026-101014 OpenDMARC 越界写入漏洞
影响攻击者可远程触发越界写入,可能导致拒绝服务或代码执行
OpenDMARC 1.4.2 及之前版本中,DMARC 记录解析组件 libopendmarc/opendmarc_util.c 的 opendmarc_util_cleanup 函数存在 off-by-one(差一)漏洞。攻击者可远程利用该缺陷,且漏洞利用代码已公开。
影响范围
Trusted Domain Project OpenDMARC 至 1.4.2 版本(含)受影响,更高版本是否受影响暂无公开信息。
漏洞详情
该漏洞属于 off-by-one 类型,成因是 opendmarc_util_cleanup 函数在处理 DMARC 记录解析相关数据时,边界计算存在偏差,导致写入或访问超出预期范围一个字节。攻击者可远程构造恶意输入触发该缺陷,进而可能造成内存破坏。
利用条件与风险
攻击可远程发起,无需本地访问权限,且利用代码已公开,实战风险较高;具体是否需要认证等前置条件暂无公开信息。
修复建议
官方已发布补丁(commit b3b1da9264bc80324094a27c71e7369bdedc62ae),建议尽快升级或部署该补丁;临时缓解措施暂无公开信息。
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely. The exploit is now public and may be used. The patch is named b3b1da9264bc80324094a27c71e7369bdedc62ae. To fix this issue, it is recommended to deploy a patch.