CVE-2026-101016 OpenDMARC 异常条件处理漏洞
影响远程攻击者可触发异常条件导致拒绝服务
OpenDMARC 1.4.2 及之前版本中,libopendmarc/opendmarc_policy.c 的 opendmarc_policy_parse_dmarc 函数在处理 DMARC 记录参数(fo/rf/ri/pct/sp/adkim/aspf/rua/ruf)时存在异常条件处理缺陷。该漏洞可被远程利用,且利用方式已公开。
影响范围
Trusted Domain Project OpenDMARC 1.4.2 及更早版本,具体受影响范围以官方公告为准。
漏洞详情
该漏洞属于异常条件处理不当(CWE-703 类)问题。攻击者通过构造包含特制 fo、rf、ri、pct、sp、adkim、aspf、rua、ruf 参数的 DMARC 记录,使解析函数进入未妥善处理的异常状态。由于解析过程通常由接收邮件时的 DMARC 校验触发,远程即可利用。
利用条件与风险
利用前提是目标使用受影响版本的 OpenDMARC 解析攻击者可控的 DMARC 记录,且无需认证。利用方式已公开,实战中可能造成邮件服务解析异常或拒绝服务,但 CVSS 6.5 表明影响以可用性为主。
修复建议
官方尚未发布修复版本,厂商未回应。建议关注 Trusted Domain Project 官方更新,临时可对 DMARC 记录来源进行过滤或限制解析输入,并监控相关异常。
A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_policy_parse_dmarc in the library libopendmarc/opendmarc_policy.c. The manipulation of the argument fo/rf/ri/pct/sp/adkim/aspf/rua/ruf leads to handling of exceptional conditions. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.