rootpwn

medium · CVSS v3 6.5

CVE-2026-101279

OpenDMARC up to 1.4.2 contains an integer overflow in the pct argument of the DMARC parser, which can be triggered remotely and may corrupt

Overview

OpenDMARC up to 1.4.2 contains an integer overflow in the pct argument of the DMARC parser, which can be triggered remotely and may corrupt memory or cause a denial of service. It affects any mail server using the vulnerable OpenDMARC library.

Description

A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown function of the file libopendmarc/opendmarc_policy.c of the component DMARC Parser. The manipulation of the argument pct leads to integer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Impact

The integer overflow can lead to memory corruption, potentially allowing attackers to crash the DMARC parser or execute arbitrary code, compromising the confidentiality, integrity, and availability of mail processing. Mail administrators and email service providers are the primary defenders impacted.

Remediation

Check the OpenDMARC version on all mail servers. Upgrade to version 1.4.3 or later where the pct handling is fixed. If an upgrade is not immediately possible, disable or sanitize the pct tag in incoming DMARC records, or apply a local patch that bounds the pct value to 0–100. Monitor logs for parsing errors or crashes.

Risk context

Severity is medium (CVSS 6.5). No EPSS data is available. The vulnerability is publicly disclosed and exploitable, so timely patching is recommended.

Affected products

  • Trusted Domain Project OpenDMARC

Scores

Severity
medium
CVSS v2
6.4
CVSS v3
6.5
CVSS v4
—
EPSS
—

dmarc integer-overflow remote-exploit mail-security patch vulnerability

← All CVEs