PT-2026-99729 · Opendkim · Opendkim

·

CVE-2026-100888

·

Published

2026-09-27

·

Updated

2026-09-28

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenDKIM versions prior to 2.11.1
Description A weakness exists in the DKIM Signature Header Selection component within the dkim canon selecthdrs() function of the libopendkim/dkim-canon.c file. A remote attacker can manipulate the h argument to trigger an out-of-bounds write, which occurs when data is written outside the intended memory boundary of a buffer.
Recommendations Update OpenDKIM to a version newer than 2.11.0. As a temporary mitigation, restrict access to the dkim canon selecthdrs() function to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100888

Affected Products

Opendkim