CVE-2026-100889

NameCVE-2026-100889
DescriptionA vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
opendkim (PTS)bookworm2.11.0~beta2-8+deb12u1vulnerable
trixie2.11.0~beta2-9.1vulnerable
forky, sid2.11.0~beta2-9.2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
opendkimsource(unstable)(unfixed)

Notes

https://weitongli.com/share/opendkim-qp-off-by-one.html
check upstream details

Search for package or bug name: Reporting problems