CVE-2026-103679

A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing multiple message bodies. During extraction, improper memory management triggers a use-after-free and double-free condition, causing the application to crash and resulting in a Denial of Service (DoS).

  • Published Oct 1, 2026
  • CVSS 6.5 medium
  • 0.3% chance of exploitation in the next 30 days (EPSS)

CVE-2026-103679 at the National Vulnerability Database