<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>OpenDKIM (&lt;= 2.11.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/opendkim--2.11.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 01:11:25 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/opendkim--2.11.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Out-of-Bounds Write Vulnerability in OpenDKIM</title><link>https://feed.craftedsignal.io/briefs/2026-09-opendkim-oob-write/</link><pubDate>Mon, 28 Sep 2026 01:11:25 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-opendkim-oob-write/</guid><description>A memory corruption vulnerability in the OpenDKIM dkim_canon_selecthdrs function allows remote attackers to trigger an out-of-bounds write via crafted DKIM signature headers.</description><content:encoded><![CDATA[<p>A security vulnerability (CVE-2026-100888) has been identified in the Trusted Domain Project OpenDKIM library up to version 2.11.0. The flaw resides within the dkim_canon_selecthdrs function located in libopendkim/dkim-canon.c, specifically within the DKIM Signature Header Selection component. By manipulating the 'h' argument in a malicious DKIM signature, a remote attacker can trigger an out-of-bounds write. This vulnerability is particularly concerning as public exploit code is already available, potentially enabling remote code execution in applications utilizing the affected library. The vendor was notified of the issue but has not provided a response or a patch as of the reporting date. Defenders should prioritize auditing mail infrastructure utilizing OpenDKIM for potential exploitation attempts or crashes indicating memory corruption.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability could lead to arbitrary code execution or service disruption of mail servers processing DKIM signatures. As OpenDKIM is a widely used library for DKIM verification, the impact is high for any organization relying on it for email authentication.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Detection engineering teams should monitor for anomalous crashes or unexpected behavior in processes utilizing libopendkim. Given the lack of a vendor patch, consider isolating mail processing components or implementing strict input validation at the edge if possible.</p>
<ul>
<li>Monitor application logs and system crash reports for memory-related errors originating from mail-handling processes linked against libopendkim.</li>
<li>Evaluate the necessity of OpenDKIM 2.11.0 or earlier in high-exposure segments and consider alternative configurations or temporary hardening measures if upgrading is not an option.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>mail-infrastructure</category><category>mail-security</category></item></channel></rss>