UBUNTU-CVE-2026-94184

Source
https://ubuntu.com/security/CVE-2026-94184
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-94184.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-94184
Upstream
Published
2026-09-21T15:17:00Z
Modified
2026-09-24T02:03:13Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening. Affects v5.0.8 through v6.6.6.

References

Affected packages

Ubuntu:16.04:LTS
fetchmail

Package

Name
fetchmail
Purl
pkg:deb/ubuntu/fetchmail?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.3.26-1
6.3.26-2

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "fetchmail",
            "binary_version":  "6.3.26-2"
        },
        {
            "binary_name":  "fetchmailconf",
            "binary_version":  "6.3.26-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-94184.json"
Ubuntu:18.04:LTS
fetchmail

Package

Name
fetchmail
Purl
pkg:deb/ubuntu/fetchmail?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.3.26-3
6.3.26-3build1
6.3.26-3ubuntu0.1~18.04.1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "fetchmail",
            "binary_version":  "6.3.26-3ubuntu0.1~18.04.1"
        },
        {
            "binary_name":  "fetchmailconf",
            "binary_version":  "6.3.26-3ubuntu0.1~18.04.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-94184.json"
Ubuntu:20.04:LTS
fetchmail

Package

Name
fetchmail
Purl
pkg:deb/ubuntu/fetchmail?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.4.0~rc4-1ubuntu1
6.4.1-1ubuntu1
6.4.2-2

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "fetchmail",
            "binary_version":  "6.4.2-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-94184.json"
Ubuntu:22.04:LTS
fetchmail

Package

Name
fetchmail
Purl
pkg:deb/ubuntu/fetchmail?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.4.22-1
6.4.23-1
6.4.24-1
6.4.25-1
6.4.26-1
6.4.27-1
6.4.27-1ubuntu0.1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "fetchmail",
            "binary_version":  "6.4.27-1ubuntu0.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-94184.json"
Ubuntu:24.04:LTS
fetchmail

Package

Name
fetchmail
Purl
pkg:deb/ubuntu/fetchmail?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.4.37-1
6.4.38-1ubuntu1
6.4.38-1ubuntu3
6.4.38-1ubuntu4
6.4.38-1ubuntu4.1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "fetchmail",
            "binary_version":  "6.4.38-1ubuntu4.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-94184.json"
Ubuntu:26.04:LTS
fetchmail

Package

Name
fetchmail
Purl
pkg:deb/ubuntu/fetchmail?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.5.4-0ubuntu2
6.5.4-0ubuntu3
6.6.2-2

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "fetchmail",
            "binary_version":  "6.6.2-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-94184.json"