Mutt 2.4.3 Releases Two Security Fixes, Closes Heap Overflow CVE-2026-107570
Mutt, the text-based terminal email client, released version 2.4.3, shipping just two commits, both bug fixes. The headline patch closes CVE-2026-107570, an out-of-bounds heap write in the charset converter that could lead to arbitrary code execution when a crafted message is reused via the resend command. A second fix restores trust in Mutt's cryptographic indicators after a flag bug could display a message as genuinely signed when it was not. The release, reported by Calif.io with Anthropic, is available now from ftp.mutt.org and is available in most distros' next rebuild.
Mutt 2.4.3 Releases Two Security Fixes, Closes Heap Overflow CVE-2026-107570 @ Linux Compatible
Mutt 2.4.3 Releases Two Security Fixes, Closes Heap Overflow CVE-2026-107570
Mutt has released version 2.4.3, which includes two important security fixes, one of which addresses a heap overflow vulnerability (CVE-2026-107570) that could potentially allow arbitrary code execution through the charset converter. The second fix corrects a bug in the cryptographic indicators that could falsely show a message as signed when it was not, misleading users regarding the authenticity of their messages. The update is a result of collaboration between security researchers from Calif.io and the maintainer, Kevin J. McCarthy, highlighting the increasing role of AI in identifying vulnerabilities in open-source software. Users can obtain the new version from the Mutt website or expect it to appear in upcoming package updates from their distributions
