In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade exim | May 4, 2026 | Apr 30, 2026 |
| Debian | — | Upgrade exim4 | May 13, 2026 | May 13, 2026 |
| Exim | — | Upgrade Exim to version 4.99.2 | Jun 9, 2026 | Apr 30, 2026 |
| Gentoo Linux | — | Upgrade mail-mta/exim. | Aug 16, 2026 | Aug 14, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub