In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
CVSS Details
- CVSS 3.1 Base Score: 4.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade exim | May 4, 2026 | Apr 30, 2026 |
| Debian | — | Upgrade exim4 | May 13, 2026 | May 13, 2026 |
| Exim | — | Upgrade Exim to version 4.99.2 | Jun 9, 2026 | Apr 30, 2026 |
| Gentoo Linux | — | Upgrade mail-mta/exim. | Aug 16, 2026 | Aug 14, 2026 |
| Ubuntu | — | Upgrade exim4-daemon-heavy (Ubuntu Pro)Upgrade exim4 (Ubuntu Pro)Upgrade exim4-baseUpgrade eximon4 (Ubuntu Pro)Upgrade exim4-base (Ubuntu Pro)Upgrade eximon4Upgrade exim4-dev (Ubuntu Pro)Upgrade exim4-daemon-light (Ubuntu Pro)Upgrade exim4 | May 4, 2026 | Apr 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub