Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade exim4 | May 13, 2026 | May 13, 2026 |
| Exim | — | Upgrade Exim to version 4.99.3 | Jun 9, 2026 | May 12, 2026 |
| Gentoo Linux | — | Upgrade mail-mta/exim. | Aug 16, 2026 | Aug 14, 2026 |
| Ubuntu | — | Upgrade eximon4 (Ubuntu Pro)Upgrade exim4-daemon-heavy (Ubuntu Pro)Upgrade exim4 (Ubuntu Pro)Upgrade exim4-base (Ubuntu Pro)Upgrade exim4-dev (Ubuntu Pro)Upgrade exim4-daemon-light (Ubuntu Pro) | May 25, 2026 | May 12, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub