Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade exim | Jun 2, 2026 | May 30, 2026 |
| Debian | — | Upgrade exim4 | May 31, 2026 | May 31, 2026 |
| Exim | — | Upgrade Exim to version 4.99.4 | Jun 9, 2026 | May 30, 2026 |
| Ubuntu | — | Upgrade exim4-daemon-heavy (Ubuntu Pro)Upgrade exim4-dev (Ubuntu Pro)Upgrade exim4-base (Ubuntu Pro)Upgrade eximon4 (Ubuntu Pro)Upgrade exim4-daemon-light (Ubuntu Pro)Upgrade exim4Upgrade exim4 (Ubuntu Pro)Upgrade eximon4Upgrade exim4-base | Jun 2, 2026 | Jun 1, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub