CVE-2026-45185
CVSS 9.8 CRITICAL: exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. EPSS 0.9% (59º percentile).
Vulnerabilità ed exploit
Il percorso BDAT di Exim non è isolato in modo sicuro dal teardown TLS nelle build GnuTLS. Un client può forzare un close_notify prima che il trasferimento termini, quindi inviare un ultimo byte in cleartext sulla stessa connessione, e Exim può scrivere in memoria liberata. Questo trasforma un edge case di consegna della posta in corruzione dell'heap e possibile esecuzione di codice.
2 fonti · 13 mag
CVSS 9.8 CRITICAL: exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. EPSS 0.9% (59º percentile).
BleepingComputer
New critical Exim mailer flaw allows remote code execution
A critical vulnerability affecting certain configurations of the Exim open-source mail transfer agent could be exploited by an unauthenticated remote attacker to execute arbitrary code.
originaleThe Hacker News
New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution
Exim BDAT flaw affects 4.97–4.99.2 GnuTLS builds, causing heap corruption and possible code execution.
originalePart of the PlainSec briefing for 2026-05-13
Every edition of this story: Exim BDAT Edge Case Apre la Possibilità di Esecuzione di Codice