CVE-2026-45185
CVSS 9.8 CRITICAL: exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. EPSS 0.9% (59º percentile).
Vulnerabilità · 140 giorni fa
Il percorso BDAT di Exim non è isolato in modo sicuro dal teardown TLS nelle build GnuTLS. Un client può forzare un close_notify prima che il trasferimento termini, quindi inviare un ultimo byte in cleartext sulla stessa connessione, e Exim può scrivere in memoria liberata. Questo trasforma un edge case di consegna della posta in corruzione dell'heap e possibile esecuzione di codice.
CVSS 9.8 CRITICAL: exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. EPSS 0.9% (59º percentile).
2 fonti che coprono questa storia
New critical Exim mailer flaw allows remote code execution
A critical vulnerability affecting certain configurations of the Exim open-source mail transfer agent could be exploited by an unauthenticated remote attacker to execute arbitrary code.
New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution
Exim BDAT flaw affects 4.97–4.99.2 GnuTLS builds, causing heap corruption and possible code execution.
Part of the PlainSec briefing for 2026-05-14