SB2026092936 - Multiple vulnerabilities in Exim



SB2026092936 - Multiple vulnerabilities in Exim

Published: September 29, 2026

Security Bulletin ID SB2026092936
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Partial DoS

Breakdown by Severity

Medium 25% Low 75%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 vulnerabilities.


1) Out-of-bounds write (CVE-ID: CVE-2026-94054)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause an out-of-bounds heap read and write.

The vulnerability exists due to an out-of-bounds write in Proxy Protocol v1 handling when processing Proxy Protocol v1 data from a configured proxy. A remote attacker can supply Proxy Protocol v1 data through the configured proxy to cause an out-of-bounds heap read and write.

The installation must be built and configured for Proxy-Protocol use, and the configured proxy must be buggy or compromised.


2) Use-after-free (CVE-ID: CVE-2026-94055)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a use-after-free in GnuTLS TLS-on-connect handling when accepting TLS-on-connect connections. A remote attacker can initiate a TLS-on-connect connection to cause a denial of service.

The installation must use GnuTLS 3.6.4 or later, accept TLS-on-connect connections, and enable the non-default tls_early_banner_hosts option.


3) Use of Uninitialized Variable (CVE-ID: CVE-2026-94056)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose stack data.

The vulnerability exists due to the use of uninitialized data in Proxy Protocol v2 handling when processing Proxy Protocol v2 data from a configured proxy. A remote attacker can supply Proxy Protocol v2 data through the configured proxy to disclose stack data.

The installation must be built and configured for Proxy-Protocol use, and the configured proxy must be buggy or compromised.


4) Input validation error (CVE-ID: CVE-2026-94057)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to submit a message different from the one sent and logged by the sending system.

The vulnerability exists due to improper message termination handling in SMTP reception when processing message data after a data-phase rejection. A remote attacker can send a message with crafted data following the rejection point to submit a message different from the one sent and logged by the sending system.

Normal configured processing for received messages is applied to the smuggled message.


Remediation

Install update from vendor's website.