SB2026092938 - Debian update for exim4
Published: September 29, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Out-of-bounds write (CVE-ID: CVE-2026-94054)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause an out-of-bounds heap read and write.
The vulnerability exists due to an out-of-bounds write in Proxy Protocol v1 handling when processing Proxy Protocol v1 data from a configured proxy. A remote attacker can supply Proxy Protocol v1 data through the configured proxy to cause an out-of-bounds heap read and write.
The installation must be built and configured for Proxy-Protocol use, and the configured proxy must be buggy or compromised.
2) Use of Uninitialized Variable (CVE-ID: CVE-2026-94056)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose stack data.
The vulnerability exists due to the use of uninitialized data in Proxy Protocol v2 handling when processing Proxy Protocol v2 data from a configured proxy. A remote attacker can supply Proxy Protocol v2 data through the configured proxy to disclose stack data.
The installation must be built and configured for Proxy-Protocol use, and the configured proxy must be buggy or compromised.
3) Input validation error (CVE-ID: CVE-2026-94057)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to submit a message different from the one sent and logged by the sending system.
The vulnerability exists due to improper message termination handling in SMTP reception when processing message data after a data-phase rejection. A remote attacker can send a message with crafted data following the rejection point to submit a message different from the one sent and logged by the sending system.
Normal configured processing for received messages is applied to the smuggled message.
Remediation
Install update from vendor's website.