Input validation error in Exim - CVE-2026-40684
Published: May 7, 2026
Exim
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of malformed DNS data in PTR record processing when processing DNS responses on systems using musl libc. A remote attacker can provide specially crafted DNS data to cause a denial of service.
Only systems using musl libc are affected.