Input validation error in Exim - CVE-2026-40684
Published: May 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of malformed DNS data in PTR record processing when processing DNS responses on systems using musl libc. A remote attacker can provide specially crafted DNS data to cause a denial of service.
Only systems using musl libc are affected.
Affected software
Debian Linux
Gentoo Linux
exim4 (Debian package)
mail-mta/exim
How to mitigate CVE-2026-40684
exim4 (Debian package) - addressed in versions 4.96-15+deb12u9, 4.98.2-1+deb13u2
mail-mta/exim - update to 4.99.4