Out-of-bounds write in Exim - CVE-2026-40685

 

Out-of-bounds write in Exim - CVE-2026-40685

Published: May 7, 2026


Vulnerability identifier: #VU130455
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40685
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to out-of-bounds read/write in json operators when processing invalid externally-provided input in headers. A remote attacker can supply corrupt JSON data to cause memory corruption.

The issue affects configurations that use json operators on externally provided input.


Affected software

Exim
Debian Linux
Ubuntu
exim4 (Ubuntu package)
exim4 (Debian package)

How to mitigate CVE-2026-40685

Install security update from vendor's website.

Exim - update to 4.99.2
exim4 (Ubuntu package) - addressed in versions 4.82-3ubuntu2.4+esm9, 4.86.2-2ubuntu2.6+esm9, 4.90.1-1ubuntu1.10+esm6, 4.93-13ubuntu1.12+esm1, 4.95-4ubuntu2.7, 4.97-4ubuntu4.4, 4.98.2-1ubuntu2.1, 4.99.1-1ubuntu1.1
exim4 (Debian package) - addressed in versions 4.96-15+deb12u9, 4.98.2-1+deb13u2

External References

Related Security Bulletins