Out-of-bounds read in Exim - CVE-2026-40686

 

Out-of-bounds read in Exim - CVE-2026-40686

Published: May 7, 2026


Vulnerability identifier: #VU130456
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40686
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in utf8 operators when processing malformed utf8 in headers with large trailing characters. A remote attacker can supply malformed utf8 header data to disclose sensitive information.

Data leakage may occur if error messages are required for subsequent emails in the current connection and similar malformed headers are present.


Affected software

Exim
Debian Linux
Ubuntu
exim4 (Ubuntu package)
exim4 (Debian package)

How to mitigate CVE-2026-40686

Install security update from vendor's website.

Exim - update to 4.99.2
exim4 (Ubuntu package) - addressed in versions 4.82-3ubuntu2.4+esm9, 4.86.2-2ubuntu2.6+esm9, 4.90.1-1ubuntu1.10+esm6, 4.93-13ubuntu1.12+esm1, 4.95-4ubuntu2.7, 4.97-4ubuntu4.4, 4.98.2-1ubuntu2.1, 4.99.1-1ubuntu1.1
exim4 (Debian package) - addressed in versions 4.96-15+deb12u9, 4.98.2-1+deb13u2

External References

Related Security Bulletins