Out-of-bounds write in Exim - CVE-2026-40687

 

Out-of-bounds write in Exim - CVE-2026-40687

Published: May 7, 2026


Vulnerability identifier: #VU130457
CSH Severity: Medium
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40687
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds read/write in the SPA authentication driver when handling a hostile or compromised external SPA/NTLM connection. A remote attacker can provide crafted SPA/NTLM responses to cause a denial of service.

The issue is exposed in configurations that use the SPA authentication driver and may also leak heap data to the instance.


Affected software

Exim
Debian Linux
Ubuntu
exim4 (Ubuntu package)
exim4 (Debian package)

How to mitigate CVE-2026-40687

Install security update from vendor's website.

Exim - update to 4.99.2
exim4 (Ubuntu package) - addressed in versions 4.82-3ubuntu2.4+esm9, 4.86.2-2ubuntu2.6+esm9, 4.90.1-1ubuntu1.10+esm6, 4.93-13ubuntu1.12+esm1, 4.95-4ubuntu2.7, 4.97-4ubuntu4.4, 4.98.2-1ubuntu2.1, 4.99.1-1ubuntu1.1
exim4 (Debian package) - addressed in versions 4.96-15+deb12u9, 4.98.2-1+deb13u2

External References

Related Security Bulletins