Use-after-free in Exim - CVE-2026-94055
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free in GnuTLS TLS-on-connect handling when accepting TLS-on-connect connections. A remote attacker can initiate a TLS-on-connect connection to cause a denial of service.
The installation must use GnuTLS 3.6.4 or later, accept TLS-on-connect connections, and enable the non-default tls_early_banner_hosts option.