On 2026-09-20 Salvatore Bonaccorso <[email protected]> wrote: > Source: exim4 > Version: 4.100-3 > Severity: grave > Tags: security upstream > Justification: user security hole > X-Debbugs-Cc: [email protected], Debian Security Team > <[email protected]>
> Hi, > The following vulnerabilities were published for exim4. > Andreas, I'm putting this at RC level, but I'm not sure how common > exploitable setups are for the more severe ones. > CVE-2026-94054[0]: > | Exim before 4.100.1, when Proxy-Protocol is used with an attacker- > | controlled proxy, has an out-of-bounds write. > CVE-2026-94055[1]: > | Exim before 4.100.1, when certain non-default TLS settings are used > | with GnuTLS, has a use-after-free. > CVE-2026-94056[2]: > | Exim before 4.100.1, when Proxy-Protocol is used with an attacker- > | controlled proxy, allows attackers to read certain uninitialized > | data from stack memory. > CVE-2026-94057[3]: > | Exim before 4.100.1 allows SMTP smuggling in which the received > | message does not match any sent message, and instead depends on > | crafted data sent after a rejection during DATA processing. Hello Salvatore, the second one (CVE-2026-94055 / GnuTLS) only applies to versions >= 4.99, i.e. stable and earlier are fine. tls_early_banner was not available in earlier releases. The proxy protocol stuff might be used for multi stage attack, one would not intentionally point exim to an untrusted proxy. Imho the 4th one warrants a security release instead of a stable update. - I will propose a patch (for all three issues). cu Andreas -- "You people are noisy," Nia said. I made the gesture of agreement.
signature.asc
Description: PGP signature

