Hi Andreas, On Thu, Sep 24, 2026 at 07:02:00PM +0200, Andreas Metzler wrote: > On 2026-09-20 Salvatore Bonaccorso <[email protected]> wrote: > > Source: exim4 > > Version: 4.100-3 > > Severity: grave > > Tags: security upstream > > Justification: user security hole > > X-Debbugs-Cc: [email protected], Debian Security Team > > <[email protected]> > > > Hi, > > > The following vulnerabilities were published for exim4. > > > Andreas, I'm putting this at RC level, but I'm not sure how common > > exploitable setups are for the more severe ones. > > > CVE-2026-94054[0]: > > | Exim before 4.100.1, when Proxy-Protocol is used with an attacker- > > | controlled proxy, has an out-of-bounds write. > > > > CVE-2026-94055[1]: > > | Exim before 4.100.1, when certain non-default TLS settings are used > > | with GnuTLS, has a use-after-free. > > > > CVE-2026-94056[2]: > > | Exim before 4.100.1, when Proxy-Protocol is used with an attacker- > > | controlled proxy, allows attackers to read certain uninitialized > > | data from stack memory. > > > > CVE-2026-94057[3]: > > | Exim before 4.100.1 allows SMTP smuggling in which the received > > | message does not match any sent message, and instead depends on > > | crafted data sent after a rejection during DATA processing. > > > Hello Salvatore, > > the second one (CVE-2026-94055 / GnuTLS) only applies to versions >= > 4.99, i.e. stable and earlier are fine. tls_early_banner was not > available in earlier releases.
Alright, thanks will update the tracker. > The proxy protocol stuff might be used for multi stage attack, one would > not intentionally point exim to an untrusted proxy. Imho the 4th one > warrants a security release instead of a stable update. - I will propose > a patch (for all three issues). Thanks! Regards, Salvatore

