Hi Andreas,

On Thu, Sep 24, 2026 at 07:02:00PM +0200, Andreas Metzler wrote:
> On 2026-09-20 Salvatore Bonaccorso <[email protected]> wrote:
> > Source: exim4
> > Version: 4.100-3
> > Severity: grave
> > Tags: security upstream
> > Justification: user security hole
> > X-Debbugs-Cc: [email protected], Debian Security Team 
> > <[email protected]>
> 
> > Hi,
> 
> > The following vulnerabilities were published for exim4.
> 
> > Andreas, I'm putting this at RC level, but I'm not sure how common
> > exploitable setups are for the more severe ones.
> 
> > CVE-2026-94054[0]:
> > | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-
> > | controlled proxy, has an out-of-bounds write.
> 
> 
> > CVE-2026-94055[1]:
> > | Exim before 4.100.1, when certain non-default TLS settings are used
> > | with GnuTLS, has a use-after-free.
> 
> 
> > CVE-2026-94056[2]:
> > | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-
> > | controlled proxy, allows attackers to read certain uninitialized
> > | data from stack memory.
> 
> 
> > CVE-2026-94057[3]:
> > | Exim before 4.100.1 allows SMTP smuggling in which the received
> > | message does not match any sent message, and instead depends on
> > | crafted data sent after a rejection during DATA processing.
> 
> 
> Hello Salvatore,
> 
> the second one (CVE-2026-94055 / GnuTLS) only applies to versions >=
> 4.99, i.e. stable and earlier are fine. tls_early_banner was not
> available in earlier releases.

Alright, thanks will update the tracker.

> The proxy protocol stuff might be used for multi stage attack, one would
> not intentionally point exim to an untrusted proxy. Imho the 4th one
> warrants a security release instead of a stable update. - I will propose
> a patch (for all three issues).

Thanks!

Regards,
Salvatore

Reply via email to