Hi Andreas,

On Thu, Sep 24, 2026 at 09:59:32PM +0200, Salvatore Bonaccorso wrote:
> Hi Andreas,
> 
> On Thu, Sep 24, 2026 at 07:02:00PM +0200, Andreas Metzler wrote:
> > On 2026-09-20 Salvatore Bonaccorso <[email protected]> wrote:
> > > Source: exim4
> > > Version: 4.100-3
> > > Severity: grave
> > > Tags: security upstream
> > > Justification: user security hole
> > > X-Debbugs-Cc: [email protected], Debian Security Team 
> > > <[email protected]>
> > 
> > > Hi,
> > 
> > > The following vulnerabilities were published for exim4.
> > 
> > > Andreas, I'm putting this at RC level, but I'm not sure how common
> > > exploitable setups are for the more severe ones.
> > 
> > > CVE-2026-94054[0]:
> > > | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-
> > > | controlled proxy, has an out-of-bounds write.
> > 
> > 
> > > CVE-2026-94055[1]:
> > > | Exim before 4.100.1, when certain non-default TLS settings are used
> > > | with GnuTLS, has a use-after-free.
> > 
> > 
> > > CVE-2026-94056[2]:
> > > | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-
> > > | controlled proxy, allows attackers to read certain uninitialized
> > > | data from stack memory.
> > 
> > 
> > > CVE-2026-94057[3]:
> > > | Exim before 4.100.1 allows SMTP smuggling in which the received
> > > | message does not match any sent message, and instead depends on
> > > | crafted data sent after a rejection during DATA processing.
> > 
> > 
> > Hello Salvatore,
> > 
> > the second one (CVE-2026-94055 / GnuTLS) only applies to versions >=
> > 4.99, i.e. stable and earlier are fine. tls_early_banner was not
> > available in earlier releases.
> 
> Alright, thanks will update the tracker.

Hmm ist that correct? The upstream advisory say:

- Exim versions from 4.98 up to and including 4.100 are affected.
- The installation must be built with GnuTLS 3.6.4 or later, and configured
   to accept TLS-on-connect.
- The configuration must enable the tls_early_banner_hosts option
   (a non-default setting).

Regards,
Salvatore

Reply via email to