Hi Andreas, On Thu, Sep 24, 2026 at 09:59:32PM +0200, Salvatore Bonaccorso wrote: > Hi Andreas, > > On Thu, Sep 24, 2026 at 07:02:00PM +0200, Andreas Metzler wrote: > > On 2026-09-20 Salvatore Bonaccorso <[email protected]> wrote: > > > Source: exim4 > > > Version: 4.100-3 > > > Severity: grave > > > Tags: security upstream > > > Justification: user security hole > > > X-Debbugs-Cc: [email protected], Debian Security Team > > > <[email protected]> > > > > > Hi, > > > > > The following vulnerabilities were published for exim4. > > > > > Andreas, I'm putting this at RC level, but I'm not sure how common > > > exploitable setups are for the more severe ones. > > > > > CVE-2026-94054[0]: > > > | Exim before 4.100.1, when Proxy-Protocol is used with an attacker- > > > | controlled proxy, has an out-of-bounds write. > > > > > > > CVE-2026-94055[1]: > > > | Exim before 4.100.1, when certain non-default TLS settings are used > > > | with GnuTLS, has a use-after-free. > > > > > > > CVE-2026-94056[2]: > > > | Exim before 4.100.1, when Proxy-Protocol is used with an attacker- > > > | controlled proxy, allows attackers to read certain uninitialized > > > | data from stack memory. > > > > > > > CVE-2026-94057[3]: > > > | Exim before 4.100.1 allows SMTP smuggling in which the received > > > | message does not match any sent message, and instead depends on > > > | crafted data sent after a rejection during DATA processing. > > > > > > Hello Salvatore, > > > > the second one (CVE-2026-94055 / GnuTLS) only applies to versions >= > > 4.99, i.e. stable and earlier are fine. tls_early_banner was not > > available in earlier releases. > > Alright, thanks will update the tracker.
Hmm ist that correct? The upstream advisory say: - Exim versions from 4.98 up to and including 4.100 are affected. - The installation must be built with GnuTLS 3.6.4 or later, and configured to accept TLS-on-connect. - The configuration must enable the tls_early_banner_hosts option (a non-default setting). Regards, Salvatore

