Hi Andreas, On Fri, Sep 25, 2026 at 11:31:39AM +0200, Andreas Metzler wrote: > On 2026-09-24 Salvatore Bonaccorso <[email protected]> wrote: > > On Thu, Sep 24, 2026 at 09:59:32PM +0200, Salvatore Bonaccorso wrote: > > > On Thu, Sep 24, 2026 at 07:02:00PM +0200, Andreas Metzler wrote: > [...] > > > > the second one (CVE-2026-94055 / GnuTLS) only applies to versions >= > > > > 4.99, i.e. stable and earlier are fine. tls_early_banner was not > > > > available in earlier releases. > > > > > > Alright, thanks will update the tracker. > > > Hmm ist that correct? The upstream advisory say: > > > - Exim versions from 4.98 up to and including 4.100 are affected. > > - The installation must be built with GnuTLS 3.6.4 or later, and configured > > to accept TLS-on-connect. > > - The configuration must enable the tls_early_banner_hosts option > > (a non-default setting). > > Hello Salvatore, > > I have asked upstream to confirm/reject this. > https://lists.exim.org/lurker/message/20260925.044831.5cb31b15.en.html > > Propopsed patch attched.
Thanks for the debdiff. Please go ahead with the upload to security-master. Regards, Salvatore

