Your message dated Fri, 02 Oct 2026 15:17:33 +0000
with message-id <[email protected]>
and subject line Bug#1148506: fixed in exim4 4.98.2-1+deb13u5
has caused the Debian Bug report #1148506,
regarding exim4: CVE-2026-94054 CVE-2026-94055 CVE-2026-94056 CVE-2026-94057
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1148506: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1148506
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: exim4
Version: 4.100-3
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for exim4.

Andreas, I'm putting this at RC level, but I'm not sure how common
exploitable setups are for the more severe ones.

CVE-2026-94054[0]:
| Exim before 4.100.1, when Proxy-Protocol is used with an attacker-
| controlled proxy, has an out-of-bounds write.


CVE-2026-94055[1]:
| Exim before 4.100.1, when certain non-default TLS settings are used
| with GnuTLS, has a use-after-free.


CVE-2026-94056[2]:
| Exim before 4.100.1, when Proxy-Protocol is used with an attacker-
| controlled proxy, allows attackers to read certain uninitialized
| data from stack memory.


CVE-2026-94057[3]:
| Exim before 4.100.1 allows SMTP smuggling in which the received
| message does not match any sent message, and instead depends on
| crafted data sent after a rejection during DATA processing.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-94054
    https://www.cve.org/CVERecord?id=CVE-2026-94054
[1] https://security-tracker.debian.org/tracker/CVE-2026-94055
    https://www.cve.org/CVERecord?id=CVE-2026-94055
[2] https://security-tracker.debian.org/tracker/CVE-2026-94056
    https://www.cve.org/CVERecord?id=CVE-2026-94056
[3] https://security-tracker.debian.org/tracker/CVE-2026-94057
    https://www.cve.org/CVERecord?id=CVE-2026-94057
[4] https://lists.exim.org/lurker/message/20260918.121220.0f87338e.en.html

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: exim4
Source-Version: 4.98.2-1+deb13u5
Done: Andreas Metzler <[email protected]>

We believe that the bug you reported is fixed in the latest version of
exim4, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Andreas Metzler <[email protected]> (supplier of updated exim4 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 25 Sep 2026 11:25:38 +0200
Source: exim4
Architecture: source
Version: 4.98.2-1+deb13u5
Distribution: trixie-security
Urgency: high
Maintainer: Exim4 Maintainers <[email protected]>
Changed-By: Andreas Metzler <[email protected]>
Closes: 1148506
Changes:
 exim4 (4.98.2-1+deb13u5) trixie-security; urgency=high
 .
   * Cherry-pick relevant changes from security release 4.100.1.
     CVE-2026-94054 EXIM-Security-2026-09-12.1 (GCVE-25-2026-09-50-1)
      Exim before 4.100.1, when Proxy-Protocol is used with an attacker-
      controlled proxy, has an out-of-bounds write.
     CVE-2026-94056 EXIM-Security-2026-09-12.2 (GCVE-25-2026-09-55-1)
      Exim before 4.100.1, when Proxy-Protocol is used with an attacker-
      controlled proxy, allows attackers to read certain uninitialized
      data from stack memory.
     CVE-2026-94057 EXIM-Security-2026-09-12.4 (GCVE-25-2026-09-56-1)
      Exim before 4.100.1 allows SMTP smuggling in which the received
      message does not match any sent message, and instead depends on
      crafted data sent after a rejection during DATA processing.
     Closes: #1148506
     (CVE-2026-94055 is not relevant - TLS Early banner support was
     introduced in 4.99.)
Checksums-Sha1: 
 0728494e6b2f1c23310ce38350a9407c74a63312 2929 exim4_4.98.2-1+deb13u5.dsc
 89e08ac252f92df88fc8fef0fa9b9e3cb986be1a 498636 
exim4_4.98.2-1+deb13u5.debian.tar.xz
Checksums-Sha256: 
 cc5147d1cd8c253da7e539e91a226b4683d720514c86be9e541c81a6b65f394f 2929 
exim4_4.98.2-1+deb13u5.dsc
 29e30dd3e189de38055a62324b5a6fcf9f68cb291e944beebbb8eaa20efb3416 498636 
exim4_4.98.2-1+deb13u5.debian.tar.xz
Files: 
 ee66f61601259ca78c83b648f26d2446 2929 mail standard exim4_4.98.2-1+deb13u5.dsc
 9a3c8538308f9d44e75a326a592074f2 498636 mail standard 
exim4_4.98.2-1+deb13u5.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIyBAEBCgAdFiEE0uCSA5741Jbt9PpepU8BhUOCFIQFAmq43oEACgkQpU8BhUOC
FITTBQ/3ZwJ+xhcbAjs/LU8jr5zDk7GG+W7fg3vpH5DAp18tHYgEkXLL1yrb1IWU
1R6aZp46G68bXbFR/9WFPnGLqz0lAGnrbVMexojhhUqKhDWot8d2CjXq+qVRTqh1
uFwSNYFO9WXEM/82Zc4jHVbfinpPvwFDTMi7uWwTszdfqlRzpqXmV6al9R5erFYP
ZbdFLmYObEUyhMhc+U+/qIe/U2bQAKvsLo6mUPo2BLgAXTdZHLK+XGX2eW4KZVj6
jGxK5PHgfkfm25J4zkxqf1a7cZUoBarKTNHsQ5/0McvjiMTYZ4HdSLfOM1IYWCYu
+ovV+gWjk7YBJvpJ2j/6P08cR707L2PB3xBRMh0UaEci3F2Da2UkZjnncGwCHvEJ
Vq2XzBOHrrk9aRxOyV0Ys+38JjFKPNHozZA6esb9kxC6VcVFFVAWlAyz18uiOVnB
XH7PWVyjhY/azPR5HkKYialVRC9xYx8mzuPc6AzlriaR5g2b7pbYHTZ7kQPPihuX
f1woxKqJbPtp8ZsSRKXq4lneA6s2K0abRjQhTzdlttEYWfv49U9bRYXPZw/EcKeM
sPD2i4Z6+Nnnvm6nM95AUTpbM7+/bzdjqyEU76lb9cp3ZgNwd87WB0fR61U4qwWR
scWWFjBCKSXIf3aS/+saF11DjPGK+vOwZgHpMxpqzmII0owUXA==
=iVmN
-----END PGP SIGNATURE-----

Attachment: pgp3HFNJ0nPFD.pgp
Description: PGP signature


--- End Message ---

Reply via email to