This bug was fixed in the package exim4 - 4.99.4-1ubuntu1

---------------
exim4 (4.99.4-1ubuntu1) stonking; urgency=medium

  * Merge with Debian unstable (LP: #2154099). Remaining changes:
    - Show Ubuntu distribution in SMTP banner
      + d/p/fix_smtp_banner.patch: Show Ubuntu distribution
        in SMTP banner.
      + d/control: Build-Depends on lsb-release to detect Distribution.
    - Disable external SPF support to avoid Build-Depends on libspf2-dev
      (only available in universe). SPF can still be implemented via
      spf-tools-perl, as documented in exim4.conf.template. This reverts
      Vcs-Git commit 494f1fe, first released in 4.95~RC0-1.
      (LP #1952738)
      + d/control: drop Build-Depends on libspf2-dev.
      + d/EDITME.exim4-heavy.diff: disable support for libspf2.
      + d/d/c/a/30_exim4-config_check_rcpt: restore SPF logic based
        on spfquery.mail-spf-perl from spf-tools-perl, but without
        the previously supported helo detection.
  * New changes:
    - Disable SPF for exim4-daemon-mod
      + d/EDITME.exim4-mod.diff, d/control: remove SUPPORT_SPF, remove
        the package exim4-mod-spf
      + d/t/spf-disabled: add test to check spf support removal
    - d/control: remove systemd-standalone-tmpfiles dep
      as it is in universe and needed only for non systemd systems.
  * Dropped changes:
    - SECURITY UPDATE: Multiple security issues
      - debian/patches/CVE-2026-4068x.patch: backported upstream fix.
      - CVE-2026-40685 - Possible OOB read/write on corrupt JSON in header
      - CVE-2026-40686 - Possible OOB read with large UTF8 trailing chars
      - CVE-2026-40687 - Possible OOB read/write with SPA authenticator
      [Fixes in upstream 4.99.2]
    - SECURITY UPDATE: one-byte write into freed buffer (LP 2152202)
      - debian/patches/202605011-security.patch: TLS: on rxd close with CHUNKING
        active, clean the input processing stack in src/functions.h,
        src/smtp_in.c, src/tls-gnu.c, src/tls-openssl.c.
      - unknown
      [Fixes in upstream 4.99.3, backported to Debian 4.99.2-2]
    - SECURITY UPDATE: information disclosure in PROXYv2 (LP 2154366)
      - debian/patches/202605191-security.patch: Security: fix PROXYv2
        uninitialised-stack disclosure (EXIM-Security-2026-05-16.1) in
        src/proxy.c.
      - CVE number pending
      [Fixes in upstream v4.99.4, backported to Debian 4.99.3-2]

 -- Hector Cao <[email protected]>  Fri, 03 Jul 2026 16:35:04
+0200

** Changed in: exim4 (Ubuntu)
       Status: In Progress => Fix Released

** CVE added: https://cve.org/CVERecord?id=CVE-2026-4068

** CVE added: https://cve.org/CVERecord?id=CVE-2026-40685

** CVE added: https://cve.org/CVERecord?id=CVE-2026-40686

** CVE added: https://cve.org/CVERecord?id=CVE-2026-40687

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2154099

Title:
  Merge exim4 from Debian for stonking cycle

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/exim4/+bug/2154099/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to