This bug was fixed in the package exim4 - 4.99.4-1ubuntu1
---------------
exim4 (4.99.4-1ubuntu1) stonking; urgency=medium
* Merge with Debian unstable (LP: #2154099). Remaining changes:
- Show Ubuntu distribution in SMTP banner
+ d/p/fix_smtp_banner.patch: Show Ubuntu distribution
in SMTP banner.
+ d/control: Build-Depends on lsb-release to detect Distribution.
- Disable external SPF support to avoid Build-Depends on libspf2-dev
(only available in universe). SPF can still be implemented via
spf-tools-perl, as documented in exim4.conf.template. This reverts
Vcs-Git commit 494f1fe, first released in 4.95~RC0-1.
(LP #1952738)
+ d/control: drop Build-Depends on libspf2-dev.
+ d/EDITME.exim4-heavy.diff: disable support for libspf2.
+ d/d/c/a/30_exim4-config_check_rcpt: restore SPF logic based
on spfquery.mail-spf-perl from spf-tools-perl, but without
the previously supported helo detection.
* New changes:
- Disable SPF for exim4-daemon-mod
+ d/EDITME.exim4-mod.diff, d/control: remove SUPPORT_SPF, remove
the package exim4-mod-spf
+ d/t/spf-disabled: add test to check spf support removal
- d/control: remove systemd-standalone-tmpfiles dep
as it is in universe and needed only for non systemd systems.
* Dropped changes:
- SECURITY UPDATE: Multiple security issues
- debian/patches/CVE-2026-4068x.patch: backported upstream fix.
- CVE-2026-40685 - Possible OOB read/write on corrupt JSON in header
- CVE-2026-40686 - Possible OOB read with large UTF8 trailing chars
- CVE-2026-40687 - Possible OOB read/write with SPA authenticator
[Fixes in upstream 4.99.2]
- SECURITY UPDATE: one-byte write into freed buffer (LP 2152202)
- debian/patches/202605011-security.patch: TLS: on rxd close with CHUNKING
active, clean the input processing stack in src/functions.h,
src/smtp_in.c, src/tls-gnu.c, src/tls-openssl.c.
- unknown
[Fixes in upstream 4.99.3, backported to Debian 4.99.2-2]
- SECURITY UPDATE: information disclosure in PROXYv2 (LP 2154366)
- debian/patches/202605191-security.patch: Security: fix PROXYv2
uninitialised-stack disclosure (EXIM-Security-2026-05-16.1) in
src/proxy.c.
- CVE number pending
[Fixes in upstream v4.99.4, backported to Debian 4.99.3-2]
-- Hector Cao <[email protected]> Fri, 03 Jul 2026 16:35:04
+0200
** Changed in: exim4 (Ubuntu)
Status: In Progress => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2026-4068
** CVE added: https://cve.org/CVERecord?id=CVE-2026-40685
** CVE added: https://cve.org/CVERecord?id=CVE-2026-40686
** CVE added: https://cve.org/CVERecord?id=CVE-2026-40687
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2154099
Title:
Merge exim4 from Debian for stonking cycle
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/exim4/+bug/2154099/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs