Source: exim4 Version: 4.100-3 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for exim4. Andreas, I'm putting this at RC level, but I'm not sure how common exploitable setups are for the more severe ones. CVE-2026-94054[0]: | Exim before 4.100.1, when Proxy-Protocol is used with an attacker- | controlled proxy, has an out-of-bounds write. CVE-2026-94055[1]: | Exim before 4.100.1, when certain non-default TLS settings are used | with GnuTLS, has a use-after-free. CVE-2026-94056[2]: | Exim before 4.100.1, when Proxy-Protocol is used with an attacker- | controlled proxy, allows attackers to read certain uninitialized | data from stack memory. CVE-2026-94057[3]: | Exim before 4.100.1 allows SMTP smuggling in which the received | message does not match any sent message, and instead depends on | crafted data sent after a rejection during DATA processing. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-94054 https://www.cve.org/CVERecord?id=CVE-2026-94054 [1] https://security-tracker.debian.org/tracker/CVE-2026-94055 https://www.cve.org/CVERecord?id=CVE-2026-94055 [2] https://security-tracker.debian.org/tracker/CVE-2026-94056 https://www.cve.org/CVERecord?id=CVE-2026-94056 [3] https://security-tracker.debian.org/tracker/CVE-2026-94057 https://www.cve.org/CVERecord?id=CVE-2026-94057 [4] https://lists.exim.org/lurker/message/20260918.121220.0f87338e.en.html Please adjust the affected versions in the BTS as needed. Regards, Salvatore

