PT-2026-40334 · Gnu+4 · Gnutls+4

CVE-2026-45185

·

Published

2026-05-12

·

Updated

2026-07-29

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Exim versions 4.97 through 4.99.2
Description Exim contains a use-after-free memory corruption issue in the BDAT body parsing path, specifically affecting builds compiled with GnuTLS. The issue occurs during a CHUNKING transfer when a client sends a TLS close notify alert before the body is complete, followed by a final cleartext byte on the same TCP connection. This sequence causes the BDAT receive wrapper to call the ungetc() function and write a byte into memory that has already been freed, which can corrupt allocator metadata. An unauthenticated remote attacker can exploit this to cause a denial of service or execute arbitrary code. It is estimated that over 3.7 million services worldwide may be affected.
Recommendations Update Exim to version 4.99.3. As a temporary mitigation, restrict the use of the BDAT extension or limit SMTP access to minimize the risk of exploitation.

Exploit

Fix

LPE

DoS

RCE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06520
CVE-2026-45185
USN-8270-1
USN-8382-1

Affected Products

Exim
Gnutls
Linuxmint
Red Os
Ubuntu