PT-2026-40334 · Gnu+4 · Gnutls+4
CVE-2026-45185
·
Published
2026-05-12
·
Updated
2026-07-29
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Exim versions 4.97 through 4.99.2
Description
Exim contains a use-after-free memory corruption issue in the BDAT body parsing path, specifically affecting builds compiled with GnuTLS. The issue occurs during a CHUNKING transfer when a client sends a TLS close notify alert before the body is complete, followed by a final cleartext byte on the same TCP connection. This sequence causes the BDAT receive wrapper to call the
ungetc() function and write a byte into memory that has already been freed, which can corrupt allocator metadata. An unauthenticated remote attacker can exploit this to cause a denial of service or execute arbitrary code. It is estimated that over 3.7 million services worldwide may be affected.Recommendations
Update Exim to version 4.99.3.
As a temporary mitigation, restrict the use of the BDAT extension or limit SMTP access to minimize the risk of exploitation.
Exploit
Fix
LPE
DoS
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exim
Gnutls
Linuxmint
Red Os
Ubuntu