CVE-2026-45185

EUVD-2026-29824
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 65.96%
Affected Products (NVD)
VendorProductVersion
eximexim
4.97 ≤
𝑥
< 4.99.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
exim4
bookworm
4.96-15+deb12u10
fixed
bookworm (security)
4.96-15+deb12u10
fixed
bullseye
vulnerable
bullseye (security)
4.94.2-7+deb11u6
fixed
forky
4.99.4-2
fixed
sid
4.99.4-2
fixed
trixie
4.98.2-1+deb13u3
fixed
trixie (security)
4.98.2-1+deb13u4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
exim4
bionic
ignored
focal
Fixed 4.93-13ubuntu1.12+esm1
released
jammy
Fixed 4.95-4ubuntu2.8
released
noble
Fixed 4.97-4ubuntu4.5
released
questing
Fixed 4.98.2-1ubuntu2.2
released
resolute
Fixed 4.99.1-1ubuntu1.2
released
trusty
ignored
xenial
ignored