logo

New Exim BDAT GnuTLS Vulnerability Enables Code Execution Attacks

ID: 7860bfd7-0d47-5dcc-a7de-3091694f7c51

STIX ID: report--7860bfd7-0d47-5dcc-a7de-3091694f7c51

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-13

Date Updated: 2026-05-14

Author: Tushar Subhra Dutta

...
...

**Exim BDAT GnuTLS vulnerability (EXIM-Security-2026-05-01.1):** A use-after-free in Exim's GnuTLS backend can be triggered when a TLS close_notify is sent mid-BDAT transfer and one additional plaintext byte is sent, enabling heap corruption and potential remote code execution on Exim builds compiled with USE_GNUTLS=yes (affecting 4.97–4.99.2); Exim released 4.99.3 on May 12, 2026 to fix the issue and administrators are urged to upgrade immediately as no mitigation other than patching is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.