New Exim BDAT GnuTLS Vulnerability Enables Code Execution Attacks
ID: 7860bfd7-0d47-5dcc-a7de-3091694f7c51
STIX ID: report--7860bfd7-0d47-5dcc-a7de-3091694f7c51
Feed Name: cybersecurityNews.com
**Exim BDAT GnuTLS vulnerability (EXIM-Security-2026-05-01.1):** A use-after-free in Exim's GnuTLS backend can be triggered when a TLS close_notify is sent mid-BDAT transfer and one additional plaintext byte is sent, enabling heap corruption and potential remote code execution on Exim builds compiled with USE_GNUTLS=yes (affecting 4.97–4.99.2); Exim released 4.99.3 on May 12, 2026 to fix the issue and administrators are urged to upgrade immediately as no mitigation other than patching is available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
