9.8 Critical Alert: One-Byte Heap Corruption in Exim Exposes Global Mail Servers to Takeover
ID: 1c0053ea-8a42-5a6b-a78c-fd2c63e0ec2d
STIX ID: report--1c0053ea-8a42-5a6b-a78c-fd2c63e0ec2d
Feed Name: securityonline.info
Threat Score
A critical Exim vulnerability (CVE-2026-45185, CVSS 9.8) in the GnuTLS integration allows remote heap corruption and potential server takeover when a malicious client uses BDAT over TLS and sends a TLS close_notify followed by a final cleartext byte; Exim versions 4.97–4.99.2 built with USE_GNUTLS=yes are affected and Exim 4.99.3 patches the issue by resetting input processing on TLS close.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
