New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution
ID: 4268e55b-15fa-576a-a500-c3fe3da4692a
STIX ID: report--4268e55b-15fa-576a-a500-c3fe3da4692a
Feed Name: The Hacker News
Threat Score
Exim released security updates to fix CVE-2026-45185 (Dead.Letter), a use-after-free in BDAT message parsing when a TLS close_notify is received under GnuTLS, which can corrupt heap allocator metadata and enable potential remote code execution on Exim builds compiled with USE_GNUTLS=yes (affecting versions 4.97–4.99.2); users should upgrade to 4.99.3 immediately as no mitigations are available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
