logo

New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution

ID: 4268e55b-15fa-576a-a500-c3fe3da4692a

STIX ID: report--4268e55b-15fa-576a-a500-c3fe3da4692a

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: [email protected] (The Hacker News)

...
...

Exim released security updates to fix CVE-2026-45185 (Dead.Letter), a use-after-free in BDAT message parsing when a TLS close_notify is received under GnuTLS, which can corrupt heap allocator metadata and enable potential remote code execution on Exim builds compiled with USE_GNUTLS=yes (affecting versions 4.97–4.99.2); users should upgrade to 4.99.3 immediately as no mitigations are available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.