CVE-2026-40684

NameCVE-2026-40684
DescriptionIn Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6265-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
exim4 (PTS)bookworm, bookworm (security)4.96-15+deb12u10fixed
trixie (security), trixie4.98.2-1+deb13u4fixed
forky, sid4.100-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
exim4sourcebookworm4.96-15+deb12u9DSA-6265-1
exim4sourcetrixie4.98.2-1+deb13u2DSA-6265-1
exim4source(unstable)4.99.2-1unimportant

Notes

Fixed by: https://code.exim.org/exim/exim/commit/628bbaca7672748d941a12e7cd5f0122a4e18c81
Debian builds with glibc

Search for package or bug name: Reporting problems