Bug 2476498 - [EXIM-Security-2026-05-01.1] Security Advisory
Summary: [EXIM-Security-2026-05-01.1] Security Advisory
Keywords:
Status: CLOSED DUPLICATE of bug 2476995
Alias: None
Product: Fedora
Classification: Fedora
Component: exim
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
urgent
Target Milestone: ---
Assignee: Jaroslav Škarvada
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-12 15:43 UTC by customercare
Modified: 2026-05-18 17:23 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-05-18 17:23:44 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description customercare 2026-05-12 15:43:51 UTC
### NOT VULNERABLE, WE USE OPENSSL ###


Hello,

The Exim maintainers are releasing an important security update to address a critical vulnerability affecting certain Exim configurations.

Vulnerability Details

A remotely reachable Use-After-Free (UAF) vulnerability has been identified in Exim's BDAT (binary data transmission) body parsing path when using the GnuTLS backend. This vulnerability can lead to heap corruption and potential code execution.

Affected Versions and Configurations

This vulnerability affects Exim versions 4.97 through 4.99.x that:
- Are built with GnuTLS support
- Have STARTTLS and CHUNKING advertised

Recommended Action

We strongly recommend all affected users upgrade to Exim 4.99.3 or later immediately.

Obtaining the Fix

Fixed versions are available:
- Repository: https://code.exim.org/exim/exim (branch: exim-4.99+fixes, tag: exim-4.99.3) (signed by me)
- Tarballs: https://downloads.exim.org/exim4/ (signed by me)
- Please see the Exim website for detailed upgrade instructions

Additional Information

- Distros already have coordinated access to patches
- Internal tracking ID: EXIM-Security-2026-05-01.1
- Full technical details will be available: https://exim.org/static/doc/security/EXIM-Security-2026-05-01.1/

Thank you for your cooperation.
And special thanks to the reporter at xbow security.

    Best regards from Dresden/Germany
    Viele Grüße aus Dresden
    Heiko Schlittermann
-- 
 SCHLITTERMANN.de ---------------------------- internet & unix support -
 Heiko Schlittermann, Dipl.-Ing. (TU)              fon +49.351.8029981 -
 gnupg encrypted messages are welcome --------------- key ID: F69376CE -



----- End forwarded message -----



-- 
## subscription configuration (requires account):
##   https://lists.exim.org/mailman3/postorius/lists/exim-users.lists.exim.org/
## unsubscribe (doesn't require an account):
##   exim-users-unsubscribe.org
## Exim details at https://www.exim.org/
## Please use the Wiki with this list - https://code.exim.org/exim/wiki/wiki

Comment 1 Tim Jackson 2026-05-15 10:33:56 UTC
Although created earlier, this should probably be marked as a duplicate of the "official" tracking bug #2476995

Comment 2 Jaroslav Škarvada 2026-05-18 17:23:44 UTC
OK, I am closing it as a dupe. AFAIK Fedora is not affected, I will update exim only in rawhide.

*** This bug has been marked as a duplicate of bug 2476995 ***


Note You need to log in before you can comment on or make changes to this bug.