Bug 2476995 - CVE-2026-45185 exim: Exim: Arbitrary code execution via use-after-free in BDAT body parsing. [fedora-all]
Summary: CVE-2026-45185 exim: Exim: Arbitrary code execution via use-after-free in BDA...
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: exim
Version: rawhide
Hardware: Unspecified
OS: Unspecified
urgent
urgent
Target Milestone: ---
Assignee: Jaroslav Škarvada
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["a4eece6e-ec81-4306-aaa9-c...
: 2476498 (view as bug list)
Depends On:
Blocks: CVE-2026-45185
TreeView+ depends on / blocked
 
Reported: 2026-05-13 12:33 UTC by Keith Grant
Modified: 2026-05-19 16:30 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-05-19 16:30:34 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Keith Grant 2026-05-13 12:33:35 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Jaroslav Škarvada 2026-05-14 13:16:50 UTC
Fixing only in Rawhide, OpenSSL builds shouldn't be vulnerable (AFAIK).

Comment 2 Jaroslav Škarvada 2026-05-18 17:23:44 UTC
*** Bug 2476498 has been marked as a duplicate of this bug. ***

Comment 3 Jaroslav Škarvada 2026-05-19 16:30:34 UTC
Closing as rawhide, feel free to reopen if other versions are also vulnerable.


Note You need to log in before you can comment on or make changes to this bug.