VMTech
Discuss a project

Friends — sharing: Dead.Letter vulnerability in Exim (CVE-2026-45185)

Friends — sharing: Dead.Letter vulnerability in Exim (CVE-2026-45185)

From cybersecurity: Exim patched a critical BDAT vulnerability affecting GnuTLS builds.

• What happened: a use-after-free in BDAT parsing when a client sends TLS close_notify then a plaintext byte.
• Affected: Exim 4.97–4.99.2 compiled with USE_GNUTLS=yes.
• Reported by: XBOW (Federico Kirschbaum), disclosure 1 May 2026.
• Mitigation: upgrade to Exim 4.99.3 — no reliable mitigations available.

Why it matters: potential remote code execution on mail servers.

How will you handle Exim upgrades in your infrastructure?

#cybersecurity #exim #GnuTLS #infosec

Open analytics
On the site 10 views
min read 1 12.05.2026
On Instagram 9 views
On Instagram 3 reach
On Instagram 1 likes
Instagram

Friends — sharing: Dead.Letter vulnerability in Exim (CVE-2026-45185)

Open the post on Instagram ↗