CVE-2026-94054

7.0

Exim · Exim

Exim versions prior to 4.100.1 contain an out-of-bounds write vulnerability when utilizing the Proxy-Protocol with an attacker-controlled proxy.

Executive summary

A critical out-of-bounds write vulnerability in Exim allows unauthenticated attackers to potentially corrupt memory or execute arbitrary code when processing malicious Proxy-Protocol traffic.

Vulnerability

This vulnerability is caused by an out-of-bounds write (CWE-787) occurring during the processing of Proxy-Protocol headers. The flaw is reachable by unauthenticated remote attackers who can manipulate the proxy connection to trigger memory corruption.

Business impact

Successful exploitation of this memory corruption vulnerability poses a significant risk to mail server availability and integrity. Given the CVSS score of 7.0, an attacker could potentially crash the mail service, leading to denial of service, or achieve unauthorized code execution to compromise sensitive email data, causing severe operational and reputational damage.

Remediation

Immediate Action: Upgrade your Exim installation to version 4.100.1 or later immediately to incorporate the necessary memory safety fixes.

Proactive Monitoring: Monitor mail server logs for unusual connection patterns or frequent service restarts that may indicate attempted exploitation of the Proxy-Protocol handling.

Compensating Controls: If immediate patching is not possible, disable the use of Proxy-Protocol in your Exim configuration if it is not strictly required for your network architecture.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The presence of an out-of-bounds write vulnerability in a core mail transfer agent requires immediate attention. Security teams should prioritize the deployment of the 4.100.1 patch across all exposed Exim instances. Verify your current version and apply the vendor-supplied update to eliminate this risk to your messaging infrastructure.

More Exim CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources