CVE-2026-40684
גבוהה 7.5
תיאור (מקור, אנגלית)
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-30/7/2026
- CWE
- CWE-684
מוצרים מושפעים
exim: exim
קישורים
- https://exim.org/static/doc/security/cve-2026-04.1/CVE2026-40684.assessment Vendor Advisory
- https://code.exim.org/exim/exim/commit/628bbaca7672748d941a12e7cd5f0122a4e18c81 Patch
- https://exim.org/static/doc/security/CVE-2026-40684.txt Broken Link
- https://www.openwall.com/lists/oss-security/2026/04/30/21 Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2026/05/01/11