PT-2026-36197 · Exim+2 · Exim+2

Bernard Quatermass

·

Published

2026-04-29

·

Updated

2026-05-04

·

CVE-2026-40686

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Exim versions prior to 4.99.2
Description An out-of-bounds read occurs when utf8 operators are enabled and malformed UTF-8 header data containing large UTF-8 trailing characters is processed. This may lead to the disclosure of information within an error message generated during the handling of an unrelated e-mail message.
Recommendations Update to version 4.99.2 or later.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-40686
USN-8228-1

Affected Products

Exim
Linuxmint
Ubuntu