PT-2026-40334 · Gnu+1 · Gnutls+1
Published
2026-05-12
·
Updated
2026-05-12
·
CVE-2026-45185
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Exim versions 4.97 through 4.99.2
Description
A use-after-free flaw exists in the BDAT (CHUNKING) SMTP extension when Exim is built with GnuTLS. An unauthenticated attacker can trigger this issue by prematurely terminating a TLS session during a binary data transfer, causing the system to write data into a freed memory buffer. This leads to heap corruption, which can be leveraged to achieve remote code execution.
Recommendations
Upgrade to version 4.99.3.
Fix
DoS
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exim
Gnutls