Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-40684

Опубликовано: 30 апр. 2026
Источник: debian
EPSS Низкий

Описание

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
exim4fixed4.99.2-1package

Примечания

  • Fixed by: https://code.exim.org/exim/exim/commit/628bbaca7672748d941a12e7cd5f0122a4e18c81

  • Debian builds with glibc

EPSS

Процентиль: 29%
0.00362
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
4 месяца назад

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

CVSS3: 5.9
nvd
4 месяца назад

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

CVSS3: 7.5
redos
20 дней назад

Уязвимость exim

CVSS3: 5.9
github
4 месяца назад

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

EPSS

Процентиль: 29%
0.00362
Низкий