Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-45185

Опубликовано: 12 мая 2026
Источник: ubuntu
Приоритет: high
EPSS Низкий
CVSS3: 9.8

Описание

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

РелизСтатусПримечание
devel

released

4.99.1-1ubuntu2
esm-infra-legacy/trusty

ignored

changes too intrusive
esm-infra-legacy/xenial

ignored

changes too intrusive
esm-infra/bionic

ignored

changes too intrusive
esm-infra/focal

released

4.93-13ubuntu1.12+esm1
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

released

4.95-4ubuntu2.8
noble

released

4.97-4ubuntu4.5
questing

released

4.98.2-1ubuntu2.2
resolute

released

4.99.1-1ubuntu1.2

Показывать по

EPSS

Процентиль: 66%
0.01225
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
3 месяца назад

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

CVSS3: 9.8
debian
3 месяца назад

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely r ...

CVSS3: 9.8
github
3 месяца назад

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

CVSS3: 9.8
fstec
3 месяца назад

Уязвимость функции ungetc() компонента BDAT/CHUNKING почтового сервера Exim, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
redos
12 дней назад

Уязвимость exim

EPSS

Процентиль: 66%
0.01225
Низкий

9.8 Critical

CVSS3

Уязвимость CVE-2026-45185