A corrective release of the Exim mail server 4.99.4 has been published, which fixes a vulnerability (CVE-2026-48840) that leads to the leakage of 16 uninitialized bytes from the stack of the handler process in the client-facing information about the IPv6 address in the SMTP Hello header. In practice, the fixed leak can be used when exploiting other vulnerabilities to determine the memory layout in configurations with Address Space Layout Randomization (ASLR).
The issue manifests starting from Exim version 4.88 (2017) in systems using the hosts_proxy setting and Exim builds compiled with the SUPPORT_PROXY option (default in Debian, Ubuntu, RHEL EPEL, and Fedora). The vulnerability is caused by the lack of proper frame size validation when processing requests using the PROXYv2 protocol.
Source: opennet.ru
