Update of the Exim mail server 4.99.2 addressing 4 vulnerabilities

A corrective release of the Exim mail server 4.99.2 has been published, fixing 4 vulnerabilities:

  • CVE-2026-40685 — buffer overflow for reading and writing when processing JSON data in the email header.
  • CVE-2026-40686 — reading data from outside the buffer boundaries when processing specially formatted UTF-8 characters at the end of headers. This vulnerability may lead to data leakage from memory in returned error messages.
  • CVE-2026-40687 — buffer overflow for reading and writing in configurations using the SPA (Simple Password Authentication) driver. This vulnerability can be exploited when accessed by an attacker-controlled entity. server SPA/NTLM.
  • CVE-2026-40684 — process crash when handling specially formatted data in PTR DNS records. This vulnerability only manifests on systems with musl libc.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster