Re: [BSA-135] Security Update for exim4
Agnes Newcombe <[email protected]> Sat, 30 May 2026 23:30:54 +0100
| Newsgroups | gmane.linux.debian.backports.general |
|---|---|
| Message-ID | <CAEL8SJUt5ri9fPqA7vSPhX0+9SJ+kC+SwsaT7ByEf5F_ateMgg@mail.gmail.com> |
--00000000000059addd0653108460 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable CVE-2026-48840 PROXYv2 parser: reject PROXY frames whose declared payload length is too short for the claimed address family (12 bytes for On Sat, May 30, 2026 at 3:39=E2=80=AFPM Andreas Metzler <[email protected]= g> wrote: > Andreas Metzler uploaded new packages for exim4 which fixed the > following security problems: > > CVE-2026-48840 > PROXYv2 parser: reject PROXY frames whose declared payload > length is too short for the claimed address family (12 bytes for > TCPv4/0x11, 36 bytes for TCPv6/0x21). Previously a frame with > family=3D0x21 and len=3D0 caused 16 bytes of uninitialized stack to be > formatted as the sender's IPv6 address and disclosed in the SMTP > greeting banner. Affects configurations with SUPPORT_PROXY and > `hosts_proxy` set. Reported by Warisjeet Singh (sin99xx). > EXIM-Security-2026-05-19.1 > > For the trixie-backports distribution the problem has been fixed in > version 4.99.3-2~bpo13+1. > --00000000000059addd0653108460 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr">CVE-2026-48840<br>=C2=A0 PROXYv2 parser: = reject PROXY frames whose declared payload<br>=C2=A0 length is too short fo= r the claimed address family (12 bytes for</div><br><div class=3D"gmail_quo= te gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Sat, May= 30, 2026 at 3:39=E2=80=AFPM Andreas Metzler <<a href=3D"mailto:ametzler= @debian.org">[email protected]</a>> wrote:<br></div><blockquote class= =3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rg= b(204,204,204);padding-left:1ex">Andreas Metzler uploaded new packages for = exim4 which fixed the<br> following security problems:<br> <br> CVE-2026-48840<br> =C2=A0 PROXYv2 parser: reject PROXY frames whose declared payload<br> =C2=A0 length is too short for the claimed address family (12 bytes for<br> =C2=A0 TCPv4/0x11, 36 bytes for TCPv6/0x21).=C2=A0 Previously a frame with<= br> =C2=A0 family=3D0x21 and len=3D0 caused 16 bytes of uninitialized stack to = be<br> =C2=A0 formatted as the sender's IPv6 address and disclosed in the SMTP= <br> =C2=A0 greeting banner.=C2=A0 Affects configurations with SUPPORT_PROXY and= <br> =C2=A0 `hosts_proxy` set.=C2=A0 Reported by Warisjeet Singh (sin99xx).<br> =C2=A0 EXIM-Security-2026-05-19.1<br> <br> For the trixie-backports distribution the problem has been fixed in<br> version 4.99.3-2~bpo13+1.<br> </blockquote></div></div> --00000000000059addd0653108460--