Re: [BSA-135] Security Update for exim4

Agnes Newcombe <[email protected]> Sat, 30 May 2026 23:30:54 +0100
Newsgroups gmane.linux.debian.backports.general
Message-ID <CAEL8SJUt5ri9fPqA7vSPhX0+9SJ+kC+SwsaT7ByEf5F_ateMgg@mail.gmail.com>
--00000000000059addd0653108460
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

CVE-2026-48840
  PROXYv2 parser: reject PROXY frames whose declared payload
  length is too short for the claimed address family (12 bytes for

On Sat, May 30, 2026 at 3:39=E2=80=AFPM Andreas Metzler <[email protected]=
g> wrote:

> Andreas Metzler uploaded new packages for exim4 which fixed the
> following security problems:
>
> CVE-2026-48840
>   PROXYv2 parser: reject PROXY frames whose declared payload
>   length is too short for the claimed address family (12 bytes for
>   TCPv4/0x11, 36 bytes for TCPv6/0x21).  Previously a frame with
>   family=3D0x21 and len=3D0 caused 16 bytes of uninitialized stack to be
>   formatted as the sender's IPv6 address and disclosed in the SMTP
>   greeting banner.  Affects configurations with SUPPORT_PROXY and
>   `hosts_proxy` set.  Reported by Warisjeet Singh (sin99xx).
>   EXIM-Security-2026-05-19.1
>
> For the trixie-backports distribution the problem has been fixed in
> version 4.99.3-2~bpo13+1.
>

--00000000000059addd0653108460
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr">CVE-2026-48840<br>=C2=A0 PROXYv2 parser: =
reject PROXY frames whose declared payload<br>=C2=A0 length is too short fo=
r the claimed address family (12 bytes for</div><br><div class=3D"gmail_quo=
te gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Sat, May=
 30, 2026 at 3:39=E2=80=AFPM Andreas Metzler &lt;<a href=3D"mailto:ametzler=
@debian.org">[email protected]</a>&gt; wrote:<br></div><blockquote class=
=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rg=
b(204,204,204);padding-left:1ex">Andreas Metzler uploaded new packages for =
exim4 which fixed the<br>
following security problems:<br>
<br>
CVE-2026-48840<br>
=C2=A0 PROXYv2 parser: reject PROXY frames whose declared payload<br>
=C2=A0 length is too short for the claimed address family (12 bytes for<br>
=C2=A0 TCPv4/0x11, 36 bytes for TCPv6/0x21).=C2=A0 Previously a frame with<=
br>
=C2=A0 family=3D0x21 and len=3D0 caused 16 bytes of uninitialized stack to =
be<br>
=C2=A0 formatted as the sender&#39;s IPv6 address and disclosed in the SMTP=
<br>
=C2=A0 greeting banner.=C2=A0 Affects configurations with SUPPORT_PROXY and=
<br>
=C2=A0 `hosts_proxy` set.=C2=A0 Reported by Warisjeet Singh (sin99xx).<br>
=C2=A0 EXIM-Security-2026-05-19.1<br>
<br>
For the trixie-backports distribution the problem has been fixed in<br>
version 4.99.3-2~bpo13+1.<br>
</blockquote></div></div>

--00000000000059addd0653108460--