Re: exim-4.99.3 in exim/exim released
Andrew C Aitchison via Exim-dev <[email protected]> Fri, 15 May 2026 20:11:37 +0100 (BST)
| Newsgroups | gmane.mail.exim.devel |
|---|---|
| Message-ID | <[email protected]> |
Is this security fix included in the development tree yet ?
My git is configured to look at
https://code.exim.org/exim/exim.git
but I cannot see the fixes there. Am I looking in the right place ?
Thanks,
On Tue, 12 May 2026, HeikoSchlittermann via Exim-dev wrote:
> *@HeikoSchlittermann* released exim-4.99.3 ( https://code.exim.org/exim/exim/releases/tag/exim-4.99.3 ) in exim/exim ( https://code.exim.org/exim/exim )
>
> Title: exim-4.99.3
>
> Note:
>
> -------------------
> Exim version 4.99.3
> -------------------
>
> This is a security release addressing Exim-Security-2026-05-01.1.
> A CVE number isn't assigned yet.
>
> JH/01 GnuTLS: when a TLS close alert was received with CHUNKING still active
> a one-byte write into a freed buffer was possible. Fix by reinstating
> the plaintext input handlers on TLS close while maintaining the bdat
> handlers.
>
> ---
> Downloads:
>
> * *Source Code (ZIP)* ( https://code.exim.org/exim/exim/archive/exim-4.99.3.zip )
> * *Source Code (TAR.GZ)* ( https://code.exim.org/exim/exim/archive/exim-4.99.3.tar.gz )
>
> ---
> View it on Exim Forgejo ( https://code.exim.org/exim/exim/releases/tag/exim-4.99.3 ).
--
Andrew C. Aitchison Kendal, UK
[email protected]