Re: exim-4.99.3 in exim/exim released

Andrew C Aitchison via Exim-dev <[email protected]> Fri, 15 May 2026 20:11:37 +0100 (BST)
Newsgroups gmane.mail.exim.devel
Message-ID <[email protected]>
Is this security fix included in the development tree yet ?

My git is configured to look at
 	https://code.exim.org/exim/exim.git
but I cannot see the fixes there. Am I looking in the right place ?

Thanks,

On Tue, 12 May 2026, HeikoSchlittermann via Exim-dev wrote:

> *@HeikoSchlittermann* released exim-4.99.3 ( https://code.exim.org/exim/exim/releases/tag/exim-4.99.3 ) in exim/exim ( https://code.exim.org/exim/exim )
>
> Title: exim-4.99.3
>
> Note:
>
> -------------------
> Exim version 4.99.3
> -------------------
>
> This is a security release addressing Exim-Security-2026-05-01.1.
> A CVE number isn't assigned yet.
>
> JH/01 GnuTLS: when a TLS close alert was received with CHUNKING still active
> a one-byte write into a freed buffer was possible. Fix by reinstating
> the plaintext input handlers on TLS close while maintaining the bdat
> handlers.
>
> ---
> Downloads:
>
> * *Source Code (ZIP)* ( https://code.exim.org/exim/exim/archive/exim-4.99.3.zip )
> * *Source Code (TAR.GZ)* ( https://code.exim.org/exim/exim/archive/exim-4.99.3.tar.gz )
>
> ---
> View it on Exim Forgejo ( https://code.exim.org/exim/exim/releases/tag/exim-4.99.3 ).

-- 
Andrew C. Aitchison                      Kendal, UK
                    [email protected]