CVE-2026-45185 - need more information and clarifications
Fabio Muzzi via Exim-users <[email protected]> Thu, 14 May 2026 16:28:58 +0200
| Newsgroups | gmane.mail.exim.user |
|---|---|
| Message-ID | <[email protected]> |
Hi everyone, I'm a long time Exim user (since version 3) and I'm very alarmed by this new CVE-2026-45185. I have already applied patches (Debian packages) to all of the servers where I don't have an old unsupported version of Debian. Sadly, for a lot of reasons, I still have some older Debian installations that are not receiving patches anymore. While I know it's time to update these, I'm currently in need of a mitigation and a clarification. First of all, the clarification: the official Exim information (https://exim.org/static/doc/security/EXIM-Security-2026-05-01.1/EXIM-Security-2026-05-01.1.txt) states that the bug "Affects: Exim 4.97 up to and including 4.99.2" Does this mean that prior to 4.97 the bug was not there, or does this mean that no one cared to look for it, but the bug is in fact there since forever? Second, the mitigation: setting "chunking_advertise_hosts=" to a null list, thus disabling chunking support for all remote hosts is enough to mitigate the risk until I can upgrade the servers? This seems to be the case, but I'm not sure. Thanks -- Fabio Muzzi -- ## subscription configuration (requires account): ## https://lists.exim.org/mailman3/postorius/lists/exim-users.lists.exim.org/ ## unsubscribe (doesn't require an account): ## [email protected] ## Exim details at https://www.exim.org/ ## Please use the Wiki with this list - https://code.exim.org/exim/wiki/wiki