Description
Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
Published: 2026-09-19
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free memory corruption
Action: Immediate Patch
AI Analysis

Impact

Exim before 4.100.1, when certain non‑default TLS settings are used with GnuTLS, can trigger a use‑after‑free. This flaw allows an attacker to read or corrupt memory that has already been freed, potentially leading to unpredictable program behavior, including crashes or other forms of denial of service. The vulnerability is classified as CWE‑416.

Affected Systems

Affected systems are Exim mail servers running any version prior to 4.100.1. The issue appears when non‑default GnuTLS TLS configurations are applied; all earlier releases are vulnerable until the version that includes the fix is deployed.

Risk and Exploitability

With a CVSS score of 3.7 the risk is considered moderate; the EPSS score is not available, and the flaw is not listed in CISA KEV. The attack vector is likely remote via a TLS connection, as the vulnerability is exercised through non‑default TLS settings. Successful exploitation could lead to memory corruption, resulting in crashes or irregular behavior, but the current data does not indicate direct code execution or data exfiltration.

Generated by OpenCVE AI on September 20, 2026 at 00:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Exim version 4.100.1 or later to apply the patch that removes the use‑after‑free condition.
  • Ensure that the server’s TLS configuration does not rely on non‑default GnuTLS options that trigger the vulnerability; revert to default settings or consult the Exim documentation for safe TLS options.
  • After upgrading and re‑configuring, monitor mail logs for TLS negotiation errors or unexpected crashes, and verify that the issue no longer occurs.

Generated by OpenCVE AI on September 20, 2026 at 00:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8834-1 Exim vulnerabilities
History

Thu, 24 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Exim with GnuTLS TLS Configurations exim: gnutls: Exim: Use-after-free vulnerability in GnuTLS TLS settings leading to denial of service
References
Metrics threat_severity

None

threat_severity

Low


Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Exim with GnuTLS TLS Configurations

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Description Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
First Time appeared Exim
Exim exim
Weaknesses CWE-416
CPEs cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:*
Vendors & Products Exim
Exim exim
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-21T15:19:07.403Z

Reserved: 2026-09-19T22:48:57.608Z

Link: CVE-2026-94055

cve-icon Vulnrichment

Updated: 2026-09-21T15:18:58.543Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-19T23:17:10.973

Modified: 2026-09-24T20:45:59.800

Link: CVE-2026-94055

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-19T22:48:57Z

Links: CVE-2026-94055 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:15:16Z

Weaknesses