Description
Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
Published: 2026-09-19
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: Use‑After‑Free memory corruption
Action: Immediate Patch
AI Analysis

Impact

Exim before 4.100.1, when certain non‑default TLS settings are used with GnuTLS, can trigger a use‑after‑free. This flaw allows an attacker to read or corrupt memory that has already been freed, potentially leading to unpredictable program behavior, including crashes or other forms of denial of service. The vulnerability is classified as CWE‑416.

Affected Systems

Affected systems are Exim mail servers running any version prior to 4.100.1. The issue appears when non‑default GnuTLS TLS configurations are applied; all earlier releases are vulnerable until the version that includes the fix is deployed.

Risk and Exploitability

With a CVSS score of 3.7 the risk is considered moderate; the EPSS score is not available, and the flaw is not listed in CISA KEV. The attack vector is likely remote via a TLS connection, as the vulnerability is exercised through non‑default TLS settings. Successful exploitation could lead to memory corruption, resulting in crashes or irregular behavior, but the current data does not indicate direct code execution or data exfiltration.

Generated by OpenCVE AI on September 20, 2026 at 00:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Exim version 4.100.1 or later to apply the patch that removes the use‑after‑free condition.
  • Ensure that the server’s TLS configuration does not rely on non‑default GnuTLS options that trigger the vulnerability; revert to default settings or consult the Exim documentation for safe TLS options.
  • After upgrading and re‑configuring, monitor mail logs for TLS negotiation errors or unexpected crashes, and verify that the issue no longer occurs.

Generated by OpenCVE AI on September 20, 2026 at 00:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Exim with GnuTLS TLS Configurations

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Description Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
First Time appeared Exim
Exim exim
Weaknesses CWE-416
CPEs cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:*
Vendors & Products Exim
Exim exim
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-19T22:48:57.996Z

Reserved: 2026-09-19T22:48:57.608Z

Link: CVE-2026-94055

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-19T23:17:10.973

Modified: 2026-09-19T23:17:10.973

Link: CVE-2026-94055

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:30:16Z

Weaknesses