ZeroHour

CVE-2026-40684

CVSS 3.1
7.5 high
EPSS
<1%p29
Published
()
Modified
Description

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

Vendors
exim
Products
exim
Weakness
CWE-684
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.