USN-8834-1: Exim vulnerabilities
Ubuntu patched Exim flaws, including a Proxy Protocol out-of-bounds write that could allow remote code execution.
Ubuntu Security Notice USN-8834-1 covers multiple Exim vulnerabilities. CVE-2026-94054 is an out-of-bounds write when Proxy Protocol is used with an attacker-controlled proxy, and a remote attacker could possibly execute arbitrary code. CVE-2026-94055 is a use-after-free under certain non-default GnuTLS settings that can crash Exim and affects only Ubuntu 26.04 LTS. A further Proxy Protocol issue could expose uninitialized stack memory; the notice does not report in-the-wild exploitation.
58