Exim Mail Server 4.100.1 Fixes 4 Security Flaws Including SMTP Smuggling and Heap Corruption
Exim 4.100.1 patches four flaws, including high-severity Proxy Protocol heap corruption, uninitialized data leak, GnuTLS use-after-free, and SMTP smuggling.
Exim released version 4.100.1 on September 18, 2026, fixing four vulnerabilities affecting versions from 4.83 to 4.100 depending on configuration. GCVE-25-2026-09-50-1 is an out-of-bounds write in Proxy Protocol v1 handling allowing a ~230-byte over-read and NUL-byte write; GCVE-25-2026-09-55-1 leaks stack data via uninitialized memory in Proxy Protocol v2 handling. A low-severity GnuTLS use-after-free (GCVE-25-2026-09-51-1) requires the non-default tls_early_banner_hosts setting, and GCVE-25-2026-09-56-1 permits SMTP smuggling that can alter submitted email content. Administrator upgrades to 4.100.1 are strongly advised; issues were reported by McCaulay Hudson of watchTowr.