USN-8834-1: Exim vulnerabilities
Ubuntu patched Exim flaws, including a Proxy Protocol out-of-bounds write that could allow remote code execution.
Ubuntu Security Notice USN-8834-1 covers multiple Exim vulnerabilities. CVE-2026-94054 is an out-of-bounds write when Proxy Protocol is used with an attacker-controlled proxy, and a remote attacker could possibly execute arbitrary code. CVE-2026-94055 is a use-after-free under certain non-default GnuTLS settings that can crash Exim and affects only Ubuntu 26.04 LTS. A further Proxy Protocol issue could expose uninitialized stack memory; the notice does not report in-the-wild exploitation.
- CVE-2026-94054: Proxy Protocol out-of-bounds write may allow remote code execution.
- CVE-2026-94055: GnuTLS use-after-free can crash Exim on Ubuntu 26.04 LTS only.
- A third Proxy Protocol bug may leak uninitialized stack memory.
- The notice does not report exploitation in the wild.
Vulnerabilities mentionedAll →
- CVE-2026-940545.3—Out-of-bounds Write in Exim MTA via attacker-controlled Proxy Protocol headerpublished · Exim (University of Cambridge) Exim Internet Mailer (mail transfer agent)+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-94054+1 related CVE | Out-of-bounds Write in Exim MTA via attacker-controlled Proxy Protocol header CVE-2026-94054 is an out-of-bounds write (CWE-787) in the Exim mail transfer agent's parsing of the Proxy Protocol header, fixed in Exim 4.100.1. It is triggered when Exim is configured to accept Proxy Protocol (a feature used to preserve real client IPs when Exim sits behind a load balancer or proxy) and the host supplying the PROXY header is attacker-controlled, allowing a crafted header line to write past the bounds of a buffer in the network-facing SMTP service. An attacker who meets that precondition gains memory corruption on a remotely reachable process; the CVSS 3.1 score of 7.0 (AV:N/AC:H/PR:N/UI:N) reflects high integrity impact with limited confidentiality and availability impact, consistent with a buffer overflow that could compromise the Exim daemon. Only deployments running a release before 4.100.1 with Proxy Protocol enabled and an insufficiently restricted trust list are affected; Exim servers without the proxy_protocol feature in use are not. No exploitation in the wild has been reported, there is no CISA KEV entry, and no public proof-of-concept is known. |
It was discovered that Exim had an out-of-bounds write when Proxy-Protocol was used with an attacker-controlled proxy. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-94054) It was discovered that Exim had a use-after-free when certain non-default TLS settings were used with GnuTLS. A remote attacker could possibly use this issue to cause Exim to crash, resulting in a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-94055) It was discovered that Exim allowed attackers to read uninitialized data from stack memory when Proxy-Protocol was used with an attacker-controlled proxy. A remote attacker could possibly use this issue to obtain…
This source does not provide full text. Read it at ubuntu.com.