Skip to content
CVSS 5.9 · MEDIUM

CVE-2026-40684

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

Ver en NVD

Severidad

Puntaje: 5.9(MEDIUM)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
AV: NETWORK
AC: HIGH
PR: NONE
UI: NONE
S: UNCHANGED
C: NONE
I: NONE
A: HIGH
Tipo de falla (CWE): CWE-684

EPSS

Probabilidad de explotación (próx. 30 días): 0.0007 (0.1%)
Percentil: 21.6%
EPSS: 2026-05-06

Afecta

exim:exim

Descripción técnica

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

Publicada: 30/4/2026, 22:16:25
Última modificación: 1/5/2026, 18:16:15

Referencias

InicioEventosBlogRecursosEquipo