CVE-2025-67896: Update: CVE-2025-67896: EXIM-Security-2025-12-09.1: Exim 4.99: mote heap corruption
Published Dec 14, 2025
·Updated
Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.
Affected Software
2 affected components
Exim Exim<4.99.1
Exim Exim<4.99.1
Event History
Dec 14, 2025
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Dec 27, 57945
Event
via NVD·08:41 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-67896?
CVE-2025-67896 is classified as a high severity vulnerability due to the potential for remote heap corruption.
2
How do I fix CVE-2025-67896?
The only effective fix for CVE-2025-67896 is to upgrade to Exim version 4.99.1 or later.
3
Who is affected by CVE-2025-67896?
CVE-2025-67896 affects Exim versions prior to 4.99.1.
4
What kind of attack does CVE-2025-67896 allow?
CVE-2025-67896 allows for remote heap corruption, which could lead to exploitation and denial of service.
5
When was CVE-2025-67896 disclosed?
CVE-2025-67896 is scheduled for further detailed description and disclosure on December 18, 2025.