CVE-2026-40684: High severity Exim Exim vulnerability
Published Apr 30, 2026
·Updated
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dnexpand oddity in octal printing.
Affected Software
2 affected components
Exim Exim<4.99.2
Exim Exim<4.99.2
Remediation
Event History
Apr 30, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-40684?
CVE-2026-40684 is considered a moderate severity vulnerability that can cause a connection instance crash.
2
How do I fix CVE-2026-40684?
To fix CVE-2026-40684, upgrade Exim to version 4.99.2 or later.
3
What systems are affected by CVE-2026-40684?
CVE-2026-40684 affects Exim versions prior to 4.99.2 on systems using musl libc.
4
What is the exploit mechanism for CVE-2026-40684?
CVE-2026-40684 can be exploited by sending malformed DNS data in PTR records.
5
Is CVE-2026-40684 related to glibc or musl libc?
CVE-2026-40684 specifically affects systems using musl libc, not glibc.