https://reddit.com/r/cybersecurity/comments/1tbrjsh/new_exim_bdat_bug_shows_why_just_patch_the_mail/: New Exim BDAT bug shows why “just patch the mail server” is still not simple
Published May 13, 2026
·Updated
Affected Software
1 affected component
Exim Exim>=4.97<=4.99.2
Frequently Asked Questions
1
What is the severity of CVE-2026-45185?
CVE-2026-45185 has been rated as a high-severity vulnerability due to its potential for memory corruption and code execution.
2
How do I fix CVE-2026-45185?
To mitigate CVE-2026-45185, upgrade Exim to version 4.99.3 or later, which addresses the vulnerability.
3
Which versions of Exim are affected by CVE-2026-45185?
CVE-2026-45185 impacts Exim versions 4.97 through 4.99.2 specifically for GnuTLS builds.
4
What is the impact of exploiting CVE-2026-45185?
Exploiting CVE-2026-45185 can lead to memory corruption, which may allow an attacker to execute arbitrary code on the mail server.
5
Is it safe to use GnuTLS builds of Exim after CVE-2026-45185?
It is not safe to use GnuTLS builds of Exim versions 4.97 through 4.99.2 until they are upgraded to a patched version.