https://seclists.org/oss-sec/2026/q2/491: [EXIM-Security-2026-05-01.1] Security lease 4.99.3
Published May 12, 2026
·Updated
Affected Software
1 affected component
Exim Exim>=4.97<4.99.3
Frequently Asked Questions
1
What is the severity of EXIM-Security-2026-05-01.1?
The severity of EXIM-Security-2026-05-01.1 is rated as critical due to the potential for remote code execution.
2
How do I fix EXIM-Security-2026-05-01.1?
To fix EXIM-Security-2026-05-01.1, update Exim to version 4.99.4 or later as recommended by the maintainers.
3
What specific vulnerability does EXIM-Security-2026-05-01.1 address?
EXIM-Security-2026-05-01.1 addresses a remotely reachable Use-After-Free (UAF) vulnerability in Exim's BDAT body parsing.
4
Is my Exim version affected by EXIM-Security-2026-05-01.1?
Exim versions prior to 4.99.4 are affected by EXIM-Security-2026-05-01.1 if certain configurations are used.
5
Can the EXIM-Security-2026-05-01.1 vulnerability be exploited remotely?
Yes, the EXIM-Security-2026-05-01.1 vulnerability can be exploited remotely, allowing attackers to execute arbitrary code.