CVE Vulnerabilities

CVE-2026-40684

Incorrect Provision of Specified Functionality

Published: Apr 30, 2026 | Modified: May 01, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

Weakness

The code does not function according to its published specifications, potentially leading to incorrect usage.

Affected Software

NameVendorStart VersionEnd Version
EximExim*4.99.2 (excluding)
Exim4Ubuntuupstream*

Potential Mitigations

References