← Back

CVE-2026-40684

nvd nist
Published: Apr 30, 2026Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

Affected (1)

Products: Exim: Exim
1 product
Exim
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.99.2

Timeline

No history available yet.