CVE-2026-48840 Details
Description
Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
A vulnerability in Exim versions 4.88 prior to 4.99.4, in certain proxy configurations, allows for the improper handling of short payloads. This mismanagement can lead to the disclosure of uninitialized stack memory values to a client. The issue arises in the proxy_protocol() function, where a PROXYv2 frame with specific characteristics can be exploited to read and leak memory that includes live userspace virtual addresses, potentially bypassing Address Space Layout Randomization (ASLR) protections.
Users are advised to upgrade to Exim version 4.99.4, available on the Exim FTP site and the Exim Git repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2026/06/msg00004.html | CVE | |
| http://www.openwall.com/lists/oss-security/2026/05/29/3 | CVE | Mailing ListMitigationThird Party Advisory |
| https://exim.org/static/doc/security/EXIM-Security-2026-05-19.1 | [email protected] | Vendor Advisory |
| https://www.openwall.com/lists/oss-security/2026/05/29/3 | [email protected] | Mailing ListMitigationThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-839 | Numeric Range Comparison Without Minimum Check | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| exim exim | >= 4.88, < 4.99.4 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 5, 2026 | CVE Modified | CVE |
| Jun 3, 2026 | Initial Analysis | [email protected] |
| May 30, 2026 | CVE Modified | CVE |
| May 30, 2026 | New CVE Received | [email protected] |