Urgent.News

What's breaking now, across thousands of outlets.

Tech

Exim 4.100.1 Remediation Guide: Patching, Workarounds and Verification

Exim 4.100.1 Remediation Guide: Patching, Workarounds and Verification Vulnerability overview On 18 September 2026 the Exim project published version 4.100.1, fixing four security defects: two High-severity Proxy Protocol bugs, a Low-severity GnuTLS use-after-free and a Medium-severity SMTP smuggling issue. The maintainers report no confirmed exploitation and no public proof-of-concept. The top…

On September 18th, 2026, the Exim project released version 4.100.1 to address four security vulnerabilities. The maintainers have not observed any confirmed exploitation or proof-of-concept attacks. The most severe issue is a High-severity Proxy Protocol bug that allows a remote attacker to access up to 230 bytes beyond a heap allocation.

Another High-severity bug involves a parser leak of uninitialized stack data under Proxy Protocol version 2. A Low-severity GnuTLS use-after-free can crash the receive process when using non-default TLS-on-connect settings, and a Medium-severity SMTP smuggling vulnerability enables an attacker to deliver a message that differs from the one sent by the sender.

The affected products range from Exim 4.83 to 4.100, and the four defects do not have any known workarounds, making patching the primary remediation method. The GnuTLS flaw is the only one affected by a stopgap fix that disables the non-default tls_early_banner_hosts option.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Monday 21 September →