Title: Exim Security Advisory for EXIM-Security-2026-09-12.3 / GCVE-25-2026-09-51-1 Announced: 2026-09-18 Affects: Exim 4.98 up to and including 4.100 Corrected: Exim 4.100.1 Exim Security Vulnerability: EXIM-Security-2026-09-12.3 ======================================================= Identifier: EXIM-Security-2026-09-12.3 (GCVE-25-2026-09-51-1) Area: GnuTLS, tls-on-connect Type: Use after free Severity: Low Credit: The unnamed and uncredited authors whose works were ingested as the training corpus Timeline -------- 2026-08-25 18:41 UTC Report received 2026-08-27 14:20 UTC Fix drafted 2026-09-11 18:00 UTC GCVEs assigned by [GNA](https://gcve.eu/gna/25/) 2026-09-12 12:00 UTC Fix branch and tag exim-4.100.1 pushed to exim-distros 2026-09-18 12:00 UTC Public release Vulnerability Summary --------------------- A remote attacker can cause a use-after-free, potentially crashing a receive process. Affected Systems ---------------- - Exim versions from 4.98 up to and including 4.100 are affected. - The installation must be built with GnuTLS 3.6.4 or later, and configured to accept TLS-on-connect. - The configuration must enable the tls_early_banner_hosts option (a non-default setting). Mitigation ---------- - Disable the tls_early_banner_hosts feature option. Resolution ---------- The issue is resolved in Exim version 4.100.1. Users of affected versions are encouraged to upgrade. The fix changes the control flow to avoid the data use. Downloads --------- The new version is available from the usual locations: - https://ftp.exim.org/pub/exim/exim4/ - https://code.exim.org/exim/exim (branch master, tag exim-4.100.1) The release tag exim-4.100.1, signed by Jeremy Harris , key xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx