{"id":244830,"date":"2026-05-12T12:44:00","date_gmt":"2026-05-12T16:44:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/05\/12\/new-exim-bdat-vulnerability-exposes-gnutls-builds-to-potential-code-execution\/"},"modified":"2026-05-13T01:20:08","modified_gmt":"2026-05-13T05:20:08","slug":"new-exim-bdat-vulnerability-exposes-gnutls-builds-to-potential-code-execution","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/05\/12\/new-exim-bdat-vulnerability-exposes-gnutls-builds-to-potential-code-execution\/","title":{"rendered":"New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/new-exim-bdat-vulnerability-exposes.html\">New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/new-exim-bdat-vulnerability-exposes.html\">https:\/\/thehackernews.com\/2026\/05\/new-exim-bdat-vulnerability-exposes.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-12 12:44:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">May 12, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Email Security<\/span><\/p>\n<p>Exim has released security updates to address a severe security issue affecting certain configurations that could enable memory corruption and potential code execution.<\/p>\n<p>Exim is an open-source Mail Transfer Agent (MTA) designed for Unix-like systems to receive, route, and deliver email.<\/p>\n<p>The vulnerability, tracked as CVE-2026-45185, aka Dead.Letter, has been described as a use-after-free vulnerability in Exim&#8217;s binary data transmission (BDAT) message body parsing when a TLS connection is handled by GnuTLS.<\/p>\n<p>&#8220;The vulnerability is triggered during BDAT message body handling when a client sends a TLS close_notify alert before the body transfer is complete, and then follows up with a final byte in cleartext on the same TCP connection,&#8221; Exim said in an advisory released today.<\/p>\n<p>&#8220;This sequence of events can cause Exim to write into a memory buffer that has already been freed during the TLS session teardown, leading to heap corruption. An attacker only needs to be able to establish a TLS connection and use the CHUNKING (BDAT) SMTP extension.&#8221;<\/p>\n<p>The issue impacts all Exim versions from 4.97 up to and including 4.99.2. That said, it only affects builds that use USE_GNUTLS=yes, meaning builds that rely on other TLS libraries like OpenSSL are not impacted.<\/p>\n<p>Federico Kirschbaum, head of Security Lab at XBOW, an autonomous cybersecurity testing platform, has been credited with discovering and reporting the flaw on May 1, 2026.<\/p>\n<p>&#8220;During TLS shutdown, Exim frees its TLS transfer buffer \u2013 but a nested BDAT receive wrapper can still process incoming bytes and end up calling ungetc(), which writes a single character (n) into the freed region,&#8221; Kirschbaum said. &#8220;That one-byte write lands on Exim&#8217;s allocator metadata, corrupting the allocator&#8217;s internal shape; the exploit then leverages that corruption to gain further primitives.&#8221;<\/p>\n<p><iframe loading=\"lazy\" title=\"BLOG Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim - ASLR BYPASS\" width=\"640\" height=\"480\" src=\"https:\/\/www.youtube.com\/embed\/qHYr7Fb0JuI?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<p>XBOW described the vulnerability&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/new-exim-bdat-vulnerability-exposes.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution https:\/\/thehackernews.com\/2026\/05\/new-exim-bdat-vulnerability-exposes.html Publish Date: 2026-05-12&#8230;<\/p>\n","protected":false},"author":1,"featured_media":244831,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgrSn3emm_NbwXDi3elR0wo5ErHhg-gPT4-u4zk7MHZg4u0ruMmj2_KGgPF8fz06Riv6Gu5NXMN3eBP8H5bVf6dmvOz-lvb-qrvhLlssLUzl97ZVmIWoIOmMPOGrupv864dt0d4V_dxgaaxYYNuy2z9rbZMWIOcjlwZaiifq4-ktRqlEBCJ6a_m3MFiwq65\/s1600\/exim.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,31,27],"class_list":["post-244830","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-exploit","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/244830"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=244830"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/244830\/revisions"}],"predecessor-version":[{"id":244832,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/244830\/revisions\/244832"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/244831"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=244830"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=244830"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=244830"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}