Executive brief
Exim is a mail transfer agent widely used by email servers. When configured to use Proxy Protocol with an attacker-controlled proxy, an attacker can read sensitive uninitialized data from the server's memory, potentially exposing authentication credentials, message content, or other confidential information.
Technical details
Use of uninitialized data in Proxy Protocol v2 implementation allows a remote attacker to leak up to 230 bytes of stack memory when the configured proxy is buggy or compromised. Attack requires Exim built with Proxy Protocol support and configured to use it. The vulnerability is patched by ensuring complete protocol headers are received before processing.
Affected products
- Exim Exim 4.83 to 4.100
Timeline
- 2026-09-18: disclosed
- 2026-09-18: patched: Version 4.100.1 released