Loading market data...
← Back to CVE feed

CVE-2026-40684

MEDIUM CVSS 5.9 View on NVD ↗

Description

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Published: Apr 30, 2026 22:16 UTC Modified: May 01, 2026 15:33 UTC