Linuxsecurity
Critical Information Disclosure Vulnerability in Exim Affects Fedora 43 and 44
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A pre-authentication information disclosure vulnerability (CVE-2026-48840) has been identified in Exim, affecting Fedora versions 43 and 44. The vulnerability allows attackers to exploit mishandled short payloads in proxy configurations, potentially leading to sensitive information exposure. The flaw was published on May 30, 2026, and has been addressed in the latest Exim version 4.99.4, released on June 1, 2026. Users are advised to update their systems using the 'dnf' update program to mitigate the risk. The vulnerability impacts all Fedora users running affected versions of Exim. The updates resolve the issues tracked under bug reports rhbz#2483300 and rhbz#2476497. As of now, there are no reports of active exploitation, but the nature of the vulnerability poses a significant risk.
Key Points: • CVE-2026-48840 allows information disclosure via Exim in Fedora 43 and 44. • The vulnerability is due to mishandled short payloads in proxy configurations. • Users are urged to upgrade to Exim version 4.99.4 to mitigate risks.