Critical Information Disclosure Vulnerability in Exim Affects Fedora 43 and 44

Critical Information Disclosure Vulnerability in Exim Affects Fedora 43 and 44

First seen 10 Jun 2026, 04:13 UTC Linuxsecurity 100% similarity 57.8

Article Content

Browse articles
ThreatCluster

A pre-authentication information disclosure vulnerability (CVE-2026-48840) has been identified in Exim, affecting Fedora versions 43 and 44. The vulnerability allows attackers to exploit mishandled short payloads in proxy configurations, potentially leading to sensitive information exposure. The flaw was published on May 30, 2026, and has been addressed in the latest Exim version 4.99.4, released on June 1, 2026. Users are advised to update their systems using the 'dnf' update program to mitigate the risk. The vulnerability impacts all Fedora users running affected versions of Exim. The updates resolve the issues tracked under bug reports rhbz#2483300 and rhbz#2476497. As of now, there are no reports of active exploitation, but the nature of the vulnerability poses a significant risk.

Key Points: • CVE-2026-48840 allows information disclosure via Exim in Fedora 43 and 44. • The vulnerability is due to mishandled short payloads in proxy configurations. • Users are urged to upgrade to Exim version 4.99.4 to mitigate risks.

ThreatCluster AI

Timeline

2026-05-30
CVE-2026-48840 published
A pre-authentication information disclosure vulnerability in Exim was disclosed, affecting Fedora systems.
Linuxsecurity
2026-06-01
Exim version 4.99.4 released
The new version addresses CVE-2026-48840 and other bugs, resolving critical vulnerabilities.
Linuxsecurity
2026-06-10
Advisories published for Fedora 43 and 44
Linuxsecurity published advisories urging users to update to the latest Exim version to prevent information disclosure.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story