Vulnerabilities
New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution
Cyber RTMay 12, 20263 min read

Exim has released updates to fix a critical use-after-free vulnerability, CVE-2026-45185, affecting versions 4.97 to 4.99.2 using GnuTLS. This flaw, named Dead.Letter, allows memory corruption and potential code execution during BDAT message handling when a TLS connection is closed prematurely. Discovered by Federico Kirschbaum, it is considered a high-caliber bug. Users are urged to upgrade to version 4.99.3 immediately.
Exim, an open-source Mail Transfer Agent (MTA) for Unix-like systems, has released critical security updates addressing a severe vulnerability that could lead to memory corruption and potential code execution. This vulnerability, identified as CVE-2026-45185 and nicknamed Dead.Letter, is a use-after-free flaw in Exim's binary data transmission (BDAT) message body parsing when a TLS connection is managed by GnuTLS.
The vulnerability is triggered during the handling of BDAT message bodies when a client sends a TLS close_notify alert before completing the body transfer and then sends a final byte in cleartext over the same TCP connection. This sequence can lead Exim to write into a memory buffer that has already been freed during the TLS session teardown, resulting in heap corruption. An attacker needs only to establish a TLS connection and utilize the CHUNKING (BDAT) SMTP extension to exploit this flaw.
The issue affects all Exim versions from 4.97 up to and including 4.99.2, but only impacts builds using USE_GNUTLS=yes. Builds relying on other TLS libraries, such as OpenSSL, are not affected. The vulnerability was discovered and reported by Federico Kirschbaum, head of Security Lab at XBOW, on May 1, 2026.
Kirschbaum explained that during TLS shutdown, Exim frees its TLS transfer buffer, but a nested BDAT receive wrapper can still process incoming bytes, leading to a single character being written into the freed region. This one-byte write corrupts Exim's allocator metadata, which can be exploited to gain further control over the system.
XBOW has described this vulnerability as one of the most severe bugs discovered in Exim to date, noting that it requires minimal special configuration on the server to be triggered. The flaw has been addressed in version 4.99.3, and all users are strongly advised to upgrade immediately, as there are no alternative mitigations available.
The fix implemented in version 4.99.3 ensures that the input processing stack is properly reset when a TLS close notification is received during an active BDAT transfer, preventing the use of stale pointers. This update is crucial for maintaining the security and integrity of systems using Exim.
This is not the first critical use-after-free vulnerability disclosed in Exim. In late 2017, a similar vulnerability (CVE-2017-16943) was patched, which could have allowed unauthenticated attackers to achieve remote code execution through specially crafted BDAT commands, potentially compromising email server control.


