[CLSA-2026:1778173472] exim: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-07 17:04:42 UTC
Description:
- CVE-2026-40685: fix heap corruption when expanding malformed JSON - CVE-2026-40687: fix heap buffer overflow and infoleak in SPA authenticator
Updated packages:
  • exim-4.97.1-1.el7.tuxcare.els2.x86_64.rpm
    sha:71bb5f5feeb92b210ea37ace68163aa90c7b51766c4c694523fe6701319b50d5
  • exim-greylist-4.97.1-1.el7.tuxcare.els2.x86_64.rpm
    sha:2958dad9560f4c9527942bbd9f5e8fa80976ef96f7174babedf3824570cf77c1
  • exim-mon-4.97.1-1.el7.tuxcare.els2.x86_64.rpm
    sha:2ce8b42624411dadd0ad57b0f69a613915a8c68e504497018f4cbf26cf1e9602
  • exim-mysql-4.97.1-1.el7.tuxcare.els2.x86_64.rpm
    sha:c4d023fd32d87f20a875cf2143674b1d149272885046d7c7dce7cff298142798
  • exim-pgsql-4.97.1-1.el7.tuxcare.els2.x86_64.rpm
    sha:771e657d47554f494688a3336a00db42b22ae633bab703afbf48bb45a888350c
  • exim-sysvinit-4.97.1-1.el7.tuxcare.els2.noarch.rpm
    sha:fea2138d194452c365862e111c9304f0bd687b25e316a5fa26991eb15495da6f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.