Title: Exim Security Advisory for EXIM-Security-2026-09-12.3 / GCVE-25-2026-09-51-1
Announced: 2026-09-xx
Affects: Exim 4.98 up to and including 4.100
Corrected: Exim 4.100.1

Exim Security Vulnerability: EXIM-Security-2026-09-12.3
=======================================================

Identifier:   EXIM-Security-2026-09-12.3 (GCVE-25-2026-09-51-1)
Type:         Use after free
Severity:     Low
Credit:       The unnamed and uncredited authors whose works
	      were ingested as the training corpus

Timeline
--------

  2026-08-25 18:41 UTC Report received
  2026-08-27 14:20 UTC Fix drafted
  2026-09-11 18:00 UTC GCVEs assigned by [GNA](https://gcve.eu/gna/25/)
  2026-09-xx xx:xx UTC Fix branch and tag exim-4.100.1 pushed to exim-distros
  2026-09-xx xx:xx UTC Public release

Vulnerability Summary
---------------------

A remote attacker can cause a use-after-free, potentially crashing a
receive process.

Affected Systems
----------------

- Exim versions from 4.98 up to and including 4.100 are affected.
- The installation must be built with GnuTLS 3.6.4 or later, and configured
  to accept TLS-on-connect.
- The configuration must enable the tls_early_banner_hosts option
  (a non-default setting).

Mitigation
----------

- Disable the tls_early_banner_hosts feature option.

Resolution
----------

The issue is resolved in Exim version 4.100.1. Users of affected versions are
encouraged to upgrade.

The fix changes the control flow to avoid the data use.

Downloads
---------

The new version is available from the usual locations:

- https://ftp.exim.org/pub/exim/exim4/
- https://code.exim.org/exim/exim (branch master, tag exim-4.100.1)

The release tag exim-4.100.1, signed by Jeremy Harris <jgh146exb@wizmail.org>,
key xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
