logoalt Hacker News

Dead.Letter (CVE-2026-45185) – How XBOW found an unauthenticated RCE on Exim

66 pointsby fedek_yesterday at 5:52 PM41 commentsview on HN

Comments

kroyesterday at 6:39 PM

It says coordinated distro release today, and I've received a notice earlier today but that does not include the CVE number. That's confusing / does not seem very coordinated to release 2 separate security update notices in a day.

https://lists.debian.org/debian-security-announce/2026/msg00...

show 1 reply
ofjcihenyesterday at 6:10 PM

>What follows is, before anything else, a story. One of those old, well-worn ones.

Gag.

show 1 reply
tardedmemetoday at 4:33 AM

I've vouched no less than four reasonable comments under this post. Was there a mass flagging campaign?

eqvinoxyesterday at 11:16 PM

I'm sorry but what the f is that timeline? (Condensed to relevant notifications:)

  2025-05-01 - Vulnerability submitted to [email protected]
  2026-05-08 - Exim maintainers notified the Distros
  2026-05-10 - Restricted Access is provided for Distros
  2026-05-12 - Public release and Coordinated distro Release
4 (2 really) days for distros, and then nothing, zero, zilch, nada between "Coordinated distro Release" and "Public release"?

"I should retrain. Something with wood." is the appropriate German idiom for this, I guess.

aftbityesterday at 6:05 PM

Ok now do postfix

show 2 replies
stackghostyesterday at 6:47 PM

>The bug is a use-after-free triggered when a TLS connection is handled by GnuTLS

Color me surprised. The GNU ecosystem has had more than its fair share of CVEs over the years to the point that it's now a common trope:

https://soatok.blog/2020/07/08/gnu-a-heuristic-for-bad-crypt...

nhattruongadmyesterday at 7:37 PM

[flagged]

alpbtoday at 12:26 AM

Never heard of Exim, I'm just realizing what it is:

> Exim is an open-source Mail Transfer Agent (MTA) designed for Unix-like systems to receive, route, and deliver email.

what's the significance of this? do people use this in production systems?

show 2 replies