CVE-2025-67896
Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://exim.org/static/doc/security/, https://exim.org/static/doc/security/EXIM-Security-2025-12-09.1/report.txt, https://www.openwall.com/lists/oss-security/2025/12/11/2, http://www.openwall.com/lists/oss-security/2025/12/14/1, http://www.openwall.com/lists/oss-security/2025/12/18/3
