---
schema: 1
kind: vulnerability
title: "CVE-2026-45185 — Exim \"Dead.Letter\" use-after-free in BDAT/CHUNKING on GnuTLS builds"
headline: "CVE-2026-45185 — Exim \"Dead.Letter\" use-after-free in BDAT/CHUNKING on GnuTLS builds"
summary: "Exim \"Dead.Letter\" pre-auth RCE on the default Debian/Ubuntu MTA. CVE-2026-45185 (CVSS 9.8) is a use-after-free in the BDAT/CHUNKING body-parsing path triggered when a client sends TLS close_notify mid-body and then one cleartext byte on the same TCP connection. GnuTLS builds only (the distro default); OpenSSL builds unaffected. CHUNKING extension is default-on. Fixed in Exim 4.99.3 (XBOW research, 2026-05-12; oss-security, 2026-05-12)."
discovered_at: "2026-05-13T05:00:03Z"
event_date: 2026-05-12
run_id: 2026-05-13-c148b9a5
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - pre-auth
  - rce
  - patch-available
regions:
  - global
sectors: []
entities: []
cves:
  - id: CVE-2026-45185
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim"
    publisher: "XBOW research, 2026-05-12"
    role: primary
  - url: "https://www.openwall.com/lists/oss-security/2026/05/12/4"
    publisher: "oss-security, 2026-05-12"
    role: corroborating
  - url: "https://thehackernews.com/2026/05/new-exim-bdat-vulnerability-exposes.html"
    publisher: "The Hacker News, 2026-05-12"
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-13.md
---

XBOW disclosed CVE-2026-45185 on 2026-05-12 after a coordinated-disclosure window with Exim maintainers, Linux distros and CVE authorities that began 2026-05-01 ([XBOW research, 2026-05-12](https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim); [oss-security, 2026-05-12](https://www.openwall.com/lists/oss-security/2026/05/12/4); [The Hacker News, 2026-05-12](https://thehackernews.com/2026/05/new-exim-bdat-vulnerability-exposes.html)). The bug is a use-after-free (CWE-416) in Exim's BDAT (RFC 3030 CHUNKING) body-parser when the binary was built with GnuTLS (`USE_GNUTLS=yes`) — the default on Debian and Ubuntu packages. OpenSSL builds are unaffected. The trigger: an SMTP client sends a TLS `close_notify` mid-BDAT body, then one final cleartext byte on the same TCP connection. Exim's `xfer_buffer` has already been freed in `tls_close()`, but the BDAT `lwr_receive_*` function pointers remain live and `tls_ungetc()` writes a single `\n` byte into the freed region. XBOW's AI-driven exploitation (within the seven-day disclosure window) produced two working chains under ASLR: a largebin-corruption → `FILE` struct hijack chain on No-PIE builds, and a `storeblock` length-inflation → bump-pointer corruption → `${run}` ACL execution chain on PIE builds. No authentication is required; the CHUNKING extension is default-on. Fixed in Exim 4.99.3. CVSS 9.8 per the XBOW disclosure. No public exploitation reported at disclosure, but exim.org is the dominant MTA on the public internet and the GnuTLS default on Debian / Ubuntu maps directly to the typical EU university, academic-research and small-government mail-relay estate. Detection / hunt concepts mapped to `T1190 Exploit Public-Facing Application` and `T1499.004 Endpoint Denial of Service: Application or System Exploitation`: monitor `exim` `panic.log` for `tls_ungetc` traces and segfaults under non-zero load; egress-monitor any outbound TCP from the MTA host that does not match the usual upstream-relay set; on Debian / Ubuntu, audit `exim -bV | grep GnuTLS` per host. Workaround pending patch: set `CHUNKING_ADVERTISE_HOSTS =` (empty) in `exim4.conf` to suppress the BDAT advertisement.
