Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.8

CVE-2026-40687: Weak Password Storage in Debian Packages Allows Unauthorized Access

CVE-2026-40687 · published 4 months ago
Summary

Debian package manager stores passwords insecurely, allowing attackers to access sensitive information. This could lead to unauthorized access to sensitive data. Update your Debian packages to the latest version to fix this issue.

What to do
  • Update canonical exim4 to version 4.95-4ubuntu2.7.
  • Update canonical exim4 to version 4.97-4ubuntu4.4.
  • Update canonical exim4 to version 4.98.2-1ubuntu2.1.
  • Update canonical exim4 to version 4.99.1-1ubuntu1.1.
  • Update debian exim4 to version 4.94.2-7+deb11u6.aikido.1.
  • Update debian rootio-exim4 to version 4.94.2-7+deb11u6.aikido.1.
  • Update exim exim to version 4.99.2 or later.
Affected software
Ecosystem VendorProductAffected versions
– exim exim < 4.99.2
cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:*
Debian:11 debian exim4 All versions
Debian:12 debian exim4 All versions
Debian:13 debian exim4 All versions
Debian:14 debian exim4 All versions
Ubuntu:Pro:14.04:LTS canonical exim4 All versions
Ubuntu:Pro:16.04:LTS canonical exim4 All versions
Ubuntu:Pro:18.04:LTS canonical exim4 All versions
Ubuntu:20.04:LTS canonical exim4 All versions
Ubuntu:22.04:LTS canonical exim4 < 4.95-4ubuntu2.7
Fix: upgrade to 4.95-4ubuntu2.7
Ubuntu:24.04:LTS canonical exim4 < 4.97-4ubuntu4.4
Fix: upgrade to 4.97-4ubuntu4.4
Ubuntu:25.10 canonical exim4 < 4.98.2-1ubuntu2.1
Fix: upgrade to 4.98.2-1ubuntu2.1
Ubuntu:26.04 canonical exim4 All versions
Ubuntu:26.04:LTS canonical exim4 < 4.99.1-1ubuntu1.1
Fix: upgrade to 4.99.1-1ubuntu1.1
Root:Debian:11 debian exim4 < 4.94.2-7+deb11u6.aikido.1
Fix: upgrade to 4.94.2-7+deb11u6.aikido.1
Root:Debian:11 debian rootio-exim4 < 4.94.2-7+deb11u6.aikido.1
Fix: upgrade to 4.94.2-7+deb11u6.aikido.1
Original advisory text
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data proce...
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
Severity
4.8 Medium
CVSS 3.1: 9.1 (OSV)
CVSS 3.1: 4.8 (NVD)
Exploitation
EPSS 1%
Type
CWE-909Missing Initialization of Resource
Timeline
Published30 Apr 2026
Updated25 Sep 2026
First seen30 Apr 2026
Track software like this
Free during beta