Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
4.8
CVE-2026-40687: Weak Password Storage in Debian Packages Allows Unauthorized Access
CVE-2026-40687 · published 4 months ago
Summary
Debian package manager stores passwords insecurely, allowing attackers to access sensitive information. This could lead to unauthorized access to sensitive data. Update your Debian packages to the latest version to fix this issue.
What to do
- Update canonical exim4 to version 4.95-4ubuntu2.7.
- Update canonical exim4 to version 4.97-4ubuntu4.4.
- Update canonical exim4 to version 4.98.2-1ubuntu2.1.
- Update canonical exim4 to version 4.99.1-1ubuntu1.1.
- Update debian exim4 to version 4.94.2-7+deb11u6.aikido.1.
- Update debian rootio-exim4 to version 4.94.2-7+deb11u6.aikido.1.
- Update exim exim to version 4.99.2 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | exim | exim |
< 4.99.2 cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:* |
| Debian:11 | debian | exim4 | All versions |
| Debian:12 | debian | exim4 | All versions |
| Debian:13 | debian | exim4 | All versions |
| Debian:14 | debian | exim4 | All versions |
| Ubuntu:Pro:14.04:LTS | canonical | exim4 | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | exim4 | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | exim4 | All versions |
| Ubuntu:20.04:LTS | canonical | exim4 | All versions |
| Ubuntu:22.04:LTS | canonical | exim4 |
< 4.95-4ubuntu2.7 Fix: upgrade to 4.95-4ubuntu2.7
|
| Ubuntu:24.04:LTS | canonical | exim4 |
< 4.97-4ubuntu4.4 Fix: upgrade to 4.97-4ubuntu4.4
|
| Ubuntu:25.10 | canonical | exim4 |
< 4.98.2-1ubuntu2.1 Fix: upgrade to 4.98.2-1ubuntu2.1
|
| Ubuntu:26.04 | canonical | exim4 | All versions |
| Ubuntu:26.04:LTS | canonical | exim4 |
< 4.99.1-1ubuntu1.1 Fix: upgrade to 4.99.1-1ubuntu1.1
|
| Root:Debian:11 | debian | exim4 |
< 4.94.2-7+deb11u6.aikido.1 Fix: upgrade to 4.94.2-7+deb11u6.aikido.1
|
| Root:Debian:11 | debian | rootio-exim4 |
< 4.94.2-7+deb11u6.aikido.1 Fix: upgrade to 4.94.2-7+deb11u6.aikido.1
|
Original advisory text
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data proce...
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
References
- https://security-tracker.debian.org/tracker/CVE-2026-40687 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-40687 Third Party Advisory
- https://lists.exim.org/lurker/message/20260429.121733.f58d9686.en.html Third Party Advisory
- https://ubuntu.com/security/CVE-2026-40687 Third Party Advisory
- https://exim.org/static/doc/security/cve-2026-04.1/CVE2026-40687.assessment
- https://code.exim.org/exim/exim/commit/68b963b9f75ca27b38e1c0f8c87037990199f505
- https://exim.org/static/doc/security/CVE-2025-40687.txt
- https://exim.org/static/doc/security/CVE-2026-40687.txt Broken Link
- https://www.openwall.com/lists/oss-security/2026/04/30/21
- https://ubuntu.com/security/notices/USN-8228-1 Vendor Advisory
Severity
4.8
Medium
CVSS 3.1: 9.1 (OSV)
CVSS 3.1: 4.8 (NVD)
Exploitation
EPSS 1%
Type
CWE-909Missing Initialization of Resource
Timeline
Published30 Apr 2026
Updated25 Sep 2026
First seen30 Apr 2026
Track software like this
Free during beta