logoalt Hacker News

Dead.Letter (CVE-2026-45185) – How XBOW found an unauthenticated RCE on Exim

43 pointsby fedek_today at 5:52 PM14 commentsview on HN

Comments

ofjcihentoday at 6:10 PM

>What follows is, before anything else, a story. One of those old, well-worn ones.

Gag.

krotoday at 6:39 PM

It says coordinated distro release today, and I've received a notice earlier today but that does not include the CVE number. That's confusing / does not seem very coordinated to release 2 separate security update notices in a day.

https://lists.debian.org/debian-security-announce/2026/msg00...

stackghosttoday at 6:47 PM

>The bug is a use-after-free triggered when a TLS connection is handled by GnuTLS

Color me surprised. The GNU ecosystem has had more than its fair share of CVEs over the years to the point that it's now a common trope:

https://soatok.blog/2020/07/08/gnu-a-heuristic-for-bad-crypt...

aftbittoday at 6:05 PM

Ok now do postfix

show 2 replies
nhattruongadmtoday at 7:37 PM

[flagged]