[CLSA-2026:1787310808] Fix CVE(s): CVE-2026-66141
Type:
security
Severity:
Important
Release date:
2026-08-21 11:14:09 UTC
Description:
* SECURITY UPDATE: .forward privilege escalation via force_command in a pipe transport - debian/patches/CVE-2026-66141.patch: do not expand the local_part obtained from a .forward file in transport_set_up_command() in src/transport.c - CVE-2026-66141
CVEs fixed:
Updated packages:
  • exim4_4.86.2-2ubuntu2.6+tuxcare.els9_all.deb
    sha:f3bec200f92ef96717ad13d82bc6df4436602039
  • exim4-base_4.86.2-2ubuntu2.6+tuxcare.els9_amd64.deb
    sha:b0b53705c244d94ca5095dfcd11686785cb34152
  • exim4-config_4.86.2-2ubuntu2.6+tuxcare.els9_all.deb
    sha:f66ace27c07296602e158744292fcc39329b02be
  • exim4-daemon-heavy_4.86.2-2ubuntu2.6+tuxcare.els9_amd64.deb
    sha:e90136e84f0d1a7931471147e626a3bcc62313c5
  • exim4-daemon-light_4.86.2-2ubuntu2.6+tuxcare.els9_amd64.deb
    sha:72f2814e7aea9fb3e215fa0939e5069a101434c9
  • exim4-dev_4.86.2-2ubuntu2.6+tuxcare.els9_amd64.deb
    sha:9a386d92e0c4ca029161819ad899603c7ded5269
  • eximon4_4.86.2-2ubuntu2.6+tuxcare.els9_amd64.deb
    sha:ef917c98c90c8cae1a2d7cdbf42e474e57371e82
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.