[CLSA-2026:1787664471] Fix CVE(s): CVE-2026-66140, CVE-2026-66141
Type:
security
Severity:
Important
Release date:
2026-08-25 15:11:29 UTC
Description:
* SECURITY UPDATE: directory traversal via named-queue arguments - debian/patches/CVE-2026-66140.patch: add validate_queue_name() and apply it to the -MCG and -q[f][f][l]G command-line queue names, rejecting names containing '/', longer than 32 characters, or colliding with the reserved spool subdirectories; restrict -MC and all -MCx arguments to admin users. - CVE-2026-66140 * SECURITY UPDATE: .forward privilege escalation under force_command - debian/patches/CVE-2026-66141.patch: stop expanding addr->local_part in a pipe transport under force_command, so a command taken from a user's .forward file is only dequoted and split into argv, never evaluated with the transport's privileges. - CVE-2026-66141
Updated packages:
  • exim4_4.90.1-1ubuntu1.10+tuxcare.els7_all.deb
    sha:c486639e494df4b7e21036916d601c5d80e4f06c
  • exim4-base_4.90.1-1ubuntu1.10+tuxcare.els7_amd64.deb
    sha:9c47a2a5cb2986d9dc6d7b467d1f0596971224a2
  • exim4-config_4.90.1-1ubuntu1.10+tuxcare.els7_all.deb
    sha:e3f8aef64fb4e347b37d7826df6538b858e4e601
  • exim4-daemon-heavy_4.90.1-1ubuntu1.10+tuxcare.els7_amd64.deb
    sha:51623178e3a790e3e94fed809a8f856867dfdb4a
  • exim4-daemon-light_4.90.1-1ubuntu1.10+tuxcare.els7_amd64.deb
    sha:92128751a961a7402c4e39d6207662a9975107c3
  • exim4-dev_4.90.1-1ubuntu1.10+tuxcare.els7_amd64.deb
    sha:fc68c421ed9dbb166fc68514e3ab8ccd90e5c397
  • eximon4_4.90.1-1ubuntu1.10+tuxcare.els7_amd64.deb
    sha:55293599de3e2271f37da22c770d8429bac36059
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.