[CLSA-2026:1787328725] Fix CVE(s): CVE-2026-66140, CVE-2026-66141
Type:
security
Severity:
Important
Release date:
2026-08-21 16:12:18 UTC
Description:
* SECURITY UPDATE: directory traversal outside the spool area through mishandled named-queue arguments, leading to privilege escalation - debian/patches/CVE-2026-66140.patch: add validate_queue_name() and apply it to both command-line sources of a queue name, -MCG and -q[f][f][l]G, rejecting a name that contains '/', is longer than 32 characters, or collides with one of the reserved spool subdirectories input, db, msglog and scan; mark -MC and every -MCx argument as admin-only and refuse them for a non-admin caller - CVE-2026-66140 * SECURITY UPDATE: .forward privilege escalation caused by expansion of the pipe command under force_command - debian/patches/CVE-2026-66141.patch: stop passing addr->local_part through expand_string() in the $address_pipe special case of a pipe transport that has force_command set, so command text supplied by a local user in a .forward file is only dequoted and split into arguments instead of being evaluated with the transport's privileges - CVE-2026-66141
Updated packages:
  • exim4_4.93-13ubuntu1.12+tuxcare.els3_all.deb
    sha:ce22e768c89bb3904f1def37d1f9213e0d6c3a79
  • exim4-base_4.93-13ubuntu1.12+tuxcare.els3_amd64.deb
    sha:31cc1199358b76fa5254a236579d2336d29785f7
  • exim4-config_4.93-13ubuntu1.12+tuxcare.els3_all.deb
    sha:0d595b1cb3e463be8d810067228bb86138984ce2
  • exim4-daemon-heavy_4.93-13ubuntu1.12+tuxcare.els3_amd64.deb
    sha:9a04dcb54e42290ae7e185973bbaca2a8f99aa66
  • exim4-daemon-light_4.93-13ubuntu1.12+tuxcare.els3_amd64.deb
    sha:61feab77dc79d6e9f488b4ebbb092a18dcd4afc0
  • exim4-dev_4.93-13ubuntu1.12+tuxcare.els3_amd64.deb
    sha:7826d70cd9258647eff03a9a1a2e00ab75d547e9
  • eximon4_4.93-13ubuntu1.12+tuxcare.els3_amd64.deb
    sha:89f59d8f076b12b2ff3c8f460b201c2835900d87
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.