Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2022-3559
Exim vulnerability analysis and mitigation

Overview

A use-after-free vulnerability was discovered in Exim's Regex Handler component, identified as CVE-2022-3559. The vulnerability was found in October 2022 and affects the processing of regular expressions in Exim mail transfer agent. The issue was addressed with patch 4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2 (Exim Bug, Exim Git).

Technical details

The vulnerability manifests as a use-after-free condition in the Regex Handler component when processing regular expressions, particularly during SMTP connections handling multiple messages in the same session. The issue occurs specifically when regex variables are accessed after being freed during SMTP connection resets (Exim Bug).

Impact

When exploited, this vulnerability could lead to unexpected system behavior and potential crashes of the Exim mail server. The issue particularly affects scenarios where multiple messages are processed in the same SMTP connection, potentially disrupting mail service operations (Debian Security).

Exploitability

The vulnerability requires specific conditions to be exploited, particularly involving the processing of multiple messages within the same SMTP connection. While the vulnerability was confirmed through testing, there were no reported instances of exploitation in the wild (Exim Bug).

Mitigation and workarounds

The issue was fixed in various Exim versions across different distributions. Fedora released updates 4.96-4.fc35, 4.96-4.fc36, and 4.96-5.fc37 to address this vulnerability. Debian also provided fixes in versions 4.94.2-7+deb11u4 for bullseye and 4.96-15+deb12u5 for bookworm (Fedora Update, Debian Security).

Additional resources


SourceThis report was generated using AI

Related Exim vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45185CRITICAL9.8
  • Exim logoExim
  • exim-mysql
NoYesMay 12, 2026
CVE-2026-40687CRITICAL9.1
  • Exim logoExim
  • exim
NoYesApr 30, 2026
CVE-2026-66141HIGH7.8
  • Exim logoExim
  • cpe:2.3:a:exim:exim
NoYesJul 24, 2026
CVE-2026-66140HIGH7.8
  • Exim logoExim
  • exim-greylist
NoYesJul 24, 2026
CVE-2026-48840MEDIUM5.3
  • Exim logoExim
  • exim
NoYesMay 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management