-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 27 May 2026 18:58:40 +0200 Source: exim4 Binary: exim4-base exim4-base-dbgsym exim4-daemon-heavy exim4-daemon-heavy-dbgsym exim4-daemon-light exim4-daemon-light-dbgsym exim4-dev eximon4 eximon4-dbgsym Architecture: riscv64 Version: 4.98.2-1+deb13u3 Distribution: trixie-security Urgency: high Maintainer: riscv64 Build Daemon (rv-manda-03) Changed-By: Andreas Metzler Description: exim4-base - support files for all Exim MTA (v4) packages exim4-daemon-heavy - Exim MTA (v4) daemon with extended features, including exiscan-ac exim4-daemon-light - lightweight Exim MTA (v4) daemon exim4-dev - header files for the Exim MTA (v4) packages eximon4 - monitor application for the Exim MTA (v4) (X11 interface) Changes: exim4 (4.98.2-1+deb13u3) trixie-security; urgency=high . * Cherry-pick fix for EXIM-Security-2026-05-19.1 from 4.99.4. Security: PROXYv2 parser: reject PROXY frames whose declared payload length is too short for the claimed address family (12 bytes for TCPv4/0x11, 36 bytes for TCPv6/0x21). Previously a frame with family=0x21 and len=0 caused 16 bytes of uninitialized stack to be formatted as the sender's IPv6 address and disclosed in the SMTP greeting banner. Affects configurations with SUPPORT_PROXY and `hosts_proxy` set. Reported by Warisjeet Singh (sin99xx). Checksums-Sha1: ab443c9a45ddba0eded81d8a7a827762c71774be 131596 exim4-base-dbgsym_4.98.2-1+deb13u3_riscv64.deb f626f702db6b22be793facfdc810edf6996fe3bc 1142096 exim4-base_4.98.2-1+deb13u3_riscv64.deb d3b0683d9b97fad4ab1446aaeb60b739a6c5669f 1617192 exim4-daemon-heavy-dbgsym_4.98.2-1+deb13u3_riscv64.deb 6b79a2cb6cf2e5b9bc210797eed25bb2a245cbca 672972 exim4-daemon-heavy_4.98.2-1+deb13u3_riscv64.deb 4b15e64a34cda4d995a4cbbc5f23ab1112019634 1427336 exim4-daemon-light-dbgsym_4.98.2-1+deb13u3_riscv64.deb 22a8a03b3ceffe95fe268d4d7218cf5e6b52d650 614804 exim4-daemon-light_4.98.2-1+deb13u3_riscv64.deb b402f683c421801913f67a2554f581383ea98966 36404 exim4-dev_4.98.2-1+deb13u3_riscv64.deb 612c5ba59edbb9ac1163d82d3596887164874de6 11310 exim4_4.98.2-1+deb13u3_riscv64-buildd.buildinfo 3dbd6ca4a4338867d2d43e8572bec14f911d3eb2 132116 eximon4-dbgsym_4.98.2-1+deb13u3_riscv64.deb 9d57bdef766822c35641ae74e7430ace47e44951 71240 eximon4_4.98.2-1+deb13u3_riscv64.deb Checksums-Sha256: a9a58bfabb8dfbc9ff1fd340e89eee65f7c18e28c7a90e7cda2f1bdd2c018873 131596 exim4-base-dbgsym_4.98.2-1+deb13u3_riscv64.deb 3d885ed3fb6e7bd23d618023f800665061511fb02a01e3d721e32e3818f83830 1142096 exim4-base_4.98.2-1+deb13u3_riscv64.deb 3fc208af766d9b9d9e2167393f85f8f33ed40572de54b7bf3fe68c1c341f3441 1617192 exim4-daemon-heavy-dbgsym_4.98.2-1+deb13u3_riscv64.deb da801d5fb3e0b3634a8d3ba884122625f51e68fd2b1e8b910d73f4aafd9acdc8 672972 exim4-daemon-heavy_4.98.2-1+deb13u3_riscv64.deb ee48871a0f8c324a4900ec21be533214ce0e914456367ad39d87645f28dda68d 1427336 exim4-daemon-light-dbgsym_4.98.2-1+deb13u3_riscv64.deb 1eb8ea28e1997817d63c624d7811887021b8c22f262dab4639a3ec4bd7879ffc 614804 exim4-daemon-light_4.98.2-1+deb13u3_riscv64.deb e54483928cb75632f546bae26fcf30ace02831cf8e0011dc6a0cdf43f497da62 36404 exim4-dev_4.98.2-1+deb13u3_riscv64.deb e2adf5a10ef38327ca2b7413a2af20105288c66670be4cff9c732756733229f5 11310 exim4_4.98.2-1+deb13u3_riscv64-buildd.buildinfo f171ba24ca633445c1fab36f12e8c94ea13151f5a1a6e88df673fbf3acf2ced2 132116 eximon4-dbgsym_4.98.2-1+deb13u3_riscv64.deb b3089546e487235a914c671cfc8b0db7b24a4651dccaedace5dbbe79aafb37f1 71240 eximon4_4.98.2-1+deb13u3_riscv64.deb Files: e7dbf88cb1983dc866b11e4de2c64b9d 131596 debug optional exim4-base-dbgsym_4.98.2-1+deb13u3_riscv64.deb c7bb322095056a6f1d3806de3c6690e7 1142096 mail optional exim4-base_4.98.2-1+deb13u3_riscv64.deb 482f7fdecb52da18c610c792972990ab 1617192 debug optional exim4-daemon-heavy-dbgsym_4.98.2-1+deb13u3_riscv64.deb 41d2c834f28c12d8bdbecbc221e7af6e 672972 mail optional exim4-daemon-heavy_4.98.2-1+deb13u3_riscv64.deb bdb4a42c3724a06f271bca49fe3df5d1 1427336 debug optional exim4-daemon-light-dbgsym_4.98.2-1+deb13u3_riscv64.deb dd630dcdc51850b9042f0d29046b4f4c 614804 mail optional exim4-daemon-light_4.98.2-1+deb13u3_riscv64.deb a8e13494d8feeb24f742b1a0b731ad87 36404 mail optional exim4-dev_4.98.2-1+deb13u3_riscv64.deb 31d383168adaa3f0ebadae5d0e073396 11310 mail standard exim4_4.98.2-1+deb13u3_riscv64-buildd.buildinfo c3573f3dfafc32d42476bdbbcb0a7330 132116 debug optional eximon4-dbgsym_4.98.2-1+deb13u3_riscv64.deb 7796c9db5e35bdd4c146e59788430408 71240 mail optional eximon4_4.98.2-1+deb13u3_riscv64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXZ9jHPkg/vETgMJZlJNduPxUf2oFAmoYpsYACgkQlJNduPxU f2ruAxAAtg3D417tM2NL1nPZg/HGWEsGCNpgw+Uy7JeuzZLbbnfnJItEQKXyoScC ZONENarMWyAeq9oBkF35sUiyxs09L7EDGyZt4IvWSPP62ork/ADtdGHtYeKPhLpG RdFS8RO45AYgK23kDGkcKPhBenw0SOfmoGH1UqGV+lxLULtfgZLLMo7GJ+CjmIfK uFZ5kYUavvXrhcIHnGTKEI/JVSeMUUNjMlD65aVZAEYpjbOg6afkRNX8SqcGqi91 YPwDqpzEKmyI2+X5DKBisKyTo5iUnmt4MKhTjTwFSn4PjaNb+bWlgMEasbHI/cKl j4OhIpieo7cCkxqcwkpFE9AFq9vcyTbouW1uLbuZARmUJ4Wjn1l7bVxlUcaZ1uEO cj2l1MOxVkAG6LJeBfpKJG9KEfEt4sy+D40zQRFJPoSM0KXSjvbbRp/5ZjQ5fWLy p2QqchTI99xZaFWaKvc3vgpzWU40FTiwI8JZTydNSwXXM2cuis1OGKX7Ayi9iWKK CdDBnGbYw71AENqx1ubpTdAwsrRWX0VtEacZYarwUAni8BsSLZkMnMDceW0WCfrJ iLNBHwy6XLoXFPj/BxshZgR8iL/t5ZMqhjnEHt9McbZCI/hhiHZ5IkPNDd0O8qk4 zb0EqUD5veW9ZNnt0nXy3IuB+o7vqYxtavBoKnRTki1SWQVRHxg= =a5PG -----END PGP SIGNATURE-----