A vulnerability was found in Exim and classified as problematic. This issue affects some unknown processing of the component Regex Handler. The manipulation leads to use after free. The name of the patch is 4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2. It is recommended to apply a patch to fix this issue. The identifier VDB-211073 was assigned to this vulnerability.
Conclusion & alert: CVE-2022-3559 is rated Moderate Risk (52.4/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 3.66%). Core evidence: EPSS rose +3.19% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.47% | 3.66% | +3.19% |
| 2 | 2026-05-16 | 0.66% | 0.47% | -0.19% |
| 3 | 2026-03-26 | — | 0.66% | — |
Full EPSS history (24 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.6 | 3.1 | MEDIUM |
|
1.2 | 3.4 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2022-3559 not yet assigned priority: Debian including 1 source packages (exim4), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2022-3559 |
ubuntu
|
medium | CVE-2022-3559 medium priority: Ubuntu including 1 source packages (exim4), 7 status rows across 7 suites (bionic, focal, jammy, kinetic, trusty, upstream, xenial): released 5, not-affected 2. | https://ubuntu.com/security/CVE-2022-3559 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| exim | exim | < 4.97 | cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:* |
| fedoraproject | fedora | 35 | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* |
| fedoraproject | fedora | 36 | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
| fedoraproject | fedora | 37 | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://bugs.exim.org/show_bug.cgi?id=2915 | Patch Vendor Advisory |
| https://git.exim.org/exim.git/commit/4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2 | Patch Vendor Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EIH4W5R7SHTUEQFWWKB4TUO5YFZX64KV/ | Mailing List Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMQ6OCKPNPBPSD37YR4FOWV2R54M2UEP/ | Mailing List Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WFHLZVHNNO2GWYP5EA4TZQZ5O4GVPARR/ | Mailing List Third Party Advisory |
| https://vuldb.com/?id.211073 | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2024/10/msg00029.html |