CVE-2024-4140
published 2024-05-02CVE-2024-4140: An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The…
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.13%
63.3th percentile
An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libemail-mime-perl | < libemail-mime-perl 1.954-1 (forky) | libemail-mime-perl 1.954-1 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| rjbs | email-mime | < 1.954 | 1.954 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-4140: An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1
osv·2024-05-02·CVSS 7.5
CVE-2024-4140 [HIGH] CVE-2024-4140: An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1
An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.
GHSA
GHSA-2rhr-29cm-5chf: An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1
ghsa_unreviewed·2024-05-02
CVE-2024-4140 [HIGH] CWE-770 GHSA-2rhr-29cm-5chf: An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1
An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.
Oracle
Oracle Oracle Siebel CRM Risk Matrix: Keyword Automation (Email-MIME) — CVE-2024-4140
vendor_oracle·2025-10-15·CVSS 7.5
CVE-2024-4140 [HIGH] Oracle Oracle Siebel CRM Risk Matrix: Keyword Automation (Email-MIME) — CVE-2024-4140
Oracle Oracle Siebel CRM Risk Matrix: Keyword Automation (Email-MIME) vulnerability
CVE: CVE-2024-4140
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Red Hat
kernel: drm/amd/display: Add null check for top_pipe_to_program in commit_planes_for_stream
vendor_redhat·2024-10-21·CVSS 5.5
CVE-2024-49913 [MEDIUM] CWE-476 kernel: drm/amd/display: Add null check for top_pipe_to_program in commit_planes_for_stream
kernel: drm/amd/display: Add null check for top_pipe_to_program in commit_planes_for_stream
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Add null check for top_pipe_to_program in commit_planes_for_stream
This commit addresses a null pointer dereference issue in the
`commit_planes_for_stream` function at line 4140. The issue could occur
when `top_pipe_to_program` is null.
The fix adds a check to ensure `top_pipe_to_program` is not null before
accessing its stream_res. This prevents a null pointer dereference.
Reported by smatch:
drivers/gpu/drm/amd/amdgpu/../display/dc/core/dc.c:4140 commit_planes_for_stream() error: we previously assumed 'top_pipe_to_program' could be null (see line 3906)
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2024-4140: libemail-mime-perl - An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.9...
vendor_debian·2024·CVSS 7.5
CVE-2024-4140 [HIGH] CVE-2024-4140: libemail-mime-perl - An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.9...
An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.954-1)
sid: resolved (fixed in 1.954-1)
trixie: resolved (fixed in 1.954-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.debian.org/960062https://github.com/rjbs/Email-MIME/commit/02bf3e26812c8f38a86a33c168571f9783365df2https://github.com/rjbs/Email-MIME/commit/3a12edd119e493156a5a05e45dd50f4e36b702e8https://github.com/rjbs/Email-MIME/commit/3dcf096eeccb8e4dd42738de676c8f4a5aa7a531https://github.com/rjbs/Email-MIME/commit/7e96ecfa1da44914a407f82ae98ba817bba08f2dhttps://github.com/rjbs/Email-MIME/commit/b2cb62f19e12580dd235f79e2546d44a6bec54d1https://github.com/rjbs/Email-MIME/commit/fc0fededd24a71ccc51bcd8b1e486385d09aae63https://github.com/rjbs/Email-MIME/issues/66https://github.com/rjbs/Email-MIME/pull/80https://lists.fedoraproject.org/archives/list/[email protected]/message/UFD5BWGYAVLW6IO4SUNLTJCFFLHZYQGT/https://lists.fedoraproject.org/archives/list/[email protected]/message/YHXHDLPZ6JV4KK3Q43O6TE3WOBAIUQRC/https://www.cve.org/CVERecord?id=CVE-2024-4140https://bugs.debian.org/960062https://github.com/rjbs/Email-MIME/commit/02bf3e26812c8f38a86a33c168571f9783365df2https://github.com/rjbs/Email-MIME/commit/3a12edd119e493156a5a05e45dd50f4e36b702e8https://github.com/rjbs/Email-MIME/commit/3dcf096eeccb8e4dd42738de676c8f4a5aa7a531https://github.com/rjbs/Email-MIME/commit/7e96ecfa1da44914a407f82ae98ba817bba08f2dhttps://github.com/rjbs/Email-MIME/commit/b2cb62f19e12580dd235f79e2546d44a6bec54d1https://github.com/rjbs/Email-MIME/commit/fc0fededd24a71ccc51bcd8b1e486385d09aae63https://github.com/rjbs/Email-MIME/issues/66https://github.com/rjbs/Email-MIME/pull/80https://lists.fedoraproject.org/archives/list/[email protected]/message/UFD5BWGYAVLW6IO4SUNLTJCFFLHZYQGT/https://lists.fedoraproject.org/archives/list/[email protected]/message/YHXHDLPZ6JV4KK3Q43O6TE3WOBAIUQRC/https://www.cve.org/CVERecord?id=CVE-2024-4140
2024-05-02
Published