Source: postfix
Version: 3.11.0-4
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for postfix.

CVE-2026-43964[0]:
| Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9
| sometimes allows a buffer over-read and process crash via an
| enhanced status code that lacks text after the third number.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-43964
    https://www.cve.org/CVERecord?id=CVE-2026-43964
[1] https://www.mail-archive.com/[email protected]/msg00110.html
[2] https://www.openwall.com/lists/oss-security/2026/05/04/25

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to