Hi! On Mon, 10 Aug 2026 17:50:35 +0200, Wietse Venema via Postfix-users wrote: > > [An on-line version of this announcement will be available at > https://www.postfix.org/announcements/postfix-3.11.6.html] > > This release addresses medium-impact problems that need to be fixed > as some enable remote DOS or policy bypass. > > The fixes below, and more, are also released in the unstable version > postfix-3.12-20260809. > > In addition to updated releases for the supported Postfix versions > 3.8-3.11, releases will also be available for the out-of-support > Postfix versions 3.5-3.7. NOTE: these do not include the patches > for out-of-support Postfix versions that have been issued for "large > SMTP inputs (June 2026)", "TLSA parsing (June 2026)", and "SMTP > smuggling fixes". Those patches still need to be applied. > > These defects were found by Qualys assisted by Claude Mythos Preview, > and by OpenAI Security; more than half date from 20 or more years > ago. When I implemented Postfix, I knew that there were going to > be mistakes. That is the reason why Postfix has its architecture > and safety nets. The number of defects may seem large, but considering > that they were found in a code base of over 150 thousand lines, the > error rate is still lower than what I designed for. > > [...]
Just FYI: The Release Notes and PGP/GPG[12] signatures are "404 Not Found". _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
