Hi!

On Mon, 10 Aug 2026 17:50:35 +0200, Wietse Venema via Postfix-users wrote:
> 
> [An on-line version of this announcement will be available at
> https://www.postfix.org/announcements/postfix-3.11.6.html]
> 
> This release addresses medium-impact problems that need to be fixed
> as some enable remote DOS or policy bypass.
> 
> The fixes below, and more, are also released in the unstable version
> postfix-3.12-20260809.
> 
> In addition to updated releases for the supported Postfix versions
> 3.8-3.11, releases will also be available for the out-of-support
> Postfix versions 3.5-3.7. NOTE: these do not include the patches
> for out-of-support Postfix versions that have been issued for "large
> SMTP inputs (June 2026)", "TLSA parsing (June 2026)", and "SMTP
> smuggling fixes". Those patches still need to be applied.
> 
> These defects were found by Qualys assisted by Claude Mythos Preview,
> and by OpenAI Security; more than half date from 20 or more years
> ago. When I implemented Postfix, I knew that there were going to
> be mistakes. That is the reason why Postfix has its architecture
> and safety nets. The number of defects may seem large, but considering
> that they were found in a code base of over 150 thousand lines, the
> error rate is still lower than what I designed for.
>
> [...]

Just FYI:
The Release Notes and PGP/GPG[12] signatures are "404 Not Found".

_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to