CVE-2026-43964

NameCVE-2026-43964
DescriptionPostfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1135718

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
postfix (PTS)bullseye3.5.25-0+deb11u1vulnerable
bookworm3.7.11-0+deb12u1vulnerable
trixie3.10.11-0+deb13u1fixed
trixie (security)3.10.12-0+deb13u2fixed
forky, sid3.11.5-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
postfixsourcetrixie3.10.10-0+deb13u1
postfixsource(unstable)3.11.2-11135718

Notes

[bookworm] - postfix <no-dsa> (Minor issue)
[bullseye] - postfix <postponed> (Minor issue, 1-byte OOB read in non-SMTP code)
https://www.mail-archive.com/postfix-announce@postfix.org/msg00110.html
https://www.openwall.com/lists/oss-security/2026/05/04/25

Search for package or bug name: Reporting problems