PT-2026-36908 · Postfix+4 · Postfix+4

·

CVE-2026-43964

·

Published

2026-05-03

·

Updated

2026-07-06

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Postfix versions prior to 3.8.16 Postfix versions 3.9 prior to 3.9.10 Postfix versions 3.10 prior to 3.10.9
Description A buffer over-read can occur, potentially leading to a process crash, when an enhanced status code is used that lacks text after the third number.
Recommendations Update to version 3.8.16 or later. Update to version 3.9.10 or later. Update to version 3.10.9 or later.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:25930
ALSA-2026:25932
ALSA-2026:26205
BDU:2026-09784
CVE-2026-43964
OESA-2026-2209
OESA-2026-2288
OESA-2026-2289
OESA-2026-2290
OESA-2026-2291
OPENSUSE-SU-2026:10707-1
OPENSUSE-SU-2026:21020-1
RHSA-2026:25930
RHSA-2026:25932
RHSA-2026:26205
SUSE-SU-2026:22335-1
SUSE-SU-2026:2780-1
SUSE-SU-2026:2781-1
USN-8253-1
USN-8253-2

Affected Products

Linuxmint
Postfix
Red Os
Rocky Linux
Ubuntu