CVE-2026-43964
EUVD-2026-2711504.05.2026, 19:16
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| postfix | postfix | 𝑥 < 3.8.16 |
| postfix | postfix | 3.9.0 ≤ 𝑥 < 3.9.10 |
| postfix | postfix | 3.10.0 ≤ 𝑥 < 3.10.9 |
𝑥
= Vulnerable software versions
Debian Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| postfix |
| ||||
| postfix-cdb |
| ||||
| postfix-ldap |
| ||||
| postfix-lmdb |
| ||||
| postfix-mysql |
| ||||
| postfix-pcre |
| ||||
| postfix-perl-scripts |
| ||||
| postfix-pgsql |
| ||||
| postfix-sqlite |
|
Common Weakness Enumeration
Vulnerability Media Exposure