CVE-2026-43964
EUVD-2026-2711504.05.2026, 19:16
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| postfix | postfix | 𝑥 < 3.8.16 |
| postfix | postfix | 3.9.0 ≤ 𝑥 < 3.9.10 |
| postfix | postfix | 3.10.0 ≤ 𝑥 < 3.10.9 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 2:3.8.5-10.el10_2 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8 | 2:3.5.8-8.el8_10 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 2:3.5.8-4.el8_6.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 2:3.5.8-4.el8_6.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 2:3.5.8-4.el8_8.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 2:3.5.8-4.el8_8.1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 2:3.5.25-3.el9_8 ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| postfix |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| postfix |
| ||||||||||
| postfix-bdb |
| ||||||||||
| postfix-bdb-lmdb |
| ||||||||||
| postfix-devel |
| ||||||||||
| postfix-doc |
| ||||||||||
| postfix-ldap |
| ||||||||||
| postfix-mysql |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| postfix |
| ||||
| postfix-cdb |
| ||||
| postfix-ldap |
| ||||
| postfix-lmdb |
| ||||
| postfix-mysql |
| ||||
| postfix-pcre |
| ||||
| postfix-perl-scripts |
| ||||
| postfix-pgsql |
| ||||
| postfix-sqlite |
|
Common Weakness Enumeration
References