Описание
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
A flaw was found in Postfix. This issue occurs when processing enhanced status codes, specifically an enhanced status code that lacks text following the third number. Depending on the configuration of the server, this allows a remote attacker to cause a buffer over-read of only 1 byte, leading to an application crash and resulting in a denial of service.
Отчет
This vulnerability cannot be triggered with an SMTP or LMTP server response. Instead, it is exposed only under specific server configurations:
- Access tables
- Policy server responses
- Pipe-to-command output, header_checks, body_checks, an error transport in transport_maps or a milter response
- DNSBL server TXT responses (specifically when Postfix is configured with "$rbl_code $rbl_text" in rbl_reply_maps or default_rbl_reply) As this flaw allows a remote attacker to cause a denial of service, it has been rated with an important severity.
Меры по смягчению последствий
To mitigate this vulnerability, review and adjust the following Postfix configurations:
- DNSBL: Remove the $rbl_text variable from the rbl_reply_maps and default_rbl_reply settings to prevent triggers via malicious DNSBL TXT responses.
- Policy Servers and Milters: Ensure any connected policy daemons or milters return fully RFC-compliant enhanced status codes. They must not return codes that lack text after the third digit (e.g., they should return 5.7.1 Rejected rather than just 5.7.1).
- Access Tables and Content Checks: Audit custom access tables, header_checks, body_checks, and transport_maps (specifically error transports) to confirm that any manually defined rejection messages or status codes include descriptive text following the numeric code.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | postfix | Out of support scope | ||
| Red Hat Enterprise Linux 7 | postfix | Affected | ||
| Red Hat Enterprise Linux 10 | postfix | Fixed | RHSA-2026:25930 | 15.06.2026 |
| Red Hat Enterprise Linux 8 | postfix | Fixed | RHSA-2026:25932 | 15.06.2026 |
| Red Hat Enterprise Linux 8 | postfix | Fixed | RHSA-2026:25932 | 15.06.2026 |
| Red Hat Enterprise Linux 9 | postfix | Fixed | RHSA-2026:26205 | 16.06.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 somet ...
EPSS
7.5 High
CVSS3