Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43964

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

A flaw was found in Postfix. This issue occurs when processing enhanced status codes, specifically an enhanced status code that lacks text following the third number. Depending on the configuration of the server, this allows a remote attacker to cause a buffer over-read of only 1 byte, leading to an application crash and resulting in a denial of service.

Отчет

This vulnerability cannot be triggered with an SMTP or LMTP server response. Instead, it is exposed only under specific server configurations:

  • Access tables
  • Policy server responses
  • Pipe-to-command output, header_checks, body_checks, an error transport in transport_maps or a milter response
  • DNSBL server TXT responses (specifically when Postfix is configured with "$rbl_code $rbl_text" in rbl_reply_maps or default_rbl_reply) As this flaw allows a remote attacker to cause a denial of service, it has been rated with an important severity.

Меры по смягчению последствий

To mitigate this vulnerability, review and adjust the following Postfix configurations:

  • DNSBL: Remove the $rbl_text variable from the rbl_reply_maps and default_rbl_reply settings to prevent triggers via malicious DNSBL TXT responses.
  • Policy Servers and Milters: Ensure any connected policy daemons or milters return fully RFC-compliant enhanced status codes. They must not return codes that lack text after the third digit (e.g., they should return 5.7.1 Rejected rather than just 5.7.1).
  • Access Tables and Content Checks: Audit custom access tables, header_checks, body_checks, and transport_maps (specifically error transports) to confirm that any manually defined rejection messages or status codes include descriptive text following the numeric code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6postfixOut of support scope
Red Hat Enterprise Linux 7postfixAffected
Red Hat Enterprise Linux 10postfixFixedRHSA-2026:2593015.06.2026
Red Hat Enterprise Linux 8postfixFixedRHSA-2026:2593215.06.2026
Red Hat Enterprise Linux 8postfixFixedRHSA-2026:2593215.06.2026
Red Hat Enterprise Linux 9postfixFixedRHSA-2026:2620516.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=2466488postfix: buffer over-read via malformed enhanced status code

EPSS

Процентиль: 34%
0.00415
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
3 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

CVSS3: 3.7
nvd
3 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

CVSS3: 3.7
msrc
3 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

CVSS3: 3.7
debian
3 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 somet ...

suse-cvrf
около 1 месяца назад

Security update for postfix

EPSS

Процентиль: 34%
0.00415
Низкий

7.5 High

CVSS3