Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:25930

Опубликовано: 19 июн. 2026
Источник: rocky
Оценка: Important

Описание

Important: postfix security update

The postfix packages provide a Mail Transport Agent (MTA), which supports protocols like LDAP, SMTP AUTH (SASL), and TLS.

Security Fix(es):

  • postfix: buffer over-read via malformed enhanced status code (CVE-2026-43964)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
postfix-mysqlx86_6410.el10_2postfix-mysql-3.8.5-10.el10_2.x86_64.rpm
postfixx86_6410.el10_2postfix-3.8.5-10.el10_2.x86_64.rpm
postfix-perl-scriptsx86_6410.el10_2postfix-perl-scripts-3.8.5-10.el10_2.x86_64.rpm
postfix-pgsqlx86_6410.el10_2postfix-pgsql-3.8.5-10.el10_2.x86_64.rpm
postfix-pcrex86_6410.el10_2postfix-pcre-3.8.5-10.el10_2.x86_64.rpm
postfix-cdbx86_6410.el10_2postfix-cdb-3.8.5-10.el10_2.x86_64.rpm
postfix-lmdbx86_6410.el10_2postfix-lmdb-3.8.5-10.el10_2.x86_64.rpm
postfix-sqlitex86_6410.el10_2postfix-sqlite-3.8.5-10.el10_2.x86_64.rpm
postfix-ldapx86_6410.el10_2postfix-ldap-3.8.5-10.el10_2.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 3.7
ubuntu
3 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

CVSS3: 7.5
redhat
3 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

CVSS3: 3.7
nvd
3 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

CVSS3: 3.7
msrc
3 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

CVSS3: 3.7
debian
3 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 somet ...