Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:26205

Опубликовано: 17 июн. 2026
Источник: rocky
Оценка: Important

Описание

Important: postfix security update

The postfix packages provide a Mail Transport Agent (MTA), which supports protocols like LDAP, SMTP AUTH (SASL), and TLS.

Security Fix(es):

  • postfix: buffer over-read via malformed enhanced status code (CVE-2026-43964)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
postfixx86_643.el9_8postfix-3.5.25-3.el9_8.x86_64.rpm
postfix-cdbx86_643.el9_8postfix-cdb-3.5.25-3.el9_8.x86_64.rpm
postfix-ldapx86_643.el9_8postfix-ldap-3.5.25-3.el9_8.x86_64.rpm
postfix-lmdbx86_643.el9_8postfix-lmdb-3.5.25-3.el9_8.x86_64.rpm
postfix-mysqlx86_643.el9_8postfix-mysql-3.5.25-3.el9_8.x86_64.rpm
postfix-pcrex86_643.el9_8postfix-pcre-3.5.25-3.el9_8.x86_64.rpm
postfix-perl-scriptsx86_643.el9_8postfix-perl-scripts-3.5.25-3.el9_8.x86_64.rpm
postfix-pgsqlx86_643.el9_8postfix-pgsql-3.5.25-3.el9_8.x86_64.rpm
postfix-sqlitex86_643.el9_8postfix-sqlite-3.5.25-3.el9_8.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 3.7
ubuntu
3 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

CVSS3: 7.5
redhat
3 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

CVSS3: 3.7
nvd
3 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

CVSS3: 3.7
msrc
3 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

CVSS3: 3.7
debian
3 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 somet ...