Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:26205

Опубликовано: 17 июн. 2026
Источник: rocky
Оценка: Important

Описание

Important: postfix security update

The postfix packages provide a Mail Transport Agent (MTA), which supports protocols like LDAP, SMTP AUTH (SASL), and TLS.

Security Fix(es):

  • postfix: buffer over-read via malformed enhanced status code (CVE-2026-43964)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
postfixaarch643.el9_8postfix-3.5.25-3.el9_8.aarch64.rpm
postfix-cdbaarch643.el9_8postfix-cdb-3.5.25-3.el9_8.aarch64.rpm
postfix-ldapaarch643.el9_8postfix-ldap-3.5.25-3.el9_8.aarch64.rpm
postfix-lmdbaarch643.el9_8postfix-lmdb-3.5.25-3.el9_8.aarch64.rpm
postfix-mysqlaarch643.el9_8postfix-mysql-3.5.25-3.el9_8.aarch64.rpm
postfix-pcreaarch643.el9_8postfix-pcre-3.5.25-3.el9_8.aarch64.rpm
postfix-perl-scriptsaarch643.el9_8postfix-perl-scripts-3.5.25-3.el9_8.aarch64.rpm
postfix-pgsqlaarch643.el9_8postfix-pgsql-3.5.25-3.el9_8.aarch64.rpm
postfix-sqliteaarch643.el9_8postfix-sqlite-3.5.25-3.el9_8.aarch64.rpm
postfixx86_643.el9_8postfix-3.5.25-3.el9_8.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 3.7
ubuntu
4 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

CVSS3: 7.5
redhat
4 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

CVSS3: 3.7
nvd
4 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

CVSS3: 3.7
msrc
4 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

CVSS3: 3.7
debian
4 месяца назад

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 somet ...