DEBIAN-CVE-2026-43964

Source
https://security-tracker.debian.org/tracker/CVE-2026-43964
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-43964.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-43964
Upstream
  • CVE-2026-43964
Published
2026-05-04T19:16:07Z
Modified
2026-09-14T17:03:13Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

References

Affected packages

Debian:12 / postfix

Package

Name
postfix
Purl
pkg:deb/debian/postfix?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.7.5-2
3.7.6-0+deb12u1
3.7.6-0+deb12u2
3.7.9-0+deb12u1
3.7.10-0+deb12u1
3.7.11-0+deb12u1
3.8.1-1
3.8.1-2
3.8.2-1
3.8.3-1
3.8.4-1
3.8.5-1
3.8.6-1
3.9.0-1~exp1
3.9.0-1
3.9.0-2
3.9.0-3
3.9.0-4
3.9.1-1
3.9.1-2
3.9.1-3
3.9.1-4
3.9.1-5
3.9.1-6
3.9.1-7
3.9.1-8
3.9.1-9
3.9.1-10
3.10.1-1
3.10.2-1
3.10.3-1
3.10.3-2~bpo12+1
3.10.3-2
3.10.3-3
3.10.4-1~deb13u1
3.10.4-1
3.10.4-2
3.10.4-3
3.10.5-1~deb13u1
3.10.5-1
3.10.5-2
3.10.5-3
3.10.6-1
3.10.6-3
3.10.6-4
3.10.8-1
3.11.0-1
3.11.0-2
3.11.0-3
3.11.0-4
3.11.2-1
3.11.2-2
3.11.2-3
3.11.2-4
3.11.3-1
3.11.3-2
3.11.4-1
3.11.4-2
3.11.5-1
3.11.6-1
3.11.7-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-43964.json"

Debian:13 / postfix

Package

Name
postfix
Purl
pkg:deb/debian/postfix?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.10.10-0+deb13u1

Affected versions

3.*
3.10.3-2
3.10.3-3
3.10.4-1~deb13u1
3.10.4-1
3.10.4-2
3.10.4-3
3.10.5-1~deb13u1
3.10.5-1
3.10.5-2
3.10.5-3
3.10.6-1
3.10.6-3
3.10.6-4
3.10.8-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-43964.json"

Debian:14 / postfix

Package

Name
postfix
Purl
pkg:deb/debian/postfix?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.11.2-1

Affected versions

3.*
3.10.3-2
3.10.3-3
3.10.4-1~deb13u1
3.10.4-1
3.10.4-2
3.10.4-3
3.10.5-1~deb13u1
3.10.5-1
3.10.5-2
3.10.5-3
3.10.6-1
3.10.6-3
3.10.6-4
3.10.8-1
3.11.0-1
3.11.0-2
3.11.0-3
3.11.0-4

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-43964.json"