CVE-2026-43964Disclosure(postfix / postfix)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch postfix postfix systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-193

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • postfix

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-05); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
postfix

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-05-04: 2Mentions · 2026-05-05: 3Mentions · 2026-06-02: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-06-02: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-05: 3Technical Details · 2026-06-02: 105-0405-0506-02
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-042
Disclosure1General1
2026-05-053
Disclosure2Patch1
2026-06-021
Patch1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-43964: Postfix: Buffer over-read when an enhanced status code is not followed by other text https://www.openwall.com/lists/oss-security/2026/05/04/30 For example, "5.7.2" without text after the three-number code. Cannot be triggered with an SMTP or LMTP server response. Can result in process termination.

    Post summary

    An advisory for CVE‑2026‑43964 that describes a buffer over‑read vulnerability in Postfix when an enhanced status code lacks trailing text, potentially terminating the process. No PoC, exploit, active exploitation, or patch information is provided.

    01031417
    4.7K followersView on X
  • TUX Network@tuxnet_work
    Patch

    ⚠️ Postfix Security Notice A new issue (CVE-2026-43964) affects Postfix before 3.8.16 / 3.9.10 / 3.10.9. Bug: buffer over-read → possible crashes (DoS in some setups) 👉 Check your version & update ASAP. Read more: https://tux.wf/cdGmXPws #Postfix #Linux #Security #Mail https://t.co/7TqA1ocdJm

    Post summary

    The notice warns of a CVE‑2026‑43964 buffer over‑read in Postfix that can cause DoS, urging users to update to the latest patched versions.

    0001063
    2 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43964 Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text aft… https://www.cve.org/CVERecord?id=CVE-2026-43964

    Post summary

    The text announces CVE-2026-43964, a Postfix vulnerability involving a buffer over‑read that can crash the process via an enhanced status code.

    00010332
    57.4K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Fedora 43 and 44 push Postfix 2:3.10.10-1 security update fixing critical buffer over-read CVE-2026-43964, mail admins urged to upgrade via dnf now. https://threatcluster.io/cluster/fedora-postfix-buffer-over-read-vulnerability-advisory-41135294

    Post summary

    Fedora releases a Postfix security update for CVE-2026-43964, urging administrators to apply the patch immediately.

    0000083
    294 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-43964 Buffer Over-Read and Process Crash in Postfix Versions Before 3.8.16, 3.9.10, and 3.10.9 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43964

    Post summary

    This post references the CVE‑2026‑43964 vulnerability affecting specified Postfix versions, describing a buffer over‑read that causes a process crash, but does not provide PoC, exploit, or patch details.

    0000048
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-43964 Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text aft… https://www.cve.org/CVERecord?id=CVE-2026-43964 ----- Traducción: CVE-2026-43964 Pos… http://infoflow.cloud`

    Post summary

    The post refers to CVE-2026‑43964 in Postfix, describing a buffer over‑read that can cause a crash; it provides a minimal summary and link but no PoC, exploit code, patch, or active exploitation information.

    0000032
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppostfixpostfix---

Explore more