Home
LOW: 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LDefault status
unaffected
2.3 (custom) before 3.8.16
affected
3.9 (custom) before 3.9.10
affected
3.10 (custom) before 3.10.9
affected
Description
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
Problem types
Product status
2.3 (custom) before 3.8.16
3.9 (custom) before 3.9.10
3.10 (custom) before 3.10.9
References
www.openwall.com/lists/oss-security/2026/05/04/30
www.mail-archive.com/...x-announce@postfix.org/msg00110.html