{"id":"ALSA-2026:26205","summary":"Important: postfix security update","details":"The postfix packages provide a Mail Transport Agent (MTA), which supports protocols like LDAP, SMTP AUTH (SASL), and TLS.  \n\nSecurity Fix(es):  \n\n  * postfix: buffer over-read via malformed enhanced status code (CVE-2026-43964)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n","modified":"2026-06-18T12:15:04.489720722Z","published":"2026-06-16T00:00:00Z","related":["CVE-2026-43964"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:26205"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-43964"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2466488"},{"type":"ADVISORY","url":"https://errata.almalinux.org/9/ALSA-2026-26205.html"}],"affected":[{"package":{"name":"postfix","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/postfix"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.5.25-3.el9_8"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:26205.json"}},{"package":{"name":"postfix-cdb","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/postfix-cdb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.5.25-3.el9_8"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:26205.json"}},{"package":{"name":"postfix-ldap","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/postfix-ldap"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.5.25-3.el9_8"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:26205.json"}},{"package":{"name":"postfix-lmdb","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/postfix-lmdb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.5.25-3.el9_8"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:26205.json"}},{"package":{"name":"postfix-mysql","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/postfix-mysql"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.5.25-3.el9_8"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:26205.json"}},{"package":{"name":"postfix-pcre","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/postfix-pcre"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.5.25-3.el9_8"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:26205.json"}},{"package":{"name":"postfix-perl-scripts","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/postfix-perl-scripts"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.5.25-3.el9_8"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:26205.json"}},{"package":{"name":"postfix-pgsql","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/postfix-pgsql"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.5.25-3.el9_8"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:26205.json"}},{"package":{"name":"postfix-sqlite","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/postfix-sqlite"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.5.25-3.el9_8"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:26205.json"}}],"schema_version":"1.7.5"}