CVE.RADIO
FREN

CVE-2026-43964

postfixVulnerabilityCVSS 3.7Patched

No public exploitation has been reported so far. A fixed version is available (see the table below).

Recommended action: Update to the fixed version listed for your distribution using the native package manager.

Severity metrics

CVSS 3.1 : 3.7 LOW

Attack vectorNetwork (remote)
Attack complexityHigh
Privileges requiredNone
User interactionNone
ScopeUnchanged
Confidentiality impactNone
Integrity impactNone
Availability impactLow

Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected & fixed versions by distribution

Versions are the native distribution strings (backport-aware): RHEL/Debian/SUSE backport fixes, so compare with the distro version comparator (dpkg / rpm / vercmp), not the upstream version.

DistributionPackageAffectedFixed versionStatus
Debian:11postfix--affected (no fix yet)
Debian:12postfix--affected (no fix yet)
Debian:13postfix-3.10.10-0+deb13u1fixed
Debian:14postfix-3.11.2-1fixed
Ubuntu:Pro:14.04:LTSpostfix-2.11.0-1ubuntu1.2+esm4fixed
Ubuntu:Pro:16.04:LTSpostfix-3.1.0-3ubuntu0.4+esm4fixed
Ubuntu:Pro:18.04:LTSpostfix-3.3.0-1ubuntu0.4+esm4fixed
Ubuntu:Pro:20.04:LTSpostfix-3.4.13-0ubuntu1.4+esm1fixed
Ubuntu:22.04:LTSpostfix-3.6.4-1ubuntu1.4fixed
Ubuntu:24.04:LTSpostfix-3.8.6-1ubuntu0.1fixed
Ubuntu:25.10postfix-3.10.2-1ubuntu2.1fixed
Ubuntu:26.04:LTSpostfix-3.10.6-4ubuntu2.1fixed
SUSE:Linux Enterprise Server 16.0postfix-3.10.2-160000.3.1fixed
SUSE:Linux Enterprise Server for SAP applications 16.0postfix-3.10.2-160000.3.1fixed
SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5postfix-3.2.10-3.33.1fixed
SUSE:Linux Enterprise Module for Basesystem 15 SP7postfix-3.8.4-150600.3.6.1fixed
SUSE:Linux Enterprise Module for Server Applications 15 SP7postfix-3.8.4-150600.3.6.1fixed
openSUSE:Tumbleweedpostfix-3.11.2-1.1fixed
openSUSE:Leap 16.0postfix-3.10.2-160000.3.1fixed
Red Hat:enterprise_linux:10.2postfix-2:3.8.5-10.el10_2fixed
Red Hat:enterprise_linux:8::baseospostfix-2:3.5.8-8.el8_10fixed
Red Hat:enterprise_linux:9::appstreampostfix-2:3.5.25-3.el9_8fixed

Sources