-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 10 Aug 2026 19:35:04 +0300 Source: postfix Architecture: source Version: 3.10.13-0+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: Debian Postfix Team Changed-By: Michael Tokarev Changes: postfix (3.10.13-0+deb13u1) trixie-security; urgency=medium . * new upstream stable/bugfix/security release From the release announcement by Wietse Wenema at https://www.postfix.org/announcements/postfix-3.11.6.html : . These defects were found by Qualys assisted by Claude Mythos Preview, and by OpenAI Security; more than half date from 20 or more years ago. When I implemented Postfix, I knew that there were going to be mistakes. That is the reason why Postfix has its architecture and safety nets. The number of defects may seem large, but considering that they were found in a code base of over 150 thousand lines, the error rate is still lower than what I designed for. . o Policy bypass: . - Bug (introduced: Postfix 2.2, date: 20041102): missing SMTP server resets of MAIL FROM and RCPT TO command state after smtpd_end_of_data_restrictions rejected a message. This resulted in SMTP protocol state desynchronization between the remote SMTP client and the Postfix SMTP server. . - A crafted remote SMTP client could then send RCPT TO and DATA without MAIL FROM, and deliver a second message. Then, smtpd_end_of_data_restrictions skipped check_recipient_access constraints, because a recipient counter was > 1. . - The failure to reset MAIL FROM and RCPT TO state also affected Milter support (added in Postfix 2.3). Here, after a Milter replied with "accept this message" based on the message envelope, and smtpd_end_of_data_restrictions rejected the message, the Postfix SMTP server as before accepted RCPT TO and DATA without MAIL FROM, and smtpd_end_of_data_restrictions as before skipped check_recipient_access constraints for the second message. Under these conditions, the Postfix Milter client remained in the "accept this message" state, skipping Milter policy enforcement for the second message. . o Denial of service: . - Bug (defect introduced: Postfix 3.4, date: 20180805): SMTP server command history memory exhaustion with a large number of very small BDAT requests. . - Bug (defect introduced: Postfix 1.1, date: 20021116): address verification cache poisoning. A local user could use the postdrop command to submit an address verification probe with envelope or message content that Postfix rejected later, resulting in a negative address verification cache entry for that address. On systems that enable address verification, the negative address verification cache entry would force the Postfix SMTP server to reject a message that it should accept (denial of service). . o Server crashes and panic()s: . - Bug (defect introduced: Postfix 3.4, date: 20180805): missing SMTP server reset of RCPT TO state, after a BDAT command error. A crafted remote SMTP client could then send a DATA command without MAIL FROM or RCPT TO, and crash a Postfix SMTP daemon process with a null pointer read error. . - Bug (defect introduced: Postfix 2.4, date: 20051222): null pointer read crash while parsing a malformed Dovecot AUTH server response. . o Read after free, uninitialized read, under/over read: . - Bug (defect introduced: Postfix 2.8, date: 20100914): read-after-free in the PSC_CALL_BACK_NOTIFY() macro. This had no effect on program execution, because myfree() wiped memory, and that memory was not yet reused. . - Read after free (no privilege escalation) in debug logging (defect introduced: Postfix 2.2, date: 20050117). . - Bug (defect introduced: Postfix 2.10, date: 20120617): uninitialized memory read in postscreen HaProxy client after remote I/O exception, causing garbage to be logged. . - Latent bug (defect introduced: Postfix 2.7, date: 20090618): uninitialized memory read after dnsblog(8) returns a string that is not an IPv4 address. . - Bug (defect introduced: before Postfix alpha, date 19970424): the DNS client could read up to two bytes past the end of an MX record, before discovering that the record was too short. This behavior was later copied with SRV records, potentially over-reading up to six bytes. . - Bug (defect introduced: Postfix 1,1, date: 20010524): the postsuper command under-read or over-read a very short queue filename. No crash, information leak, or privilege escalation. . o Other code hygiene: . - Bug (defect introduced: before Postfix alpha, date: 19971106): 'int' over-shift, in the queue file record-length parser. Postfix programs do not generate such records, but an attacker could cause postdrop to reject input or panic(). . - Bug (defect introduced: Postfix 2.2, date: 20050117): non-transitive comparison of IPv4 addresses. . - Bug (defect introduced: Postfix 1.0, date: 20000928): the fast flush server, used by the SMTP command "ETRN", and by the commands "postqueue -s site" and "postqueue -i queue_id" (and their sendmail(1) equivalents), used the wrong duplicate suppression API, resulting in unnecessary queue scans by the queue manager. . - Queue hygiene: the postdrop command accepted the null record type which the rest of Postfix ignores. Checksums-Sha1: 913e6f7ecc74b6642b2b4ec8a6eb3d68f3696f78 3203 postfix_3.10.13-0+deb13u1.dsc f9d703bfa5118ef127d2d255122ad92e6151cd1b 5048920 postfix_3.10.13.orig.tar.gz dc9a26c47559c611859ef50343c122572b5413db 220 postfix_3.10.13.orig.tar.gz.asc e1d3a3a8f70e92bc5d15e1c323d0a4906acab0b8 204240 postfix_3.10.13-0+deb13u1.debian.tar.xz 414eeb49daee75254ec24e36082a42ecede522eb 5756 postfix_3.10.13-0+deb13u1_source.buildinfo Checksums-Sha256: 5f1916822244e13900b6b86affb7475e010140cc501ff4681f786023b5d55d7c 3203 postfix_3.10.13-0+deb13u1.dsc de6526fb11bbf20fcfa5aa4b67e88cc6b246cad614a9bcb4b006f457ba3788bc 5048920 postfix_3.10.13.orig.tar.gz bf23e5117b5c6337e6aa9142c4b2b5a6e06220e68b023dd50d7ac42f0a3b359d 220 postfix_3.10.13.orig.tar.gz.asc 5d737f7d2590517fb0e9492e201875350558fbeaa9fb3e489b075e8278eba924 204240 postfix_3.10.13-0+deb13u1.debian.tar.xz 95144c307860a8a5777c4b25dd8f281bd4c04df9fe608d792dfd4b971610445a 5756 postfix_3.10.13-0+deb13u1_source.buildinfo Files: d26d3ab4123c4c753302e1da9095e0da 3203 mail optional postfix_3.10.13-0+deb13u1.dsc 1de1237bbccd164a192e6712ede4c1d4 5048920 mail optional postfix_3.10.13.orig.tar.gz 85998e79e87a8414ef5e4635594ed921 220 mail optional postfix_3.10.13.orig.tar.gz.asc ac278e3281575916bf7748d08ff3ee1e 204240 mail optional postfix_3.10.13-0+deb13u1.debian.tar.xz 8651689376a4be347581afe7dd20a8be 5756 mail optional postfix_3.10.13-0+deb13u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEZKoqtTHVaQM2a/75gqpKJDselHgFAmp5/ksACgkQgqpKJDse lHhZKRAAhAkzckUho9OJyQJjE48RLa9+Z9XdVvt39gjUbYBFLxQJwZtgH/O16M2d y5vIqmqDj/ceQGADyL0C/uKuRsOapQKPzLWqkWoVKfy3gHXVzdH68Og28OkTyd90 aoefZ5x6Y3JnJ/yOFONzgOYNhxxDLDPfEOdHOP0udD4YPr69q/hAgkhow9vK+OC6 LPUpo6lMLTXkfjL29ww9SIYE57G7vH8PfVdbZRcL2FIv/12bTenUZDeMN6OhyQtV 3+jPf9Bvcu0WI9QekhrjuUXnfOueKW5Si1GamiymEIaLiCH+0wtat4xH9UAGp2zx bXUgvDO94SvGpG7SCj4Mfv1FDhZCyy1MYBeUSsk42Tj7i8Zd/Rwe8vq6Xqdmc4KY lepZlT8+gPVrU86o5HoARh8VSwODoSi2AHeTT30dsbI2f5wkItnyTfTv3vX++P7r xXDB++0Dcn6iDDik9ohhclqq1O+jQjl8S0b7iFkFD6W+h5hZaihBVFN9D4u4eYkZ yhc2psDq/Attv7rytOG5JHpdhI0bLiF/zpPjqeImpvtvAHX6AedUG5t+lYGBVAf7 DlTOikixYpmopzt56LZmgOkPA6WaI7vDpPnwme1RuQ8c68OEHqDmIkPdhMX6nAan zm/tWgTyc66/d8VrcAaPmo5f/awqENTfvnsNlXvhfuLQITZNT6k= =dk0x -----END PGP SIGNATURE-----