CVE Vulnerabilities

CVE-2026-43964

Off-by-one Error

Published: May 04, 2026 | Modified: May 11, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

Weakness

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Affected Software

NameVendorStart VersionEnd Version
PostfixPostfix*3.8.16 (excluding)
PostfixPostfix3.9.0 (including)3.9.10 (excluding)
PostfixPostfix3.10.0 (including)3.10.9 (excluding)
Red Hat Enterprise Linux 10RedHatpostfix-2:3.8.5-10.el10_2*
Red Hat Enterprise Linux 8RedHatpostfix-2:3.5.8-8.el8_10*
Red Hat Enterprise Linux 8RedHatpostfix-2:3.5.8-8.el8_10*
Red Hat Enterprise Linux 9RedHatpostfix-2:3.5.25-3.el9_8*
PostfixUbuntudevel*
PostfixUbuntuesm-infra-legacy/trusty*
PostfixUbuntuesm-infra-legacy/xenial*
PostfixUbuntuesm-infra/bionic*
PostfixUbuntuesm-infra/focal*
PostfixUbuntuesm-infra/xenial*
PostfixUbuntujammy*
PostfixUbuntunoble*
PostfixUbuntuquesting*
PostfixUbunturesolute*

Potential Mitigations

References