yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2026-43964
Component Overview
Vulnerability Overview
Name
CVE-2026-43964
Source
NVD (
link
)
Debian (
link
)
Description
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
CWEs
CWE-193
Published Date
May 4, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://www.mail-archive.com/postfix-announce@postfix.org/msg00110.html
Mailing List
http://www.openwall.com/lists/oss-security/2026/05/04/30
Mailing List
Analysis
#
Affected Component
Analysis
postfix
Exploitable
Vulnerability Ratings
#
3.7
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
postfix
openwrt
master
3.8.2-r2
Exploitable
postfix
openwrt
openwrt-25.12
3.8.2-r2
Exploitable
postfix
yocto
master
3.11.3
Not Affected
postfix
yocto
scarthgap
3.8.17
Not Affected