Low severity3.7NVD Advisory· Published May 4, 2026· Updated Aug 7, 2026
CVE-2026-43964
CVE-2026-43964
Description
Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14- osv-coords12 versionspkg:rpm/almalinux/postfixpkg:rpm/almalinux/postfix-cdbpkg:rpm/almalinux/postfix-ldappkg:rpm/almalinux/postfix-lmdbpkg:rpm/almalinux/postfix-mysqlpkg:rpm/almalinux/postfix-pcrepkg:rpm/almalinux/postfix-perl-scriptspkg:rpm/almalinux/postfix-pgsqlpkg:rpm/almalinux/postfix-sqlitepkg:rpm/opensuse/postfix&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/postfix&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/postfix-bdb&distro=openSUSE%20Leap%2016.0
< 2:3.8.5-10.el10_2+ 11 more
- (no CPE)range: < 2:3.8.5-10.el10_2
- (no CPE)range: < 2:3.8.5-10.el10_2
- (no CPE)range: < 2:3.8.5-10.el10_2
- (no CPE)range: < 2:3.8.5-10.el10_2
- (no CPE)range: < 2:3.8.5-10.el10_2
- (no CPE)range: < 2:3.8.5-10.el10_2
- (no CPE)range: < 2:3.8.5-10.el10_2
- (no CPE)range: < 2:3.8.5-10.el10_2
- (no CPE)range: < 2:3.8.5-10.el10_2
- (no CPE)range: < 3.10.2-160000.3.1
- (no CPE)range: < 3.11.2-1.1
- (no CPE)range: < 3.10.2-160000.3.1
Patches
Vulnerability mechanics
References
12- www.openwall.com/lists/oss-security/2026/05/04/30nvdMailing ListThird Party Advisory
- www.mail-archive.com/[email protected]/msg00110.htmlnvdMailing ListThird Party Advisory
- access.redhat.com/errata/RHSA-2026:25930nvd
- access.redhat.com/errata/RHSA-2026:25932nvd
- access.redhat.com/errata/RHSA-2026:26205nvd
- access.redhat.com/errata/RHSA-2026:50963nvd
- access.redhat.com/errata/RHSA-2026:50964nvd
- access.redhat.com/errata/RHSA-2026:51034nvd
- access.redhat.com/errata/RHSA-2026:51436nvd
- access.redhat.com/security/cve/CVE-2026-43964nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43964.jsonnvd
News mentions
1- Patch Tuesday - May 2026Rapid7 Blog · May 13, 2026