-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 10 Aug 2026 19:35:04 +0300
Source: postfix
Architecture: source
Version: 3.10.13-0+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Debian Postfix Team <[email protected]>
Changed-By: Michael Tokarev <[email protected]>
Changes:
 postfix (3.10.13-0+deb13u1) trixie-security; urgency=medium
 .
   * new upstream stable/bugfix/security release
     From the release announcement by Wietse Wenema at
     https://www.postfix.org/announcements/postfix-3.11.6.html :
 .
     These defects were found by Qualys assisted by Claude Mythos Preview,
     and by OpenAI Security; more than half date from 20 or more years ago.
     When I implemented Postfix, I knew that there were going to be mistakes.
     That is the reason why Postfix has its architecture and safety nets.
     The number of defects may seem large, but considering that they were
     found in a code base of over 150 thousand lines, the error rate
     is still lower than what I designed for.
 .
   o Policy bypass:
 .
    - Bug (introduced: Postfix 2.2, date: 20041102): missing SMTP server
      resets of MAIL FROM and RCPT TO command state after
      smtpd_end_of_data_restrictions rejected a message.  This resulted in
      SMTP protocol state desynchronization between the remote SMTP client
      and the Postfix SMTP server.
 .
    - A crafted remote SMTP client could then send RCPT TO and DATA without
      MAIL FROM, and deliver a second message.  Then,
      smtpd_end_of_data_restrictions skipped check_recipient_access
      constraints, because a recipient counter was > 1.
 .
    - The failure to reset MAIL FROM and RCPT TO state also affected Milter
      support (added in Postfix 2.3).  Here, after a Milter replied with
      "accept this message" based on the message envelope, and
      smtpd_end_of_data_restrictions rejected the message, the Postfix SMTP
      server as before accepted RCPT TO and DATA without MAIL FROM, and
      smtpd_end_of_data_restrictions as before skipped check_recipient_access
      constraints for the second message.  Under these conditions, the Postfix
      Milter client remained in the "accept this message" state, skipping
      Milter policy enforcement for the second message.
 .
   o Denial of service:
 .
    - Bug (defect introduced: Postfix 3.4, date: 20180805): SMTP server
      command history memory exhaustion with a large number of very small
      BDAT requests.
 .
    - Bug (defect introduced: Postfix 1.1, date: 20021116): address
      verification cache poisoning. A local user could use the postdrop
      command to submit an address verification probe with envelope or
      message content that Postfix rejected later, resulting in a negative
      address verification cache entry for that address.  On systems that
      enable address verification, the negative address verification cache
      entry would force the Postfix SMTP server to reject a message that it
      should accept (denial of service).
 .
   o Server crashes and panic()s:
 .
    - Bug (defect introduced: Postfix 3.4, date: 20180805): missing SMTP server
      reset of RCPT TO state, after a BDAT command error.  A crafted remote
      SMTP client could then send a DATA command without MAIL FROM or RCPT TO,
      and crash a Postfix SMTP daemon process with a null pointer read error.
 .
    - Bug (defect introduced: Postfix 2.4, date: 20051222): null pointer read
      crash while parsing a malformed Dovecot AUTH server response.
 .
   o Read after free, uninitialized read, under/over read:
 .
    - Bug (defect introduced: Postfix 2.8, date: 20100914): read-after-free
      in the PSC_CALL_BACK_NOTIFY() macro.  This had no effect on program
      execution, because myfree() wiped memory, and that memory was not yet
      reused.
 .
    - Read after free (no privilege escalation) in debug logging (defect
      introduced: Postfix 2.2, date: 20050117).
 .
    - Bug (defect introduced: Postfix 2.10, date: 20120617): uninitialized
      memory read in postscreen HaProxy client after remote I/O exception,
      causing garbage to be logged.
 .
    - Latent bug (defect introduced: Postfix 2.7, date: 20090618):
      uninitialized memory read after dnsblog(8) returns a string
      that is not an IPv4 address.
 .
    - Bug (defect introduced: before Postfix alpha, date 19970424): the DNS
      client could read up to two bytes past the end of an MX record, before
      discovering that the record was too short.  This behavior was later
      copied with SRV records, potentially over-reading up to six bytes.
 .
    - Bug (defect introduced: Postfix 1,1, date: 20010524): the postsuper
      command under-read or over-read a very short queue filename.  No crash,
      information leak, or privilege escalation.
 .
   o Other code hygiene:
 .
    - Bug (defect introduced: before Postfix alpha, date: 19971106): 'int'
      over-shift, in the queue file record-length parser.  Postfix programs
      do not generate such records, but an attacker could cause postdrop to
      reject input or panic().
 .
    - Bug (defect introduced: Postfix 2.2, date: 20050117):
      non-transitive comparison of IPv4 addresses.
 .
    - Bug (defect introduced: Postfix 1.0, date: 20000928): the fast
      flush server, used by the SMTP command "ETRN", and by the commands
      "postqueue -s site" and "postqueue -i queue_id" (and their sendmail(1)
      equivalents), used the wrong duplicate suppression API, resulting in
      unnecessary queue scans by the queue manager.
 .
    - Queue hygiene: the postdrop command accepted the null record type
      which the rest of Postfix ignores.
Checksums-Sha1:
 913e6f7ecc74b6642b2b4ec8a6eb3d68f3696f78 3203 postfix_3.10.13-0+deb13u1.dsc
 f9d703bfa5118ef127d2d255122ad92e6151cd1b 5048920 postfix_3.10.13.orig.tar.gz
 dc9a26c47559c611859ef50343c122572b5413db 220 postfix_3.10.13.orig.tar.gz.asc
 e1d3a3a8f70e92bc5d15e1c323d0a4906acab0b8 204240 
postfix_3.10.13-0+deb13u1.debian.tar.xz
 414eeb49daee75254ec24e36082a42ecede522eb 5756 
postfix_3.10.13-0+deb13u1_source.buildinfo
Checksums-Sha256:
 5f1916822244e13900b6b86affb7475e010140cc501ff4681f786023b5d55d7c 3203 
postfix_3.10.13-0+deb13u1.dsc
 de6526fb11bbf20fcfa5aa4b67e88cc6b246cad614a9bcb4b006f457ba3788bc 5048920 
postfix_3.10.13.orig.tar.gz
 bf23e5117b5c6337e6aa9142c4b2b5a6e06220e68b023dd50d7ac42f0a3b359d 220 
postfix_3.10.13.orig.tar.gz.asc
 5d737f7d2590517fb0e9492e201875350558fbeaa9fb3e489b075e8278eba924 204240 
postfix_3.10.13-0+deb13u1.debian.tar.xz
 95144c307860a8a5777c4b25dd8f281bd4c04df9fe608d792dfd4b971610445a 5756 
postfix_3.10.13-0+deb13u1_source.buildinfo
Files:
 d26d3ab4123c4c753302e1da9095e0da 3203 mail optional 
postfix_3.10.13-0+deb13u1.dsc
 1de1237bbccd164a192e6712ede4c1d4 5048920 mail optional 
postfix_3.10.13.orig.tar.gz
 85998e79e87a8414ef5e4635594ed921 220 mail optional 
postfix_3.10.13.orig.tar.gz.asc
 ac278e3281575916bf7748d08ff3ee1e 204240 mail optional 
postfix_3.10.13-0+deb13u1.debian.tar.xz
 8651689376a4be347581afe7dd20a8be 5756 mail optional 
postfix_3.10.13-0+deb13u1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEZKoqtTHVaQM2a/75gqpKJDselHgFAmp5/ksACgkQgqpKJDse
lHhZKRAAhAkzckUho9OJyQJjE48RLa9+Z9XdVvt39gjUbYBFLxQJwZtgH/O16M2d
y5vIqmqDj/ceQGADyL0C/uKuRsOapQKPzLWqkWoVKfy3gHXVzdH68Og28OkTyd90
aoefZ5x6Y3JnJ/yOFONzgOYNhxxDLDPfEOdHOP0udD4YPr69q/hAgkhow9vK+OC6
LPUpo6lMLTXkfjL29ww9SIYE57G7vH8PfVdbZRcL2FIv/12bTenUZDeMN6OhyQtV
3+jPf9Bvcu0WI9QekhrjuUXnfOueKW5Si1GamiymEIaLiCH+0wtat4xH9UAGp2zx
bXUgvDO94SvGpG7SCj4Mfv1FDhZCyy1MYBeUSsk42Tj7i8Zd/Rwe8vq6Xqdmc4KY
lepZlT8+gPVrU86o5HoARh8VSwODoSi2AHeTT30dsbI2f5wkItnyTfTv3vX++P7r
xXDB++0Dcn6iDDik9ohhclqq1O+jQjl8S0b7iFkFD6W+h5hZaihBVFN9D4u4eYkZ
yhc2psDq/Attv7rytOG5JHpdhI0bLiF/zpPjqeImpvtvAHX6AedUG5t+lYGBVAf7
DlTOikixYpmopzt56LZmgOkPA6WaI7vDpPnwme1RuQ8c68OEHqDmIkPdhMX6nAan
zm/tWgTyc66/d8VrcAaPmo5f/awqENTfvnsNlXvhfuLQITZNT6k=
=dk0x
-----END PGP SIGNATURE-----

Attachment: pgp8TCEe6eUcb.pgp
Description: PGP signature

Reply via email to