Red Hat Product Errata RHSA-2026:51436 - Security Advisory Issued: 2026-08-06 Updated: 2026-08-06 RHSA-2026:51436 - Security Advisory Overview Updated Packages Synopsis Important: postfix security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for postfix is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The postfix packages provide a Mail Transport Agent (MTA), which supports protocols like LDAP, SMTP AUTH (SASL), and TLS. Security Fix(es): postfix: buffer over-read via malformed enhanced status code (CVE-2026-43964) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2466488 - CVE-2026-43964 postfix: buffer over-read via malformed enhanced status code CVEs CVE-2026-43964 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM postfix-3.8.5-8.el10_0.1.src.rpm SHA-256: 659aaccf014cc78f5641b558e14bc239c1a1f85679a475be89af932cc2b856e0 x86_64 postfix-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: 96349e10d5a0478a19686ce6826263f35e179139044ee2964393eeaad6de26b2 postfix-cdb-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: b9fd23717ca73376d3b7b99585424b46ac3bffe19e4ab57bdf8afdf42a434fb8 postfix-cdb-debuginfo-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: 02b981274200a359f1955e7b2b982452700b65994219f71df40415fd7fcf8581 postfix-debuginfo-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: b24e7016949b229fcf35c013b1c9e615ba8ab0c67b1637aad6c139d38982ad1c postfix-debugsource-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: 352bb27caf2d64864b22874f77a10e8fcae5d28a7826e33e407db5441c79683f postfix-ldap-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: 49105ccedfe6f480c77d09951751111246ab4a79c7559ee0243642b1c127a8e0 postfix-ldap-debuginfo-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: 9bd554acc2b5389832e942e8e453a47a823c055fbbde5f427f663f38d7d5bd9f postfix-lmdb-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: bead958b5ee3bec41e0e76688e22f763d7b34e4b8f39330944103cac90236def postfix-lmdb-debuginfo-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: e6ac8efefb6946ea0fc818b549e327d24ae65feb67410a12ee80f7c1893ac94b postfix-mysql-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: b061b486ea6829f9ee513a0dfdea408b29a5bbbb553459ab02b0de28b3c3f6bc postfix-mysql-debuginfo-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: 71b380e5b0860c8c1ac2fb1439607e3d3b328276ff1a72eeef1c9ee1fd77f85c postfix-pcre-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: 56958b27b4eeafd36f7a07653a90e7a89f555f8ab8abe650f5fdad1022423e26 postfix-pcre-debuginfo-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: ebb030b0ad2bbe7e1ca279c7bea2d0feec86cdcf7254a2f4a8e2989dec841637 postfix-perl-scripts-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: 69ad722c9e3dfd191976ce0493555192e3bfc898fc5fe55b90362e48564da1f6 postfix-pgsql-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: 9debd1e97200acea0ac63e44429177a5e1865a71ac90cf8495fc6e1d6ca23235 postfix-pgsql-debuginfo-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: de235084a17b539dc53ef9152b1fa26f9f87ee6f1952ce0b3d7239b1924e8181 postfix-sqlite-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: 7977f9ee7ceacac596df4ab628ea555f3407619621f1d4cfa434d65ee7ae63d8 postfix-sqlite-debuginfo-3.8.5-8.el10_0.1.x86_64.rpm SHA-256: 241ba5233f801532904cf0a1c89cf48cf6612d63b12962634aa1d39a07ccbb1e Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 SRPM postfix-3.8.5-8.el10_0.1.src.rpm SHA-256: 659aaccf014cc78f5641b558e14bc239c1a1f85679a475be89af932cc2b856e0 s390x postfix-3.8.5-8.el10_0.1.s390x.rpm SHA-256: 4caa9d646693ef64c38345f1075dac1e6f802d67b87926deeb4d5e4bacf0ef85 postfix-cdb-3.8.5-8.el10_0.1.s390x.rpm SHA-256: 1c67235d2f7fddb8546e9b18feb0a06a504205ad2c95cf12b512238d94cac43e postfix-cdb-debuginfo-3.8.5-8.el10_0.1.s390x.rpm SHA-256: bb5b70e0c9a3d1accf73e403aaa515beb8fc022ac24d4b60f062e83dd13c7671 postfix-debuginfo-3.8.5-8.el10_0.1.s390x.rpm SHA-256: 3a5cc6c2b7b572c0c0cbc3ff548f74435649ce94b6d6c1cc6bd8583f82e3f5f0 postfix-debugsource-3.8.5-8.el10_0.1.s390x.rpm SHA-256: 87b7cfc5e50d16b3ce61dbe0febc01a0e7f8fc66e127191391b60a286167c82c postfix-ldap-3.8.5-8.el10_0.1.s390x.rpm SHA-256: a31adf369d263cb8b45dcffcbf337aec172bc2013db58028ca498d55bb419250 postfix-ldap-debuginfo-3.8.5-8.el10_0.1.s390x.rpm SHA-256: 50538cb3e1cb0467d03abbac9de7d4ab82f81839bfb54c793507f4f3967b299e postfix-lmdb-3.8.5-8.el10_0.1.s390x.rpm SHA-256: ab131fd3172eeafaff9abe22ee4c55c78d18394dab519d7fbca123de801e3722 postfix-lmdb-debuginfo-3.8.5-8.el10_0.1.s390x.rpm SHA-256: 08cffbfee6ebe42c5002e34f7ebefe02aee36802f85241841ef4d99f929900b0 postfix-mysql-3.8.5-8.el10_0.1.s390x.rpm SHA-256: 73a0fd6abb0baa2657d73a64e35442f54d1c1c40f73076f25a0e830d04421b9b postfix-mysql-debuginfo-3.8.5-8.el10_0.1.s390x.rpm SHA-256: bae69d2d7d2ca3e4befd4c1b0af48a830bc582f13bea279fa02bec033d9275df postfix-pcre-3.8.5-8.el10_0.1.s390x.rpm SHA-256: b5064eed23dc3ba1a743dd2c6b6e3086a78e25e5813b6b3a6aedfe12aa870f0d postfix-pcre-debuginfo-3.8.5-8.el10_0.1.s390x.rpm SHA-256: 37a76aacc20c274f843c670c918989d5a76231a06d65c621551260b7bd82124a postfix-perl-scripts-3.8.5-8.el10_0.1.s390x.rpm SHA-256: 03d454a9f1f7cabff318a9acd721ffa9029ad7211d2f3fb0b405510a7b5a09e3 postfix-pgsql-3.8.5-8.el10_0.1.s390x.rpm SHA-256: a6a2d3e312a2cda6481c020922229a49130cf81c410d7709b0bf67352df0cbdd postfix-pgsql-debuginfo-3.8.5-8.el10_0.1.s390x.rpm SHA-256: 4f1f78d2f64eb37d47433b83007e2bb47ad179a32cb81321fa0a5c8693c76de1 postfix-sqlite-3.8.5-8.el10_0.1.s390x.rpm SHA-256: 7d915214ab75938adaafc02e19318e4f120c87d1ffc230d37d897626799da079 postfix-sqlite-debuginfo-3.8.5-8.el10_0.1.s390x.rpm SHA-256: 2b8729dd2ce670a77197449fc1e43e523ac58cf06bca89cc0107ade97e5814dc Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM postfix-3.8.5-8.el10_0.1.src.rpm SHA-256: 659aaccf014cc78f5641b558e14bc239c1a1f85679a475be89af932cc2b856e0 ppc64le postfix-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: c51428c9158f01e7c46b8fef067550dc901a1114de8033a57f5e8d1e7390ca7e postfix-cdb-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: 495b65d70f225abe9448421acfed3d1dbe393c70fdb06cb2a3c16a786d82bd66 postfix-cdb-debuginfo-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: 8fa7a0ea4dd12eab53f34b23513f93847c389e8c5f6a05b3bc216d14f69b0c25 postfix-debuginfo-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: 953c115c08c45873b2ef8d966d662225a0c64c5a79dfe87aff60a00822dc1272 postfix-debugsource-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: c39286ece8f019cb564e6a10c612b06cff899e64456bc59e4b4ec70c2604b30b postfix-ldap-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: 9dd15cbf955a7f26ced42f551270cbe746702dc9e421ff5bb86b12368f3b4300 postfix-ldap-debuginfo-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: e2e25498470ef2789383305b8d291bebd11465c47b4d925d700ee0fcccaf81e5 postfix-lmdb-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: 32dcabfd3f699de30189e4e5311b328a2c0dbf1769c7de8eea3bb6258c5cd0fd postfix-lmdb-debuginfo-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: 14635eddc062cb1afbc869b18c8584326e90d6ad8683c7462c406f33fb3065f8 postfix-mysql-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: 91a7e9af8ab52ec48b88fee56f6570035a17e483094f693892357e6a516177a0 postfix-mysql-debuginfo-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: 3071adcca5069a5a59216642c08b65d175a2a19b7120fc35bd14729bc4cefaa4 postfix-pcre-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: d1e280967b5290bb086e144058e13eee1d3f596ce388661feaa80136139a9822 postfix-pcre-debuginfo-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: 31f4be1754fc3ae4e0f29e63a7fbb3247af96b352ca3397a1ab0632e95b23a2f postfix-perl-scripts-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: 50c568c703554ebc449d7d80fd7855f96857e167d966583f8511645d0df08292 postfix-pgsql-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: 5d5610094099479eed684783f50e6bcc871329ce0ddf8d68e86b74409fd6f353 postfix-pgsql-debuginfo-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: 96d96a0ae058289273bc1011883ba268612c1643898e8aa3a2424559040ce13e postfix-sqlite-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: 2665f6e83cf30118eb8ba31889e13f6c3953caec408377d2e5c4ba17093d73ca postfix-sqlite-debuginfo-3.8.5-8.el10_0.1.ppc64le.rpm SHA-256: c6fb5b8878a28ce48691af5ca57b82780a9f0562402e64e7d2d4aa20add5921c Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 SRPM postfix-3.8.5-8.el10_0.1.src.rpm SHA-256: 659aaccf014cc78f5641b558e14bc239c1a1f85679a475be89af932cc2b856e0 aarch64 postfix-3.8.5-8.el10_0.1.aarch64.rpm SHA-256: a8c9ba9774d631f4eaa1fd0e6d9cc6e7c9d89e3f6a2fa575d55776cc2cdbd02b postfix-cdb-3.8.5-8.el10_0.1.aarch64.rpm SHA-256: 9604b195dfd6594bf179b68f19028067a2a8ea14eadc515584a20265aaa6614a postfix-cdb-debuginfo-3.8.5-8.el10_0.1.aarch64.rpm SHA-256: 528be766312911a68b49973cf6a273f7f0c085662db7602781b6418a00f182ce postfix-debuginfo-3.8.5-8.el10_0.1.aarch64.rpm SHA-256: d1805097882e4ad7c23dca42e1637dbe97305e4bb7efdd6e36ab66b75cf1ffa1 postfix-debugsource-3.8.5-8.el10_0.1
This update addresses a buffer over-read vulnerability (CVE-2026-43964, CVSS 3.7 LOW) in Postfix, triggered by processing a malformed enhanced status code. The affected versions are Postfix 3.8.x before 3.8.16, 3.9.x before 3.9.10, and 3.10.x before 3.10.9. Red Hat has released patched packages for its Enterprise Linux 10.0 Extended Update Support repositories.