-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 10 Aug 2026 19:35:04 +0300
Source: postfix
Architecture: source
Version: 3.10.13-0+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Debian Postfix Team <team+postfix@tracker.debian.org>
Changed-By: Michael Tokarev <mjt@tls.msk.ru>
Changes:
postfix (3.10.13-0+deb13u1) trixie-security; urgency=medium
.
* new upstream stable/bugfix/security release
From the release announcement by Wietse Wenema at
https://www.postfix.org/announcements/postfix-3.11.6.html :
.
These defects were found by Qualys assisted by Claude Mythos Preview,
and by OpenAI Security; more than half date from 20 or more years ago.
When I implemented Postfix, I knew that there were going to be mistakes.
That is the reason why Postfix has its architecture and safety nets.
The number of defects may seem large, but considering that they were
found in a code base of over 150 thousand lines, the error rate
is still lower than what I designed for.
.
o Policy bypass:
.
- Bug (introduced: Postfix 2.2, date: 20041102): missing SMTP server
resets of MAIL FROM and RCPT TO command state after
smtpd_end_of_data_restrictions rejected a message. This resulted in
SMTP protocol state desynchronization between the remote SMTP client
and the Postfix SMTP server.
.
- A crafted remote SMTP client could then send RCPT TO and DATA without
MAIL FROM, and deliver a second message. Then,
smtpd_end_of_data_restrictions skipped check_recipient_access
constraints, because a recipient counter was > 1.
.
- The failure to reset MAIL FROM and RCPT TO state also affected Milter
support (added in Postfix 2.3). Here, after a Milter replied with
"accept this message" based on the message envelope, and
smtpd_end_of_data_restrictions rejected the message, the Postfix SMTP
server as before accepted RCPT TO and DATA without MAIL FROM, and
smtpd_end_of_data_restrictions as before skipped check_recipient_access
constraints for the second message. Under these conditions, the Postfix
Milter client remained in the "accept this message" state, skipping
Milter policy enforcement for the second message.
.
o Denial of service:
.
- Bug (defect introduced: Postfix 3.4, date: 20180805): SMTP server
command history memory exhaustion with a large number of very small
BDAT requests.
.
- Bug (defect introduced: Postfix 1.1, date: 20021116): address
verification cache poisoning. A local user could use the postdrop
command to submit an address verification probe with envelope or
message content that Postfix rejected later, resulting in a negative
address verification cache entry for that address. On systems that
enable address verification, the negative address verification cache
entry would force the Postfix SMTP server to reject a message that it
should accept (denial of service).
.
o Server crashes and panic()s:
.
- Bug (defect introduced: Postfix 3.4, date: 20180805): missing SMTP server
reset of RCPT TO state, after a BDAT command error. A crafted remote
SMTP client could then send a DATA command without MAIL FROM or RCPT TO,
and crash a Postfix SMTP daemon process with a null pointer read error.
.
- Bug (defect introduced: Postfix 2.4, date: 20051222): null pointer read
crash while parsing a malformed Dovecot AUTH server response.
.
o Read after free, uninitialized read, under/over read:
.
- Bug (defect introduced: Postfix 2.8, date: 20100914): read-after-free
in the PSC_CALL_BACK_NOTIFY() macro. This had no effect on program
execution, because myfree() wiped memory, and that memory was not yet
reused.
.
- Read after free (no privilege escalation) in debug logging (defect
introduced: Postfix 2.2, date: 20050117).
.
- Bug (defect introduced: Postfix 2.10, date: 20120617): uninitialized
memory read in postscreen HaProxy client after remote I/O exception,
causing garbage to be logged.
.
- Latent bug (defect introduced: Postfix 2.7, date: 20090618):
uninitialized memory read after dnsblog(8) returns a string
that is not an IPv4 address.
.
- Bug (defect introduced: before Postfix alpha, date 19970424): the DNS
client could read up to two bytes past the end of an MX record, before
discovering that the record was too short. This behavior was later
copied with SRV records, potentially over-reading up to six bytes.
.
- Bug (defect introduced: Postfix 1,1, date: 20010524): the postsuper
command under-read or over-read a very short queue filename. No crash,
information leak, or privilege escalation.
.
o Other code hygiene:
.
- Bug (defect introduced: before Postfix alpha, date: 19971106): 'int'
over-shift, in the queue file record-length parser. Postfix programs
do not generate such records, but an attacker could cause postdrop to
reject input or panic().
.
- Bug (defect introduced: Postfix 2.2, date: 20050117):
non-transitive comparison of IPv4 addresses.
.
- Bug (defect introduced: Postfix 1.0, date: 20000928): the fast
flush server, used by the SMTP command "ETRN", and by the commands
"postqueue -s site" and "postqueue -i queue_id" (and their sendmail(1)
equivalents), used the wrong duplicate suppression API, resulting in
unnecessary queue scans by the queue manager.
.
- Queue hygiene: the postdrop command accepted the null record type
which the rest of Postfix ignores.
Checksums-Sha1:
913e6f7ecc74b6642b2b4ec8a6eb3d68f3696f78 3203 postfix_3.10.13-0+deb13u1.dsc
f9d703bfa5118ef127d2d255122ad92e6151cd1b 5048920 postfix_3.10.13.orig.tar.gz
dc9a26c47559c611859ef50343c122572b5413db 220 postfix_3.10.13.orig.tar.gz.asc
e1d3a3a8f70e92bc5d15e1c323d0a4906acab0b8 204240 postfix_3.10.13-0+deb13u1.debian.tar.xz
414eeb49daee75254ec24e36082a42ecede522eb 5756 postfix_3.10.13-0+deb13u1_source.buildinfo
Checksums-Sha256:
5f1916822244e13900b6b86affb7475e010140cc501ff4681f786023b5d55d7c 3203 postfix_3.10.13-0+deb13u1.dsc
de6526fb11bbf20fcfa5aa4b67e88cc6b246cad614a9bcb4b006f457ba3788bc 5048920 postfix_3.10.13.orig.tar.gz
bf23e5117b5c6337e6aa9142c4b2b5a6e06220e68b023dd50d7ac42f0a3b359d 220 postfix_3.10.13.orig.tar.gz.asc
5d737f7d2590517fb0e9492e201875350558fbeaa9fb3e489b075e8278eba924 204240 postfix_3.10.13-0+deb13u1.debian.tar.xz
95144c307860a8a5777c4b25dd8f281bd4c04df9fe608d792dfd4b971610445a 5756 postfix_3.10.13-0+deb13u1_source.buildinfo
Files:
d26d3ab4123c4c753302e1da9095e0da 3203 mail optional postfix_3.10.13-0+deb13u1.dsc
1de1237bbccd164a192e6712ede4c1d4 5048920 mail optional postfix_3.10.13.orig.tar.gz
85998e79e87a8414ef5e4635594ed921 220 mail optional postfix_3.10.13.orig.tar.gz.asc
ac278e3281575916bf7748d08ff3ee1e 204240 mail optional postfix_3.10.13-0+deb13u1.debian.tar.xz
8651689376a4be347581afe7dd20a8be 5756 mail optional postfix_3.10.13-0+deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEZKoqtTHVaQM2a/75gqpKJDselHgFAmp5/ksACgkQgqpKJDse
lHhZKRAAhAkzckUho9OJyQJjE48RLa9+Z9XdVvt39gjUbYBFLxQJwZtgH/O16M2d
y5vIqmqDj/ceQGADyL0C/uKuRsOapQKPzLWqkWoVKfy3gHXVzdH68Og28OkTyd90
aoefZ5x6Y3JnJ/yOFONzgOYNhxxDLDPfEOdHOP0udD4YPr69q/hAgkhow9vK+OC6
LPUpo6lMLTXkfjL29ww9SIYE57G7vH8PfVdbZRcL2FIv/12bTenUZDeMN6OhyQtV
3+jPf9Bvcu0WI9QekhrjuUXnfOueKW5Si1GamiymEIaLiCH+0wtat4xH9UAGp2zx
bXUgvDO94SvGpG7SCj4Mfv1FDhZCyy1MYBeUSsk42Tj7i8Zd/Rwe8vq6Xqdmc4KY
lepZlT8+gPVrU86o5HoARh8VSwODoSi2AHeTT30dsbI2f5wkItnyTfTv3vX++P7r
xXDB++0Dcn6iDDik9ohhclqq1O+jQjl8S0b7iFkFD6W+h5hZaihBVFN9D4u4eYkZ
yhc2psDq/Attv7rytOG5JHpdhI0bLiF/zpPjqeImpvtvAHX6AedUG5t+lYGBVAf7
DlTOikixYpmopzt56LZmgOkPA6WaI7vDpPnwme1RuQ8c68OEHqDmIkPdhMX6nAan
zm/tWgTyc66/d8VrcAaPmo5f/awqENTfvnsNlXvhfuLQITZNT6k=
=dk0x
-----END PGP SIGNATURE-----