[pfx] Re: Postfix stable release 3.11.6 and legacy releases 3.10.13, 3.9.14, 3.8.20, 3.7.22, 3.6.20, 3.5.27

"Herbert J. Skuhra via Postfix-users" <[email protected]>
Newsgroups gmane.mail.postfix.user
Message-ID <[email protected]>
Hi!

On Mon, 10 Aug 2026 17:50:35 +0200, Wietse Venema via Postfix-users wrote:
> 
> [An on-line version of this announcement will be available at
> https://www.postfix.org/announcements/postfix-3.11.6.html]
> 
> This release addresses medium-impact problems that need to be fixed
> as some enable remote DOS or policy bypass.
> 
> The fixes below, and more, are also released in the unstable version
> postfix-3.12-20260809.
> 
> In addition to updated releases for the supported Postfix versions
> 3.8-3.11, releases will also be available for the out-of-support
> Postfix versions 3.5-3.7. NOTE: these do not include the patches
> for out-of-support Postfix versions that have been issued for "large
> SMTP inputs (June 2026)", "TLSA parsing (June 2026)", and "SMTP
> smuggling fixes". Those patches still need to be applied.
> 
> These defects were found by Qualys assisted by Claude Mythos Preview,
> and by OpenAI Security; more than half date from 20 or more years
> ago. When I implemented Postfix, I knew that there were going to
> be mistakes. That is the reason why Postfix has its architecture
> and safety nets. The number of defects may seem large, but considering
> that they were found in a code base of over 150 thousand lines, the
> error rate is still lower than what I designed for.
>
> [...]

Just FYI:
The Release Notes and PGP/GPG[12] signatures are "404 Not Found".

_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.