| Message ID | 20260813133942.2669472-10-adolf.belka@ipfire.org |
|---|---|
| State | Staged |
| Commit | 0381b339dc9da6df7e47930afd91b33839914843 |
| Headers |
Return-Path: <development+bounces-2534-patchwork=ipfire.org@lists.ipfire.org> Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4hLRTr2KW3z3wqM for <patchwork@web04.haj.ipfire.org>; Thu, 13 Aug 2026 13:46:24 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [172.28.1.201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "YE1" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4hLRTh0nfsz7N2 for <patchwork@ipfire.org>; Thu, 13 Aug 2026 13:46:16 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4hLRMp2ND3z37Lp for <patchwork@ipfire.org>; Thu, 13 Aug 2026 13:41:10 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4hLRMl4VYDz2xMg for <development@lists.ipfire.org>; Thu, 13 Aug 2026 13:41:07 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4hLRMb3CL5z39m; Thu, 13 Aug 2026 13:40:59 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1786628459; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=f4RG7T3lv+SDeCNtMqy3VRvZ+z8O48UEl/d1tgOoie8=; b=5u4aEHSAILh1N+teMhnU53gTE3OCut1l6wNEkDlwy7dzNQATZLrjBq7827tno1Hn8Xbbs8 Gk2nt2nOQWorYrDQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1786628459; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=f4RG7T3lv+SDeCNtMqy3VRvZ+z8O48UEl/d1tgOoie8=; b=KKZfOv9Sy7idZUQrX0in6u2pII/tnOp5fzitlWpRfrXB9Q1KYmfqNBle2gDci6o0+aeAYq C5GUCknz1i4sDiYFXQgaazozCy7f/7Vo1P8XSclfYHaeBu4VhwHrty30o+UQ2fmJJcjkqV /Plwn4uiTwerpBYN1qxiuVizIG2Q2pJoJcQv/akRmq62yKtKK/rfFJR193SNytX7gnvuvA h52WExUlr1f0MG75MUKI34be4L7xvMO7BIT1ocsHsEDM4gyzrqjE6dmMSJVZOL1B/hyFtb Et/DqfsbjUqHOVRnnb7jwZ3Wy38uiO7uHXRF4m0CTvWHJZ/tvbhu8Z3JduudZQ== From: Adolf Belka <adolf.belka@ipfire.org> To: development@lists.ipfire.org Cc: Adolf Belka <adolf.belka@ipfire.org> Subject: [PATCH] postfix: Update to version 3.11.6 Date: Thu, 13 Aug 2026 15:39:39 +0200 Message-ID: <20260813133942.2669472-10-adolf.belka@ipfire.org> In-Reply-To: <20260813133942.2669472-1-adolf.belka@ipfire.org> References: <20260813133942.2669472-1-adolf.belka@ipfire.org> Precedence: list List-Id: <development.lists.ipfire.org> List-Subscribe: <https://lists.ipfire.org/>, <mailto:development+subscribe@lists.ipfire.org?subject=subscribe> List-Unsubscribe: <https://lists.ipfire.org/>, <mailto:development+unsubscribe@lists.ipfire.org?subject=unsubscribe> List-Post: <mailto:development@lists.ipfire.org> List-Help: <mailto:development+help@lists.ipfire.org?subject=help> Sender: <development@lists.ipfire.org> Mail-Followup-To: <development@lists.ipfire.org> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit |
| Series |
postfix: Update to version 3.11.6
|
|
Commit Message
Adolf Belka
13 Aug 2026, 1:39 p.m. UTC
- Update from version 3.11.5 to 3.11.6
- No change in rootfile
- Changelog
3.11.6
These defects were found by Qualys assisted by Claude Mythos Preview, and by OpenAI
Security; more than half date from 20 or more years ago. When I implemented Postfix,
I knew that there were going to be mistakes. That is the reason why Postfix has its
architecture and safety nets. The number of defects may seem large, but considering
that they were found in a code base of over 150 thousand lines, the error rate is
still lower than what I designed for.
Policy bypass:
Bug (introduced: Postfix 2.2, date: 20041102): missing SMTP server resets of
MAIL FROM and RCPT TO command state after smtpd_end_of_data_restrictions
rejected a message. This resulted in SMTP protocol state desynchronization
between the remote SMTP client and the Postfix SMTP server.
A crafted remote SMTP client could then send RCPT TO and DATA without MAIL FROM,
and deliver a second message. Then, smtpd_end_of_data_restrictions skipped
check_recipient_access constraints, because a recipient counter was > 1.
Reported by OpenAI Security. File: smtpd/smtpd.c.
As reported by OpenAI Security, the failure to reset MAIL FROM and RCPT TO state
also affected Milter support (added in Postfix 2.3). Here, after a Milter
replied with "accept this message" based on the message envelope, and
smtpd_end_of_data_restrictions rejected the message, the Postfix SMTP server
as before accepted RCPT TO and DATA without MAIL FROM, and
smtpd_end_of_data_restrictions as before skipped check_recipient_access
constraints for the second message. Under these conditions, the Postfix
Milter client remained in the "accept this message" state, skipping Milter
policy enforcement for the second message.
Denial of service:
Bug (defect introduced: Postfix 3.4, date: 20180805): SMTP server command
history memory exhaustion with a large number of very small BDAT requests.
Reported by OpenAI security. File: smtpd.c.
Bug (defect introduced: Postfix 1.1, date: 20021116): address verification cache
poisoning. A local user could use the postdrop command to submit an address
verification probe with envelope or message content that Postfix rejected
later, resulting in a negative address verification cache entry for that
address. On systems that enable address verification, the negative address
verification cache entry would force the Postfix SMTP server to reject a
message that it should accept (denial of service). Problem reported by
OpenAI Security. File: postdrop.c.
Server crashes and panic()s:
Bug (defect introduced: Postfix 3.4, date: 20180805): missing SMTP server reset
of RCPT TO state, after a BDAT command error. A crafted remote SMTP client
could then send a DATA command without MAIL FROM or RCPT TO, and crash a
Postfix SMTP daemon process with a null pointer read error. Reported by
OpenAI Security. File: smtpd/smtpd.c.
Bug (defect introduced: Postfix 2.4, date: 20051222): null pointer read crash
while parsing a malformed Dovecot AUTH server response. Reported by Qualys,
assisted by Claude Mythos Preview. File: xsasl_dovecot_server.c.
Read after free, uninitialized read, under/over read:
Bug (defect introduced: Postfix 2.8, date: 20100914): read-after-free in the
PSC_CALL_BACK_NOTIFY() macro. This had no effect on program execution,
because myfree() wiped memory, and that memory was not yet reused. Problem
reported by Qualys, assisted by Claude Mythos Preview. File: postscreen_dnsbl.c.
Read after free (no privilege escalation) in debug logging (defect introduced:
Postfix 2.2, date: 20050117). Reported by Qualys, assisted by Claude Mythos
Preview. File: util/inet_connect.c.
Bug (defect introduced: Postfix 2.10, date: 20120617): uninitialized memory read
in postscreen HaProxy client after remote I/O exception, causing garbage to
be logged. Reported by Qualys, assisted by Claude Mythos Preview.
File: postscreen_haproxy.c.
Latent bug (defect introduced: Postfix 2.7, date: 20090618): uninitialized memory
read after dnsblog(8) returns a string that is not an IPv4 address. Reported
by Qualys, assisted by Claude Mythos Preview. File: postscreen_dnsbl.c.
Bug (defect introduced: before Postfix alpha, date 19970424): the DNS client
could read up to two bytes past the end of an MX record, before discovering
that the record was too short. This behavior was later copied with SRV
records, potentially over-reading up to six bytes. Problem reported by
Qualys, assisted by Claude Mythos Preview. File: dns_lookup.c.
Bug (defect introduced: Postfix 1,1, date: 20010524): the postsuper command
under-read or over-read a very short queue filename. No crash, information
leak, or privilege escalation. Reported by Qualys, assisted by Claude Mythos
Preview. Files: postsuper.c, mail_queue.h.
Other code hygiene:
Bug (defect introduced: before Postfix alpha, date: 19971106): 'int' over-shift,
in the queue file record-length parser. Postfix programs do not generate such
records, but an attacker could cause postdrop to reject input or panic().
Reported by Qualys, assisted by Claude Mythos Preview. File: record.c.
Bug (defect introduced: Postfix 2.2, date: 20050117): non-transitive comparison
of IPv4 addresses. Reported by Qualys, assisted by Claude Mythos Preview.
File: sock_addr.c.
Bug (defect introduced: Postfix 1.0, date: 20000928): the fast flush server, used
by the SMTP command "ETRN", and by the commands "postqueue -s site" and
"postqueue -i queue_id" (and their sendmail(1) equivalents), used the wrong
duplicate suppression API, resulting in unnecessary queue scans by the queue
manager. Reported by Qualys, assisted by Claude Mythos Preview. File: flush.c.
Queue hygiene: the postdrop command accepted the null record type which the rest
of Postfix ignores. Reported by OpenAI Security. File: postdrop.c.
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
lfs/postfix | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/lfs/postfix b/lfs/postfix index 9584412ad..4ab686707 100644 --- a/lfs/postfix +++ b/lfs/postfix @@ -26,7 +26,7 @@ include Config SUMMARY = A fast, secure, and flexible mailer -VER = 3.11.5 +VER = 3.11.6 THISAPP = postfix-$(VER) DL_FILE = $(THISAPP).tar.gz @@ -34,7 +34,7 @@ DL_FROM = $(URL_IPFIRE) DIR_APP = $(DIR_SRC)/$(THISAPP) TARGET = $(DIR_INFO)/$(THISAPP) PROG = postfix -PAK_VER = 55 +PAK_VER = 56 DEPS = @@ -72,7 +72,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = c677014019ce0851e45b103e5d6a88972a10cd3685d4c68b47f6b94ee318b9e81fb017f5b15f4307f3b8c6719afcbba33f4fc1c31a4fb65fe040522d6af38704 +$(DL_FILE)_BLAKE2 = e4a1194fa3f718212413bcee4f61f3c7fe3bd6b0bc6e96a714ca4093e3827350c2eda0e68c5826d865fc9c657e6bcebb0724b99c282c7a85dd877f2207de5075 install : $(TARGET)