freenode
Security & Cryptography

Postfix 3.11.7 closes SMTP smuggling and remote crash flaws

Stable and legacy releases fix medium-impact defects, some decades old, reported by Qualys and OpenAI Security.

Postfix has shipped 3.11.7 and matching updates across supported and legacy branches to close medium-impact flaws that can enable SMTP smuggling or remote denial of service.

The problems were found by Qualys (assisted by Claude Mythos Preview) and by OpenAI Security. Several date back twenty years or more. Fixes also land in the unstable 3.12 snapshots.

SMTP smuggling remained possible when the optional proxy filter was enabled under default bare-newline handling, and again in 3.11 when a Require-TLS header was injected before the filter. Both paths are closed; stray carriage returns are now stripped from the proxy input stream. The same releases address remote crash bugs and related hardening.

Builds cover supported versions 3.8 through 3.11, with packages also offered for out-of-support 3.5 through 3.7. Those older lines still need the earlier large SMTP input and TLSA parsing patches applied separately. Wietse Venema wrote the fixes.