Postfix 3.11.6: The Audit That Dug Up 30 Years of Bugs

On August 10, 2026, Wietse Venema released Postfix 3.11.6, along with coordinated updates for six legacy branches: 3.10.13, 3.9.14, 3.8.20, 3.7.22, 3.6.20, and 3.5.27. If you run mail on Linux, you almost certainly run Postfix. You should update. The release is unusual for two reasons: the scope of what was found, and how it was found. How the bugs were discovered Qualys, working with Anthropic’s Claude Mythos Preview, and separately OpenAI Security, ran an AI-assisted audit of the Postfix codebase — over 150,000 lines of C accumulated across nearly three decades of single-developer maintenance. The results were, to put it charitably, humbling. More than half of the discovered defects date from 20 or more years ago. The oldest traces back to before Postfix’s first public alpha release in April 1997. ...

September 2, 2026 · 4 min

Postfix 3.11.2 Patches a 20-Year-Old Buffer Over-Read — and an AI Found Most of the Rest

On May 4, 2026, Wietse Venema released Postfix 3.11.2, 3.10.9, 3.9.10, and 3.8.16. If you run a mail server, this is the update you actually want to read — not because the CVSS score is alarming (it isn’t), but because one of the bugs patched in this release has been sitting in the codebase since 2005. The CVE Worth Knowing About CVE-2026-43964 is an off-by-one error in how Postfix handles enhanced status codes. If an SMTP access table, policy server, DNSBL response, or milter returns a bare status code — something like 5.7.2 without any text following it — the daemon reads past the end of the allocated buffer. The result is a process crash. ...

May 7, 2026 · 3 min