<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Smtp on kalfaoglu.net</title><link>https://blog.kalfaoglu.net/tags/smtp/</link><description>Recent content in Smtp on kalfaoglu.net</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 02 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.kalfaoglu.net/tags/smtp/index.xml" rel="self" type="application/rss+xml"/><item><title>Postfix 3.11.6: The Audit That Dug Up 30 Years of Bugs</title><link>https://blog.kalfaoglu.net/posts/2026-09-02-postfix-3116-security-audit-en/</link><pubDate>Wed, 02 Sep 2026 00:00:00 +0000</pubDate><guid>https://blog.kalfaoglu.net/posts/2026-09-02-postfix-3116-security-audit-en/</guid><description>&lt;p&gt;On August 10, 2026, Wietse Venema released &lt;a href="https://www.postfix.org/announcements/postfix-3.11.6.html"&gt;Postfix 3.11.6&lt;/a&gt;, along with coordinated updates for six legacy branches: 3.10.13, 3.9.14, 3.8.20, 3.7.22, 3.6.20, and 3.5.27. If you run mail on Linux, you almost certainly run Postfix. You should update.&lt;/p&gt;
&lt;p&gt;The release is unusual for two reasons: the scope of what was found, and how it was found.&lt;/p&gt;
&lt;h2 id="how-the-bugs-were-discovered"&gt;How the bugs were discovered&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://www.qualys.com/"&gt;Qualys&lt;/a&gt;, working with &lt;a href="https://www.anthropic.com/"&gt;Anthropic&amp;rsquo;s Claude Mythos Preview&lt;/a&gt;, and separately &lt;a href="https://openai.com/security/"&gt;OpenAI Security&lt;/a&gt;, ran an AI-assisted audit of the Postfix codebase — over 150,000 lines of C accumulated across nearly three decades of single-developer maintenance. The results were, to put it charitably, humbling. More than half of the discovered defects date from 20 or more years ago. The oldest traces back to before Postfix&amp;rsquo;s first public alpha release in April 1997.&lt;/p&gt;</description></item></channel></rss>