Postfix stable release 3.11.7 and legacy releases 3.10.14, 3.9.15, 3.8.21, 3.7.23, 3.6.21, 3.5.28

[An on-line version of this announcement will be available at https://www.postfix.org/announcements/postfix-3.11.7.html]

This release addresses medium-impact problems that need to be fixed as some enable remote DOS or SMTP smugggling.

The fixes below, and more, are also released in the unstable version postfix-3.12-20260902.

In addition to updated releases for the supported Postfix versions 3.8-3.11, releases will also be available for the out-of-support Postfix versions 3.5-3.7. NOTE: these do not include the patches for out-of-support Postfix versions that have been issued for "large SMTP inputs (June 2026)", and for "TLSA parsing (June 2026)". Those patches still need to be applied.

These defects were found by "Qualys assisted by Claude Mythos Preview", and by "OpenAI Security"; three date from 20 or more years ago.

SMTP smuggling:

Server crashes and panic()s:

Other bugs

TLS

Configuration safety

Read after free, memory over-read

Code hardening (defense in depth, prevention)

Other:

You can find the updated Postfix source code on the mirrors listed at https://www.postfix.org/.