Postfix 3.11.7 Security Update: AI-Discovered Bugs Spanning 27 Years

Published by

Postfix has released version 3.11.7 to address medium-severity security vulnerabilities, including SMTP smuggling and memory corruption bugs, some dating back 27 years. These vulnerabilities were identified using AI tools by OpenAI Security and Qualys, highlighting the effectiveness of modern technology in uncovering long-standing issues within legacy code. The update is particularly critical for those using smtpd_proxy_filter or Oracle MySQL 8, and administrators are urged to apply the patches promptly to mitigate risks, especially concerning remote denial-of-service attacks. Additionally, the release includes various hardening changes to improve overall security, emphasizing the importance of regular updates and audits, even for background services like Postfix



Postfix 3.11.7 Security Update: AI-Discovered Bugs Spanning 27 Years

Postfix has released version 3.11.7, addressing medium-severity security flaws including two distinct SMTP smuggling vectors and critical memory corruption bugs. The vulnerabilities were independently uncovered by OpenAI Security and Qualys using Anthropic's Claude, surfacing defects that have lingered in the codebase for up to 27 years. While the patches are especially important for administrators running smtpd_proxy_filter or Oracle MySQL 8, legacy branches 3.5 through 3.7 will require separate application of earlier June 2026 advisories. Organizations relying on Postfix should update immediately to close remote denial-of-service and data interception risks.

Postfix 3.11.7 Security Update: AI-Discovered Bugs Spanning 27 Years @ Linux Compatible