Advisories » MGASA-2026-0385

Updated dovecot package fixes security vulnerabilities

Publication date: 09 Sep 2026
Modification date: 09 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-33263 , CVE-2026-33607 , CVE-2026-27852 , CVE-2026-33606 , CVE-2026-33604 , CVE-2026-40014 , CVE-2026-40013 , CVE-2026-33605 , CVE-2026-40018 , CVE-2026-40019 , CVE-2026-40015 , CVE-2026-40017 , CVE-2026-40203 , CVE-2026-42007 , CVE-2026-40204 , CVE-2026-40205 , CVE-2026-42008 , CVE-2026-42395 , CVE-2026-42393 , CVE-2026-52681 , CVE-2026-42392 , CVE-2026-73208 , CVE-2026-73209 , CVE-2026-42391 , CVE-2026-52687

Description

submission-login: Panic when mail_max_userip_connections is reached:
Panic: epoll_ctl(del, 8) failed: Bad file descriptor. (CVE-2026-33263)
Dovecot IMAP LIST match_sub() Exponential Backtracking — CPU Denial of
Service. (CVE-2026-33607)
DoS by sending mail with bad header. (CVE-2026-27852)
dsync: Mail content can cause dsync protocol injection. (CVE-2026-33606)
SMTP Smuggling via Missing Dot-Stuffing After Bare Carriage Return.
(CVE-2026-33604)
IMAP THREAD REFERENCES O(N²) CPU DoS via Crafted References Header
(index-thread-links.c). (CVE-2026-40014)
pigeonhole: Stack Buffer Underflow in Pigeonhole ManageSieve
CHECKSCRIPT/PUTSCRIPT. (CVE-2026-40013)
managesieve-login: Pre-auth crash. (CVE-2026-33605)
MySQL multi-byte escaping wrong. (CVE-2026-40018)
v2.4.3 regression: managesieve-login pre-auth infinite loop.
(CVE-2026-40019)
imap-hibernate can be crashed. (CVE-2026-40015)
IMAP THREAD O(M³) CPU DoS via CRC32 Hash Collision in strmap
(mail-index-strmap.c / hash2.c). (CVE-2026-40017)
IMAP Compression Can Reveal Whether a Small Synced Email Body Matches
Sender-Chosen Text. (CVE-2026-40203)
Sieve editheader RCE. (CVE-2026-42007)
acl: lda_mailbox_autocreate can bypass acl restrictions.
(CVE-2026-40204)
OAuth2 passdb scope enforcement bypass via OR semantics in remote
validation path. (CVE-2026-40205)
XCLIENT FORWARD= bare token not namespaced, allows nopassword injection
via trusted proxy. (CVE-2026-42008)
Single NUL-Byte XCLIENT FORWARD Payload Crashes. (CVE-2026-42395)
doveadm_password or api key length can still be leaked with timing
comparisons. (CVE-2026-42393)
Sieve resource usage tracking lost when active script changes.
(CVE-2026-52681)
imap-urlauth leaks memory into user-visible error messages.
(CVE-2026-42392)
auth: db-oauth2: aud claim used as fallback for missing scope claim.
(CVE-2026-73208)
imap-login crash: Self-recursion on zero-output decompress chunks.
(CVE-2026-73209)
imap: Pre-login memory/CPU growth with ID command. (CVE-2026-42391)
IMAP: COMPRESS ZSTD can cause excessive memory usage. (CVE-2026-52687)
                

References

SRPMS

10/core