{
  "schema_version": "1.7.0",
  "id": "MGASA-2026-0385",
  "published": "2026-09-09T04:15:20Z",
  "modified": "2026-09-09T03:12:43Z",
  "summary": "Updated dovecot package fixes security vulnerabilities",
  "details": "submission-login: Panic when mail_max_userip_connections is reached:\nPanic: epoll_ctl(del, 8) failed: Bad file descriptor. (CVE-2026-33263)\nDovecot IMAP LIST match_sub() Exponential Backtracking — CPU Denial of\nService. (CVE-2026-33607)\nDoS by sending mail with bad header. (CVE-2026-27852)\ndsync: Mail content can cause dsync protocol injection. (CVE-2026-33606)\nSMTP Smuggling via Missing Dot-Stuffing After Bare Carriage Return.\n(CVE-2026-33604)\nIMAP THREAD REFERENCES O(N²) CPU DoS via Crafted References Header\n(index-thread-links.c). (CVE-2026-40014)\npigeonhole: Stack Buffer Underflow in Pigeonhole ManageSieve\nCHECKSCRIPT/PUTSCRIPT. (CVE-2026-40013)\nmanagesieve-login: Pre-auth crash. (CVE-2026-33605)\nMySQL multi-byte escaping wrong. (CVE-2026-40018)\nv2.4.3 regression: managesieve-login pre-auth infinite loop.\n(CVE-2026-40019)\nimap-hibernate can be crashed. (CVE-2026-40015)\nIMAP THREAD O(M³) CPU DoS via CRC32 Hash Collision in strmap\n(mail-index-strmap.c / hash2.c). (CVE-2026-40017)\nIMAP Compression Can Reveal Whether a Small Synced Email Body Matches\nSender-Chosen Text. (CVE-2026-40203)\nSieve editheader RCE. (CVE-2026-42007)\nacl: lda_mailbox_autocreate can bypass acl restrictions.\n(CVE-2026-40204)\nOAuth2 passdb scope enforcement bypass via OR semantics in remote\nvalidation path. (CVE-2026-40205)\nXCLIENT FORWARD= bare token not namespaced, allows nopassword injection\nvia trusted proxy. (CVE-2026-42008)\nSingle NUL-Byte XCLIENT FORWARD Payload Crashes. (CVE-2026-42395)\ndoveadm_password or api key length can still be leaked with timing\ncomparisons. (CVE-2026-42393)\nSieve resource usage tracking lost when active script changes.\n(CVE-2026-52681)\nimap-urlauth leaks memory into user-visible error messages.\n(CVE-2026-42392)\nauth: db-oauth2: aud claim used as fallback for missing scope claim.\n(CVE-2026-73208)\nimap-login crash: Self-recursion on zero-output decompress chunks.\n(CVE-2026-73209)\nimap: Pre-login memory/CPU growth with ID command. (CVE-2026-42391)\nIMAP: COMPRESS ZSTD can cause excessive memory usage. (CVE-2026-52687)\n",
  "upstream": [
    "CVE-2026-33263",
    "CVE-2026-33607",
    "CVE-2026-27852",
    "CVE-2026-33606",
    "CVE-2026-33604",
    "CVE-2026-40014",
    "CVE-2026-40013",
    "CVE-2026-33605",
    "CVE-2026-40018",
    "CVE-2026-40019",
    "CVE-2026-40015",
    "CVE-2026-40017",
    "CVE-2026-40203",
    "CVE-2026-42007",
    "CVE-2026-40204",
    "CVE-2026-40205",
    "CVE-2026-42008",
    "CVE-2026-42395",
    "CVE-2026-42393",
    "CVE-2026-52681",
    "CVE-2026-42392",
    "CVE-2026-73208",
    "CVE-2026-73209",
    "CVE-2026-42391",
    "CVE-2026-52687"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2026-0385.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=36219"
    },
    {
      "type": "WEB",
      "url": "https://www.openwall.com/lists/oss-security/2026/08/28/1"
    },
    {
      "type": "ADVISORY",
      "url": "https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "dovecot",
        "purl": "pkg:rpm/mageia/dovecot?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.4.5-2.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
