[Git][security-tracker-team/security-tracker][master] first batch of dovecot commit references

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Sep 23 22:55:28 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b11a4b99 by Moritz Muehlenhoff at 2026-09-23T23:54:57+02:00
first batch of dovecot commit references

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -31603,6 +31603,20 @@ CVE-2026-33263 (When mail_max_userip_connections is set (default 10) and reached
 CVE-2026-27852 (An attacker that can send mail to a user can craft a message whose hea ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-27852-dos-by-sending-mail-with-bad-header
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/035fbfa155288ac037965e0e4700eb198ccbf39a (2.4.3)
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/4380d7c5293760c0473566a227c63f3f91304f90
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/8f0089e5a811d7ee46eff17e2a46de7e004a74f4
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/ec0294808ea6443690044132c5f309ed0272cc06
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/977de721d6fcac09ab254958253856abcc0393c1
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/f27b7ae04f88f662c5f2bdd256ee9bef86d4c937
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/00daee1af18d929b3fcd14aa52840e38fe929711
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/41c4a77d2830a70616273962c720b7e2a9041efa
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/a81dd72a884a4f3e6b2859e9dd4fbada8c3900fe
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/84e6d207c83e9c1ed1d533d591475d9da2d6b55b
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/4b7e869b4b8fb70e0c32e4106aebc31a07b9f75b
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/c853685f820157046136bd027861cb2a21c13fbc
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/32010a7067a7970d302981c888f1e10904184499
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/1fa4c5a3fe21ca1994e54022050d23e260416c3c
 CVE-2026-19423 (The Ultimate Member  WordPress plugin before 2.13.0 does not validate  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19412 (This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to th ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -32,7 +32,7 @@ containerd
 --
 cups
 --
-dovecot
+dovecot (jmm)
 --
 dulwich
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b11a4b99c03b9cceb0e3c47378cf96991afe047a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b11a4b99c03b9cceb0e3c47378cf96991afe047a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/2c1d889f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list