[Git][security-tracker-team/security-tracker][master] dovecot commit references

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 24 08:52:48 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e4a3371b by Moritz Muehlenhoff at 2026-09-24T09:52:28+02:00
dovecot commit references

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -32490,9 +32490,15 @@ CVE-2026-33606 (Mail content stored by a user can be crafted so that it is inter
 CVE-2026-33605 (An unauthenticated attacker can crash the ManageSieve login process by ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33605-managesieve-login-pre-auth-crash
+	NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/14c28ca9c4aab11b1074c629bb744c4741434148
+	NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/77bf1049ab8652b125e02ed00a15e1dd2e1feb98
 CVE-2026-33604 (An attacker that can get Dovecot to relay a message, for example throu ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33604-smtp-smuggling-via-missing-dot-stuffing-after-bare-carriage-return
+	NOTE: Incomplete list of patches, not all landed in git yet
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/e94a6c3cb984f9d1e5fe51714ea5015205d79fd1
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/4677492d038f5187363790b5a93bd5fccc989a98
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/8f04979a7e72d3b3e04f3a93bd8088f5e2332dd9
 CVE-2026-33263 (When mail_max_userip_connections is set (default 10) and reached, subm ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33263-submission-login-panic-when-mail-max-userip-connections-is-reached-panic-epoll-ctl-del-8-failed-bad-file-descriptor



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4a3371befb5e033d4c34c1a0c720c3f4f41dc83

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4a3371befb5e033d4c34c1a0c720c3f4f41dc83
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/5a7501dd/attachment.htm>


More information about the debian-security-tracker-commits mailing list