[Git][security-tracker-team/security-tracker][master] dovecot references

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 24 14:47:16 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1fb66696 by Moritz Muehlenhoff at 2026-09-24T15:46:46+02:00
dovecot references

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -32496,6 +32496,9 @@ CVE-2026-56854 (The source-address critical option in the Permissions returned b
 CVE-2026-52687 (An attacker that has valid credentials can select a compression algori ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-52687-imap-compress-zstd-can-cause-excessive-memory-usage
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/65293cc0a6bc74f730b9ff036ec1e6456e671f88
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/e58c15ba1486a055462f7a2853a4b6a954e0eafa
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/b020b257c45d48c623db54909df4d3ae9b0975a1
 CVE-2026-52681 (Sieve CPU resource usage is tracked in the compiled script, so an atta ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-52681-sieve-resource-usage-tracking-lost-when-active-script-changes
@@ -32517,6 +32520,8 @@ CVE-2026-42392 (An attacker that has valid credentials can send an invalid IMAP
 CVE-2026-42391 (An unauthenticated attacker can send an IMAP ID command with a very la ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42391-imap-pre-login-memory-cpu-growth-with-id-command
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/277e5c880a7f6a7741e717036570812910fff7b7
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/78518c10c7aa1236c1ed1ebb2d558ce24e6bc122
 CVE-2026-42008 (Forwarding information received from a host listed as a trusted proxy  ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42008-xclient-forward-bare-token-not-namespaced-allows-nopassword-injection-via-trusted-proxy
@@ -32538,6 +32543,10 @@ CVE-2026-40205 (An attacker that holds an OAuth2 token granting only part of the
 CVE-2026-40204 (None None None No publicly available exploits are known.)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40204-acl-lda-mailbox-autocreate-can-bypass-acl-restrictions
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/7f2fbf017c479af0363aa35b2cd2dca4b92e16d2
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/fbf82497a2a7423825c5b6066559b8870ec9fa2a
+	NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/f0dfa83a01194126d9a7688bcf30e730d5873b63
+	NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/c211355da2ecdd2d858204468b12bd5667a44e30
 CVE-2026-40203 (When IMAP compression is enabled, the same compression state is reused ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40203-imap-compression-can-reveal-whether-a-small-synced-email-body-matches-sender-chosen-text



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fb66696767a1b5d9868a92f252eec55b8ae1955

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fb66696767a1b5d9868a92f252eec55b8ae1955
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/98484c09/attachment.htm>


More information about the debian-security-tracker-commits mailing list