[Git][security-tracker-team/security-tracker][master] dovecot references
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 24 14:47:16 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1fb66696 by Moritz Muehlenhoff at 2026-09-24T15:46:46+02:00
dovecot references
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -32496,6 +32496,9 @@ CVE-2026-56854 (The source-address critical option in the Permissions returned b
CVE-2026-52687 (An attacker that has valid credentials can select a compression algori ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-52687-imap-compress-zstd-can-cause-excessive-memory-usage
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/65293cc0a6bc74f730b9ff036ec1e6456e671f88
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/e58c15ba1486a055462f7a2853a4b6a954e0eafa
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/b020b257c45d48c623db54909df4d3ae9b0975a1
CVE-2026-52681 (Sieve CPU resource usage is tracked in the compiled script, so an atta ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-52681-sieve-resource-usage-tracking-lost-when-active-script-changes
@@ -32517,6 +32520,8 @@ CVE-2026-42392 (An attacker that has valid credentials can send an invalid IMAP
CVE-2026-42391 (An unauthenticated attacker can send an IMAP ID command with a very la ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42391-imap-pre-login-memory-cpu-growth-with-id-command
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/277e5c880a7f6a7741e717036570812910fff7b7
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/78518c10c7aa1236c1ed1ebb2d558ce24e6bc122
CVE-2026-42008 (Forwarding information received from a host listed as a trusted proxy ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42008-xclient-forward-bare-token-not-namespaced-allows-nopassword-injection-via-trusted-proxy
@@ -32538,6 +32543,10 @@ CVE-2026-40205 (An attacker that holds an OAuth2 token granting only part of the
CVE-2026-40204 (None None None No publicly available exploits are known.)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40204-acl-lda-mailbox-autocreate-can-bypass-acl-restrictions
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/7f2fbf017c479af0363aa35b2cd2dca4b92e16d2
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/fbf82497a2a7423825c5b6066559b8870ec9fa2a
+ NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/f0dfa83a01194126d9a7688bcf30e730d5873b63
+ NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/c211355da2ecdd2d858204468b12bd5667a44e30
CVE-2026-40203 (When IMAP compression is enabled, the same compression state is reused ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40203-imap-compression-can-reveal-whether-a-small-synced-email-body-matches-sender-chosen-text
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fb66696767a1b5d9868a92f252eec55b8ae1955
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fb66696767a1b5d9868a92f252eec55b8ae1955
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/98484c09/attachment.htm>
More information about the debian-security-tracker-commits
mailing list