[Git][security-tracker-team/security-tracker][master] dovecot commit references

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 24 22:38:39 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3b5cedea by Moritz Muehlenhoff at 2026-09-24T23:37:48+02:00
dovecot commit references

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -33854,6 +33854,8 @@ CVE-2026-40203 (When IMAP compression is enabled, the same compression state is
 	NOTE: Fixed by: https://github.com/dovecot/core/commit/dd2cd9fec90267ed9b34e93a46a26b36fbbb457f
 CVE-2026-40019 (An unauthenticated attacker can send a truncated quoted argument to th ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
+	[trixie] - dovecot <not-affected> (Vulnerable code not present, introduced in 2.4.3)
+	[bookworm] - dovecot <not-affected> (Vulnerable code not present, introduced in 2.4.3)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40019-v2-4-3-regression-managesieve-login-pre-auth-infinite-loop
 CVE-2026-40018 (None None None No publicly available exploits are known.)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
@@ -33930,6 +33932,15 @@ CVE-2026-33606 (Mail content stored by a user can be crafted so that it is inter
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33606-dsync-mail-content-can-cause-dsync-protocol-injection
 	NOTE: Fixed by: https://github.com/dovecot/core/commit/bd707cab9decd4a069c9cdfd3e28d28cf9346fdd
 	NOTE: Fixed by: https://github.com/dovecot/core/commit/7d782e5f5e51f63483393a460594d6a8f920b6d6
+CVE-2026-42394 [sieve: symlink traversal flaw could result in arbitrary file disclosure]
+	- dovecot 1:2.4.5+dfsg1-1
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/3b3e091effb83e0810ca55123bb5ebbe8ccbd7f5
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/70473a5e603863f7e862e939f4e5daea54cd4e45
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/2af14ac44f31978b0fdea83b46c9154a3773f838
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/9e0abbe2ee3bd93a3f8d6cdfdc11f16b6fe4a49d
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/84b3bb795768cd76d2af9bc5fc749bc87192da68
+	NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/11599c24512eca1605f05c07f6d4ed967f5859e7
+	NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/34edf6f49441be91b389050ac38943e17c12c2c8
 CVE-2026-33605 (An unauthenticated attacker can crash the ManageSieve login process by ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33605-managesieve-login-pre-auth-crash
@@ -33948,6 +33959,15 @@ CVE-2026-33604 (An attacker that can get Dovecot to relay a message, for example
 CVE-2026-33263 (When mail_max_userip_connections is set (default 10) and reached, subm ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-33263-submission-login-panic-when-mail-max-userip-connections-is-reached-panic-epoll-ctl-del-8-failed-bad-file-descriptor
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/ff8d8059d7ba85375c6dc723fc1b7743114fbba4
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/3e1959d6820207393c7059944333102d4897ef83
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/d4e13a3773db97a1ce6f4545d43c64ef0780672c
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/4d016e968857437ca1a6aa804c473e06079539f2
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/db0835c84bf754a260ce0d3dca1d69eb90f87518
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/a16f235aafb557eab10a653c4689d43e51fedcac
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/5fde53de4ebdf791a5fe583d4f8e52b89215bc7c
+	NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/33f5a95c0448e0d104f2cd7591e7f42c19b33199
+	NOTE: Fixed by: https://github.com/dovecot/pigeonhole/commit/25e1e0adfa4ad44e3205fc8c62ca26a73cf6ee41
 CVE-2026-27852 (An attacker that can send mail to a user can craft a message whose hea ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-27852-dos-by-sending-mail-with-bad-header



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3b5cedea20f94e4a7dbe2cd4be8c9086efb8e3fb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3b5cedea20f94e4a7dbe2cd4be8c9086efb8e3fb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/3c2b282f/attachment.htm>


More information about the debian-security-tracker-commits mailing list