{"id":"MGASA-2026-0385","summary":"Updated dovecot package fixes security vulnerabilities","details":"submission-login: Panic when mail_max_userip_connections is reached:\nPanic: epoll_ctl(del, 8) failed: Bad file descriptor. (CVE-2026-33263)\nDovecot IMAP LIST match_sub() Exponential Backtracking — CPU Denial of\nService. (CVE-2026-33607)\nDoS by sending mail with bad header. (CVE-2026-27852)\ndsync: Mail content can cause dsync protocol injection. (CVE-2026-33606)\nSMTP Smuggling via Missing Dot-Stuffing After Bare Carriage Return.\n(CVE-2026-33604)\nIMAP THREAD REFERENCES O(N²) CPU DoS via Crafted References Header\n(index-thread-links.c). (CVE-2026-40014)\npigeonhole: Stack Buffer Underflow in Pigeonhole ManageSieve\nCHECKSCRIPT/PUTSCRIPT. (CVE-2026-40013)\nmanagesieve-login: Pre-auth crash. (CVE-2026-33605)\nMySQL multi-byte escaping wrong. (CVE-2026-40018)\nv2.4.3 regression: managesieve-login pre-auth infinite loop.\n(CVE-2026-40019)\nimap-hibernate can be crashed. (CVE-2026-40015)\nIMAP THREAD O(M³) CPU DoS via CRC32 Hash Collision in strmap\n(mail-index-strmap.c / hash2.c). (CVE-2026-40017)\nIMAP Compression Can Reveal Whether a Small Synced Email Body Matches\nSender-Chosen Text. (CVE-2026-40203)\nSieve editheader RCE. (CVE-2026-42007)\nacl: lda_mailbox_autocreate can bypass acl restrictions.\n(CVE-2026-40204)\nOAuth2 passdb scope enforcement bypass via OR semantics in remote\nvalidation path. (CVE-2026-40205)\nXCLIENT FORWARD= bare token not namespaced, allows nopassword injection\nvia trusted proxy. (CVE-2026-42008)\nSingle NUL-Byte XCLIENT FORWARD Payload Crashes. (CVE-2026-42395)\ndoveadm_password or api key length can still be leaked with timing\ncomparisons. (CVE-2026-42393)\nSieve resource usage tracking lost when active script changes.\n(CVE-2026-52681)\nimap-urlauth leaks memory into user-visible error messages.\n(CVE-2026-42392)\nauth: db-oauth2: aud claim used as fallback for missing scope claim.\n(CVE-2026-73208)\nimap-login crash: Self-recursion on zero-output decompress chunks.\n(CVE-2026-73209)\nimap: Pre-login memory/CPU growth with ID command. (CVE-2026-42391)\nIMAP: COMPRESS ZSTD can cause excessive memory usage. (CVE-2026-52687)\n","modified":"2026-09-09T04:42:28.305980613Z","published":"2026-09-09T04:15:20Z","upstream":["CVE-2026-27852","CVE-2026-33263","CVE-2026-33604","CVE-2026-33605","CVE-2026-33606","CVE-2026-33607","CVE-2026-40013","CVE-2026-40014","CVE-2026-40015","CVE-2026-40017","CVE-2026-40018","CVE-2026-40019","CVE-2026-40203","CVE-2026-40204","CVE-2026-40205","CVE-2026-42007","CVE-2026-42008","CVE-2026-42391","CVE-2026-42392","CVE-2026-42393","CVE-2026-42395","CVE-2026-52681","CVE-2026-52687","CVE-2026-73208","CVE-2026-73209"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0385.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=36219"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/08/28/1"},{"type":"ADVISORY","url":"https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html"}],"affected":[{"package":{"name":"dovecot","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/dovecot?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.5-2.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0385.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}