{"id":"SUSE-SU-2026:22185-1","summary":"Security update for dovecot24","details":"This update for dovecot24 fixes the following issues\n\n- CVE-2026-27851: lib-var-expand: safe filter leaks to all following pipelines (bsc#1265146).\n- CVE-2026-33603: login: base64 input can contain tabs that bypass IPC protection (bsc#1265147).\n- CVE-2026-40016: Sieve: contains/: matches O(NxM) substring match bypasses sieve_max_cpu_time limit (bsc#1265148).\n- CVE-2026-40020: IMAP folders can be shared-spammed to everyone (bsc#1265149).\n- CVE-2026-42006: imap-login: uncontrolled memory usage with excessive bracing over IMAP (bsc#1265150).\n\nChanges for dovecot24:\n\n- Update to 2.4.4\n","modified":"2026-06-24T18:24:23.823797864Z","published":"2026-06-19T17:04:26Z","related":["CVE-2026-27851","CVE-2026-33603","CVE-2026-40016","CVE-2026-40020","CVE-2026-42006"],"upstream":["CVE-2026-27851","CVE-2026-33603","CVE-2026-40016","CVE-2026-40020","CVE-2026-42006"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202622185-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265146"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265147"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265148"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265149"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265150"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27851"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33603"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40016"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40020"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42006"}],"affected":[{"package":{"name":"dovecot24","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/dovecot24&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.4-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"dovecot24-devel":"2.4.4-160000.1.1","dovecot24-fts":"2.4.4-160000.1.1","dovecot24-fts-solr":"2.4.4-160000.1.1","dovecot24":"2.4.4-160000.1.1","dovecot24-backend-mysql":"2.4.4-160000.1.1","dovecot24-backend-pgsql":"2.4.4-160000.1.1","dovecot24-backend-sqlite":"2.4.4-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22185-1.json"}},{"package":{"name":"dovecot24","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/dovecot24&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.4-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"dovecot24-fts-solr":"2.4.4-160000.1.1","dovecot24":"2.4.4-160000.1.1","dovecot24-backend-mysql":"2.4.4-160000.1.1","dovecot24-backend-pgsql":"2.4.4-160000.1.1","dovecot24-backend-sqlite":"2.4.4-160000.1.1","dovecot24-devel":"2.4.4-160000.1.1","dovecot24-fts":"2.4.4-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22185-1.json"}}],"schema_version":"1.7.5"}