{"id":"SUSE-SU-2026:4139-1","summary":"Security update for dovecot23","details":"This update for dovecot23 fixes the following issues:\n\n- CVE-2024-23184: parsing of messages containing many address headers (From, To, Cc, Bcc, etc.) could be excessively CPU\n  intensive (bsc#1229184).\n- CVE-2024-23185: large headers can cause resource exhaustion when parsing message (bsc#1229183).\n- CVE-2025-59028: Invalid base64 authentication can cause DoS for other logins (bsc#1260894).\n- CVE-2025-59031: decode2text.sh OOXML extraction may follow symlinks and read unintended files during indexing\n  (bsc#1260895).\n- CVE-2025-59032: pigeonhole: ManageSieve panic occurs with sieve-connect as a client (bsc#1260902).\n- CVE-2026-27852: DoS by sending mail with bad header (bsc#1276799).\n- CVE-2026-27855: OTP driver vulnerable to replay attack (bsc#1260900).\n- CVE-2026-27856: Doveadm credentials were not checked using timing-safe checking function (bsc#1260899).\n- CVE-2026-27857: sending excessive parenthesis causes imap-login to use excessive memory (bsc#1260898).\n- CVE-2026-27858: pigeonhole: managesieve-login can allocate large amount of memory during authentication (bsc#1260901).\n- CVE-2026-27859: excessive RFC 2231 MIME parameters in email would can excessive CPU usage (bsc#1260897).\n- CVE-2026-33263: submission-login: Panic when mail_max_userip_connections is reached (bsc#1276794).\n- CVE-2026-33603: login: base64 input can contain tabs that bypass IPC protection (bsc#1265147).\n- CVE-2026-33604: SMTP Smuggling via Missing Dot-Stuffing (bsc#1276802).\n- CVE-2026-33605: managesieve-login: Pre-auth crash (bsc#1276809).\n- CVE-2026-33606: dsync: Mail content can cause dsync protocol injection (bsc#1276800).\n- CVE-2026-33607: IMAP LIST match_sub() Exponential Backtracking -- CPU Denial of Service (bsc#1276795).\n- CVE-2026-40014: CPU DoS via Crafted References Header (bsc#1276804).\n- CVE-2026-40015: imap-hibernate can be crashed (bsc#1276812).\n- CVE-2026-40016: Sieve :contains/:matches O(NxM) substring match bypasses sieve_max_cpu_time limit (bsc#1265148).\n- CVE-2026-40019: managesieve-login pre-auth infinite loop (bsc#1276811).\n- CVE-2026-40020: IMAP folders can be shared-spammed to everyone (bsc#1265149).\n- CVE-2026-40203: IMAP Compression Can Reveal Whether a Small Synced Email Body Matches Sender-Chosen Text\n  (bsc#1276815).\n- CVE-2026-40205: OAuth2 passdb scope enforcement bypass via OR semantics in remote validation path (bsc#1276820).\n- CVE-2026-42006: imap-login: uncontrolled memory usage with excessive bracing over IMAP (bsc#1265150).\n- CVE-2026-42007: editheader RCE (bsc#1276817).\n- CVE-2026-42008: XCLIENT FORWARD= bare token not namespaced (bsc#1276824).\n- CVE-2026-42391: imap: Pre-login memory/CPU growth with ID command (bsc#1276835).\n- CVE-2026-42393: doveadm_password or api key length can still be leaked with timing comparisons (bsc#1276827).\n- CVE-2026-42395: Single NUL-Byte XCLIENT FORWARD Payload Crashes (bsc#1276826).\n- CVE-2026-52681: Sieve resource usage tracking lost when active script changes (bsc#1276828).\n- CVE-2026-52687: IMAP: COMPRESS ZSTD can cause excessive memory usage (bsc#1276837).\n- CVE-2026-73208: auth: db-oauth2: aud claim used as fallback for missing scope claim (bsc#1276830).\n- CVE-2026-73209: imap-login crash: Self-recursion on zero-output decompress chunks (bsc#1276833).\n\nChanges for dovecot23:\n\n- Update to version 2.3.21.1.\n","modified":"2026-09-28T18:23:37.297898157Z","published":"2026-09-14T07:22:32Z","related":["CVE-2024-23184","CVE-2024-23185","CVE-2025-59028","CVE-2025-59031","CVE-2025-59032","CVE-2026-27852","CVE-2026-27855","CVE-2026-27856","CVE-2026-27857","CVE-2026-27858","CVE-2026-27859","CVE-2026-33263","CVE-2026-33603","CVE-2026-33604","CVE-2026-33605","CVE-2026-33606","CVE-2026-33607","CVE-2026-40014","CVE-2026-40015","CVE-2026-40016","CVE-2026-40019","CVE-2026-40020","CVE-2026-40203","CVE-2026-40205","CVE-2026-42006","CVE-2026-42007","CVE-2026-42008","CVE-2026-42391","CVE-2026-42393","CVE-2026-42395","CVE-2026-52681","CVE-2026-52687","CVE-2026-73208","CVE-2026-73209"],"upstream":["CVE-2024-23184","CVE-2024-23185","CVE-2025-59028","CVE-2025-59031","CVE-2025-59032","CVE-2026-27852","CVE-2026-27855","CVE-2026-27856","CVE-2026-27857","CVE-2026-27858","CVE-2026-27859","CVE-2026-33263","CVE-2026-33603","CVE-2026-33604","CVE-2026-33605","CVE-2026-33606","CVE-2026-33607","CVE-2026-40014","CVE-2026-40015","CVE-2026-40016","CVE-2026-40019","CVE-2026-40020","CVE-2026-40203","CVE-2026-40205","CVE-2026-42006","CVE-2026-42007","CVE-2026-42008","CVE-2026-42391","CVE-2026-42393","CVE-2026-42395","CVE-2026-52681","CVE-2026-52687","CVE-2026-73208","CVE-2026-73209"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264139-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1229183"},{"type":"REPORT","url":"https://bugzilla.suse.com/1229184"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260894"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260895"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260897"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260898"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260899"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260900"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260901"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260902"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265147"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265148"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265149"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265150"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276794"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276795"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276799"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276800"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276802"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276804"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276809"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276811"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276812"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276815"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276817"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276820"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276824"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276826"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276827"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276828"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276830"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276833"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276835"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276837"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-23184"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-23185"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-59028"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-59031"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-59032"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27852"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27855"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27856"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27857"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27858"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27859"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33263"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33603"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33604"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33605"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33606"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33607"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40014"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40015"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40016"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40019"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40020"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40203"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40205"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42006"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42007"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42008"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42391"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42393"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42395"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52687"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73208"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73209"}],"affected":[{"package":{"name":"dovecot23","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP7","purl":"pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.21.1-150200.76.1"}]}],"ecosystem_specific":{"binaries":[{"dovecot23-fts-lucene":"2.3.21.1-150200.76.1","dovecot23-backend-mysql":"2.3.21.1-150200.76.1","dovecot23-fts":"2.3.21.1-150200.76.1","dovecot23-fts-solr":"2.3.21.1-150200.76.1","dovecot23-backend-sqlite":"2.3.21.1-150200.76.1","dovecot23-devel":"2.3.21.1-150200.76.1","dovecot23":"2.3.21.1-150200.76.1","dovecot23-backend-pgsql":"2.3.21.1-150200.76.1","dovecot23-fts-squat":"2.3.21.1-150200.76.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"}},{"package":{"name":"dovecot23","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.21.1-150200.76.1"}]}],"ecosystem_specific":{"binaries":[{"dovecot23-backend-mysql":"2.3.21.1-150200.76.1","dovecot23-backend-pgsql":"2.3.21.1-150200.76.1","dovecot23-backend-sqlite":"2.3.21.1-150200.76.1","dovecot23":"2.3.21.1-150200.76.1","dovecot23-fts-squat":"2.3.21.1-150200.76.1","dovecot23-fts":"2.3.21.1-150200.76.1","dovecot23-devel":"2.3.21.1-150200.76.1","dovecot23-fts-lucene":"2.3.21.1-150200.76.1","dovecot23-fts-solr":"2.3.21.1-150200.76.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"}},{"package":{"name":"dovecot23","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.21.1-150200.76.1"}]}],"ecosystem_specific":{"binaries":[{"dovecot23":"2.3.21.1-150200.76.1","dovecot23-backend-mysql":"2.3.21.1-150200.76.1","dovecot23-backend-sqlite":"2.3.21.1-150200.76.1","dovecot23-fts":"2.3.21.1-150200.76.1","dovecot23-backend-pgsql":"2.3.21.1-150200.76.1","dovecot23-devel":"2.3.21.1-150200.76.1","dovecot23-fts-solr":"2.3.21.1-150200.76.1","dovecot23-fts-lucene":"2.3.21.1-150200.76.1","dovecot23-fts-squat":"2.3.21.1-150200.76.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"}},{"package":{"name":"dovecot23","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.21.1-150200.76.1"}]}],"ecosystem_specific":{"binaries":[{"dovecot23-fts-solr":"2.3.21.1-150200.76.1","dovecot23-fts-lucene":"2.3.21.1-150200.76.1","dovecot23-devel":"2.3.21.1-150200.76.1","dovecot23-fts":"2.3.21.1-150200.76.1","dovecot23-backend-sqlite":"2.3.21.1-150200.76.1","dovecot23":"2.3.21.1-150200.76.1","dovecot23-backend-mysql":"2.3.21.1-150200.76.1","dovecot23-backend-pgsql":"2.3.21.1-150200.76.1","dovecot23-fts-squat":"2.3.21.1-150200.76.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"}},{"package":{"name":"dovecot23","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.21.1-150200.76.1"}]}],"ecosystem_specific":{"binaries":[{"dovecot23-backend-sqlite":"2.3.21.1-150200.76.1","dovecot23-backend-mysql":"2.3.21.1-150200.76.1","dovecot23-backend-pgsql":"2.3.21.1-150200.76.1","dovecot23-fts-squat":"2.3.21.1-150200.76.1","dovecot23-devel":"2.3.21.1-150200.76.1","dovecot23-fts":"2.3.21.1-150200.76.1","dovecot23":"2.3.21.1-150200.76.1","dovecot23-fts-solr":"2.3.21.1-150200.76.1","dovecot23-fts-lucene":"2.3.21.1-150200.76.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"}},{"package":{"name":"dovecot23","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.21.1-150200.76.1"}]}],"ecosystem_specific":{"binaries":[{"dovecot23-backend-mysql":"2.3.21.1-150200.76.1","dovecot23":"2.3.21.1-150200.76.1","dovecot23-backend-sqlite":"2.3.21.1-150200.76.1","dovecot23-fts":"2.3.21.1-150200.76.1","dovecot23-fts-lucene":"2.3.21.1-150200.76.1","dovecot23-fts-solr":"2.3.21.1-150200.76.1","dovecot23-devel":"2.3.21.1-150200.76.1","dovecot23-fts-squat":"2.3.21.1-150200.76.1","dovecot23-backend-pgsql":"2.3.21.1-150200.76.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"}},{"package":{"name":"dovecot23","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.21.1-150200.76.1"}]}],"ecosystem_specific":{"binaries":[{"dovecot23-backend-mysql":"2.3.21.1-150200.76.1","dovecot23-devel":"2.3.21.1-150200.76.1","dovecot23-fts":"2.3.21.1-150200.76.1","dovecot23-fts-solr":"2.3.21.1-150200.76.1","dovecot23":"2.3.21.1-150200.76.1","dovecot23-fts-squat":"2.3.21.1-150200.76.1","dovecot23-backend-sqlite":"2.3.21.1-150200.76.1","dovecot23-backend-pgsql":"2.3.21.1-150200.76.1","dovecot23-fts-lucene":"2.3.21.1-150200.76.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"}},{"package":{"name":"dovecot23","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.21.1-150200.76.1"}]}],"ecosystem_specific":{"binaries":[{"dovecot23-backend-sqlite":"2.3.21.1-150200.76.1","dovecot23-backend-pgsql":"2.3.21.1-150200.76.1","dovecot23":"2.3.21.1-150200.76.1","dovecot23-fts":"2.3.21.1-150200.76.1","dovecot23-fts-solr":"2.3.21.1-150200.76.1","dovecot23-fts-squat":"2.3.21.1-150200.76.1","dovecot23-fts-lucene":"2.3.21.1-150200.76.1","dovecot23-backend-mysql":"2.3.21.1-150200.76.1","dovecot23-devel":"2.3.21.1-150200.76.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"}},{"package":{"name":"dovecot23","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.21.1-150200.76.1"}]}],"ecosystem_specific":{"binaries":[{"dovecot23-devel":"2.3.21.1-150200.76.1","dovecot23-fts-lucene":"2.3.21.1-150200.76.1","dovecot23-fts":"2.3.21.1-150200.76.1","dovecot23":"2.3.21.1-150200.76.1","dovecot23-backend-mysql":"2.3.21.1-150200.76.1","dovecot23-fts-solr":"2.3.21.1-150200.76.1","dovecot23-backend-pgsql":"2.3.21.1-150200.76.1","dovecot23-fts-squat":"2.3.21.1-150200.76.1","dovecot23-backend-sqlite":"2.3.21.1-150200.76.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"}},{"package":{"name":"dovecot23","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.21.1-150200.76.1"}]}],"ecosystem_specific":{"binaries":[{"dovecot23-backend-pgsql":"2.3.21.1-150200.76.1","dovecot23-devel":"2.3.21.1-150200.76.1","dovecot23-fts-lucene":"2.3.21.1-150200.76.1","dovecot23-fts-squat":"2.3.21.1-150200.76.1","dovecot23-backend-mysql":"2.3.21.1-150200.76.1","dovecot23-backend-sqlite":"2.3.21.1-150200.76.1","dovecot23":"2.3.21.1-150200.76.1","dovecot23-fts-solr":"2.3.21.1-150200.76.1","dovecot23-fts":"2.3.21.1-150200.76.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"}},{"package":{"name":"dovecot23","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.21.1-150200.76.1"}]}],"ecosystem_specific":{"binaries":[{"dovecot23-backend-mysql":"2.3.21.1-150200.76.1","dovecot23-devel":"2.3.21.1-150200.76.1","dovecot23-backend-sqlite":"2.3.21.1-150200.76.1","dovecot23":"2.3.21.1-150200.76.1","dovecot23-fts-solr":"2.3.21.1-150200.76.1","dovecot23-fts-squat":"2.3.21.1-150200.76.1","dovecot23-backend-pgsql":"2.3.21.1-150200.76.1","dovecot23-fts-lucene":"2.3.21.1-150200.76.1","dovecot23-fts":"2.3.21.1-150200.76.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"}}],"schema_version":"1.9.0"}