-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 31 Aug 2026 15:19:46 -0400 Source: dovecot Architecture: source Version: 1:2.4.5+dfsg1-1 Distribution: unstable Urgency: medium Maintainer: Dovecot Maintainers <dovecot@packages.debian.org> Changed-By: Noah Meyerhans <noahm@debian.org> Closes: 1146018 Changes: dovecot (1:2.4.5+dfsg1-1) unstable; urgency=medium . * [e470328] New upstream version 2.4.5+dfsg1 (Closes: #1146018) - https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html - CVE-2026-27852 - DoS by sending mail with bad header. - CVE-2026-33263 - submission-login: Panic when mail_max_userip_connections is reached - CVE-2026-33604 - SMTP Smuggling via Missing Dot-Stuffing After Bare Carriage Return. - CVE-2026-33605 - managesieve-login: Pre-auth crash. - CVE-2026-33606 - dsync: Mail content can cause dsync protocol injection. - CVE-2026-33607 - Dovecot IMAP LIST match_sub() Exponential Backtracking - CPU Denial of Service. - CVE-2026-40013 - pigeonhole: Stack Buffer Underflow in Pigeonhole ManageSieve CHECKSCRIPT/PUTSCRIPT. - CVE-2026-40014 - Whenever a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. - CVE-2026-40015 - An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process. - CVE-2026-40017 - IMAP THREAD O(M³) CPU DoS via CRC32 Hash Collision in strmap - CVE-2026-40018 - MySQL multi-byte escaping wrong. - CVE-2026-40019 - v2.4.3 regression: managesieve-login pre-auth infinite loop. - CVE-2026-40203 - IMAP Compression Can Reveal Whether a Small Synced Email Body Matches Sender-Chosen Text. - CVE-2026-40204 - acl: lda_mailbox_autocreate can bypass acl restrictions. - CVE-2026-40205 - OAuth2 passdb scope enforcement bypass via OR semantics in remote validation path - CVE-2026-42007 - Sieve editheader RCE. An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. - CVE-2026-42008 - XCLIENT FORWARD= bare token not namespaced, allows nopassword injection via trusted proxy. - CVE-2026-42391 - imap: Pre-login memory/CPU growth with ID command. - CVE-2026-42392 - imap-urlauth leaks memory into user-visible error messages. - CVE-2026-42393 - doveadm_password or api key length can still be leaked with timing comparisons. - CVE-2026-42395 - Single NUL-Byte XCLIENT FORWARD Payload Crashes. A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. - CVE-2026-52681 - Sieve resource usage tracking lost when active script changes. - CVE-2026-52687 - IMAP: COMPRESS ZSTD can cause excessive memory usage. - CVE-2026-73208 - auth: db-oauth2: aud claim used as fallback for missing scope claim. - CVE-2026-73209 - imap-login crash: Self-recursion on zero-output decompress chunks. * [0f045ed] refresh patches * [43cc0a0] d/copyright: reflect upstream's removal of src/lib-otp * [e781a92] update dovecot-mysql transitional package metadata Checksums-Sha1: 67f2929efff70648a7c89f5eda017044484ee7c6 4184 dovecot_2.4.5+dfsg1-1.dsc dc6d8c3ba239770f8ddbb0c13631c78f1086f61b 1868063 dovecot_2.4.5+dfsg1.orig-pigeonhole.tar.gz 53c1b26fdfe710a047955ab82629cb900d35b592 8747733 dovecot_2.4.5+dfsg1.orig.tar.gz 684789ead1a216eaf86a12214bf21dab7084026a 228 dovecot_2.4.5+dfsg1.orig.tar.gz.asc a234f6852b90aadc20a6fc31a48e468bfe541b7a 90704 dovecot_2.4.5+dfsg1-1.debian.tar.xz bada98abba1b7209bdc36af0804ce87746ac75ef 7918 dovecot_2.4.5+dfsg1-1_source.buildinfo Checksums-Sha256: 1bff3dba4224bc472946e3bc8b4f99308eec523cefae6a2b0e9e7fcc501b7f09 4184 dovecot_2.4.5+dfsg1-1.dsc 8ebd0fdc00059aaff68eabd0cc4744772675556015c3ce52f986eae6409e9dec 1868063 dovecot_2.4.5+dfsg1.orig-pigeonhole.tar.gz 868c2686a61b5f8e00a3e4721789b1ab46e6528fd773a5fbed07a6ecba7731e6 8747733 dovecot_2.4.5+dfsg1.orig.tar.gz 2f12736988393b3f42cdb164b23e8ff19a46f9f0580a79dc540976aa5b15f4f0 228 dovecot_2.4.5+dfsg1.orig.tar.gz.asc b678823c19facb89c7859f79be67c41b1d107beeb4edceb66d3768121bdb2259 90704 dovecot_2.4.5+dfsg1-1.debian.tar.xz 5689b07cc256b4afa51d101332a0749ba5a66ef12b6c3362e96db16235dc9930 7918 dovecot_2.4.5+dfsg1-1_source.buildinfo Files: 6dbec9dc76ca7eb029f7362c48f1619b 4184 mail optional dovecot_2.4.5+dfsg1-1.dsc 5cbd3e3ddcd275f8807fd2709b0e92cd 1868063 mail optional dovecot_2.4.5+dfsg1.orig-pigeonhole.tar.gz af363b82469387f8b2fbb5b7f6e6e1ec 8747733 mail optional dovecot_2.4.5+dfsg1.orig.tar.gz 54e0d6bc91caa3076c6e00d2ebaf7bb1 228 mail optional dovecot_2.4.5+dfsg1.orig.tar.gz.asc 413e3c20c8f5e8c48872ba8c6438c32c 90704 mail optional dovecot_2.4.5+dfsg1-1.debian.tar.xz 7a586d2aba483c6f46035c61b8301616 7918 mail optional dovecot_2.4.5+dfsg1-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5G+E0xEKhJuZ7RJ34+c1IpshdTUFAmqWFuwACgkQ4+c1Ipsh dTXwUA/+I4gwILdcT25Zf6wLD0KABJZy675jnIQbfH57q43oSIL03mzOygeDbJen fwowd6Km7gstQJCWybrQRi/B1U6qiKVbBoaRugawTEpM4sZyZWguCClJHVGHWdon gzPh/OSFpZ2VFbn+f+G8gCqiwtGXN3/m+dPVS6w0OVZXn+FeP6Si4JigeKb2hZs1 eJ8AJ2z+V8U/CAyzXmmma+bi4oVBKG/tspBAqi5TWRw8e8CwBwxLyWfFG4TBHkEq //xXNplpDDcgty4u697i5HbYMIZMOBfgiN90PTUBu/JazPjILMriqhn57qwc9UU3 ctSb4jGiAgyw+KsIMwdrJuc5PLxzRpziPmUZhpl8yOsNSAqfi3t/tfBaek/8HMoH cDw865X0Fama2Phd3nSKIkmZhQqk4HUascleWXt7uSP9dk4OMFtNTTUExzJON5TF zDSTxUwjbnqnN/O48OaPuX/rgRqvU5yhyOmb2zSMIUHYxPAMbme72sidMa9jlAjp t4AkNjZ4W9IUiWFmPI9Ummb1iNFUYJkxxyloIkrRp5lsQyFnedYXvfaH7vBPaWEV t1oyExsHFOTGQ/fYg3xQGTcBheSDU5I7ROfXpbq6JumglSge8gQ0YxXU5370NRjI uorsM49IovdbxmcyeznhBoh/IWcr3YCbNNzfSdGD+4VQJoJuki4= =cV5D -----END PGP SIGNATURE-----