-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 16 Sep 2026 15:06:35 -0400 Source: dovecot Architecture: source Version: 1:2.4.1+dfsg1-6+deb13u7 Distribution: trixie-security Urgency: medium Maintainer: Dovecot Maintainers <dovecot@packages.debian.org> Changed-By: Noah Meyerhans <noahm@debian.org> Closes: 1144639 1146018 Changes: dovecot (1:2.4.1+dfsg1-6+deb13u7) trixie-security; urgency=medium . * Import upstream fixes for multiple security issues. (Closes: #1146018) - CVE-2026-27852: DoS by sending mail with bad header - CVE-2026-33263: submission-login: Panic when mail_max_userip_connections is reached: Panic: epoll_ctl(del, 8) failed: Bad file descriptor - CVE-2026-33604: SMTP Smuggling via Missing Dot-Stuffing After Bare Carriage Return - CVE-2026-33605: managesieve-login: Pre-auth crash - CVE-2026-33607: Dovecot IMAP LIST match_sub() Exponential Backtracking — CPU Denial of Service - CVE-2026-40013: pigeonhole: Stack Buffer Underflow in Pigeonhole ManageSieve CHECKSCRIPT/PUTSCRIPT - CVE-2026-40014: IMAP THREAD REFERENCES O(N²) CPU DoS via Crafted References Header (index-thread-links.c) - CVE-2026-40015: imap-hibernate can be crashed - CVE-2026-40017: IMAP THREAD O(M³) CPU DoS via CRC32 Hash Collision in strmap (mail-index-strmap.c / hash2.c) - CVE-2026-40018: MySQL multi-byte escaping wrong - CVE-2026-40204: acl: lda_mailbox_autocreate can bypass acl restrictions - CVE-2026-42007: Sieve editheader RCE - CVE-2026-42391: imap: Pre-login memory/CPU growth with ID command - CVE-2026-42394: sieve: symlink traversal flaw could result in arbitrary file disclosure - CVE-2026-52681: Sieve resource usage tracking lost when active script changes - CVE-2026-52687: IMAP: COMPRESS ZSTD can cause excessive memory usage - CVE-2026-73209: imap-login crash: Self-recursion on zero-output decompress chunks - CVE-2026-33606: dsync: Mail content can cause dsync protocol injection - CVE-2026-40203: IMAP Compression Can Reveal Whether a Small Synced Email Body Matches Sender-Chosen Text - CVE-2026-42008: XCLIENT FORWARD= bare token not namespaced, allows nopassword injection via trusted proxy - CVE-2026-42392: imap-urlauth leaks memory into user-visible error messages - CVE-2026-42393: doveadm_password or api key length can still be leaked with timing comparisons - CVE-2026-42395: Single NUL-Byte XCLIENT FORWARD Payload Crashes - CVE-2026-40205: OAuth2 passdb scope enforcement bypass via OR semantics in remote validation path - CVE-2026-73208: auth: db-oauth2: aud claim used as fallback for missing scope claim * lib-mail: istream-header-filter - Fix potential assert-crash (Closes: #1144639) * CI: Disable test-build-twice job, which is known to fail on trixie Checksums-Sha1: 5d580e68fbf81eea11ab0d2382aef780ee8640e6 3992 dovecot_2.4.1+dfsg1-6+deb13u7.dsc 269572ee0e0af1ca6dfdf180142ecc28f462d945 202952 dovecot_2.4.1+dfsg1-6+deb13u7.debian.tar.xz 275e296f29f19114b8bc618d1115623daed3e559 7748 dovecot_2.4.1+dfsg1-6+deb13u7_source.buildinfo Checksums-Sha256: c69943573c24825eee761e23deaf0de4fbc7cc251e6c7564916dbe586cbeaa4d 3992 dovecot_2.4.1+dfsg1-6+deb13u7.dsc e8831e6dbcbd17fb8485af9bc5c81b48cdb16fd89a8084561f672475236f556d 202952 dovecot_2.4.1+dfsg1-6+deb13u7.debian.tar.xz 46d4552c23225e205abc6eb8693352f53e3e2de6735a29d60fe1e90882275b20 7748 dovecot_2.4.1+dfsg1-6+deb13u7_source.buildinfo Files: 81419335a1847c4d9370af6f43ea3631 3992 mail optional dovecot_2.4.1+dfsg1-6+deb13u7.dsc 108e44d7bdd4896814eca4a0dc1e899f 202952 mail optional dovecot_2.4.1+dfsg1-6+deb13u7.debian.tar.xz 929cbc0d5c7969f6167ea2bd5a76ba24 7748 mail optional dovecot_2.4.1+dfsg1-6+deb13u7_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5G+E0xEKhJuZ7RJ34+c1IpshdTUFAmq5GpkACgkQ4+c1Ipsh dTXKtxAAu39fM8dWDUz+9LXojP/kj8KLzGtWIy4S0uBhzjT/ye+wcSSN631IRfXz eckDwXRg3vGiT+IALuk5nl8MMSH5P+kO6xqJV6j4gQclUR5TkTYJUso9rYFmoCNH njUfF+1fkcGSZeNs/7Blkh2ERPC3yHsxxZ645Nj6UYJDU+nRIkdx5sXGpEzvAW23 zl7WHyfC9tO354k6iCqxQm8mn20B05zF8ZXozObLSOKjU8JA1VnF5YLaKSUkkGIu qS7DcWMJlniKoB1qUVJSPsIphMWoy3pXIWU+Z++pZmTYzg2HEPPuIoD8oF2c2HQA bcjCH77mnmbHmTg4CIQU0XjDkolGKSg9bHseE/ehPw+u2q+6SwhgmS+QOLZhgifw 3jrEnkcl54rtrdTtpGLg6Q7GKTUizRVbO0pa5xHuNcdd9sYRjo7hd+n6rkPRs/g8 tyeEDVg/UqAWG8Tyiv08EFat8U3dSXX/fQi7OoNIVMDdCBmO1N9q63gRh8Dld6ZC KdOn38PAltF5jQM+oMm57zZ39VZBrCDpNdoxdRCnLfMQjuu3bu1ufGyjvJxB80rP iAOZRvc2pnTDn/J1Z+QDdZbSUPXkZ8TQEX0D5ArCK1g6vNlemv9K95tfeDRTr4Uh DUMi2PllZ/PoaAo7xAnFYm8vkMSn0wEXPlTRvkIwwnZCE9OYIdo= =tX12 -----END PGP SIGNATURE-----