{"id":"ALSA-2026:76763","summary":"Important: dovecot security, bug fix, and enhancement update","details":"Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages.   \n\nSecurity Fix(es):  \n\n  * dovecot: Dovecot: Denial of Service via IMAP ID command with excessive parameters (CVE-2026-42391)\n  * dovecot: Dovecot: Authentication bypass via incorrect OAuth2 token validation (CVE-2026-73208)\n  * dovecot: Dovecot: Denial of service via crafted email headers (CVE-2026-27852)\n  * dovecot: Dovecot: Denial of Service via truncated quoted argument in ManageSieve (CVE-2026-40019)\n  * dovecot: Dovecot: Denial of Service and potential message duplication via connection limit exhaustion (CVE-2026-33263)\n  * dovecot: Dovecot: Denial of Service in ManageSieve login process (CVE-2026-33605)\n  * dovecot: Dovecot: Arbitrary Code Execution via Sieve editheader use-after-free (CVE-2026-42007)\n  * dovecot: Dovecot: MySQL multi-byte escaping wrong (CVE-2026-40018)\n\n\nBug Fix(es) and Enhancement(s):  \n\n  * Dovecot crashes when accessing mailbox with: \"Panic: file mail-user.c: line 229 (mail_user_deinit): assertion failed: ((*user)-\u003erefcount == 1)\" (JIRA:AlmaLinux-176273)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n","modified":"2026-10-07T12:56:52.469309474Z","published":"2026-10-06T00:00:00Z","related":["CVE-2026-27852","CVE-2026-33263","CVE-2026-33605","CVE-2026-40018","CVE-2026-40019","CVE-2026-42007","CVE-2026-42391","CVE-2026-73208"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:76763"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-27852"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-33263"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-33605"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-40018"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-40019"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-42007"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-42391"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-73208"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2525545"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2525547"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2525557"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2525559"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2525567"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2525576"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2525583"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2525584"},{"type":"ADVISORY","url":"https://errata.almalinux.org/8/ALSA-2026-76763.html"}],"affected":[{"package":{"name":"dovecot","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/dovecot"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.3.16-16.el8_10"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:76763.json"}},{"package":{"name":"dovecot-devel","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/dovecot-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.3.16-16.el8_10"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:76763.json"}},{"package":{"name":"dovecot-mysql","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/dovecot-mysql"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.3.16-16.el8_10"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:76763.json"}},{"package":{"name":"dovecot-pgsql","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/dovecot-pgsql"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.3.16-16.el8_10"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:76763.json"}},{"package":{"name":"dovecot-pigeonhole","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/dovecot-pigeonhole"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.3.16-16.el8_10"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:76763.json"}}],"schema_version":"1.9.0"}