{"id":"SUSE-SU-2026:23595-1","summary":"Security update for dovecot24","details":"This update for dovecot24 fixes the following issues:\n\nUpdate to 2.4.5.\n\n- CVE-2026-33263: `submission-login`: panic when `mail_max_userip_connections` is reached (bsc#1276794).\n- CVE-2026-27852: DoS by sending mail with bad header (bsc#1276799).\n- CVE-2026-33604: SMTP smuggling via missing dot-stuffing after bare carriage return (bsc#1276802).\n- CVE-2026-33605: `managesieve-login`: pre-auth crash (bsc#1276809).\n- CVE-2026-33606: `dsync`: mail content can cause `dsync` protocol injection (bsc#1276800).\n- CVE-2026-33607: IMAP `LIST` `match_sub()` exponential backtracking leading to CPU denial of service (bsc#1276795).\n- CVE-2026-40013: stack buffer underflow in `pigeonhole` `ManageSieve` `CHECKSCRIPT/PUTSCRIPT` (bsc#1276807).\n- CVE-2026-40014: CPU DoS via crafted references header (bsc#1276804).\n- CVE-2026-40015: `imap-hibernate` can be crashed (bsc#1276812).\n- CVE-2026-40017: CPU DoS via CRC32 hash collision in `strmap` (bsc#1276813).\n- CVE-2026-40018: MySQL multi-byte escaping performed incorrectly (bsc#1276810).\n- CVE-2026-40203: IMAP compression can reveal whether a small synced email body matches sender-chosen text\n  (bsc#1276815).\n- CVE-2026-40204: `lda_mailbox_autocreate` can bypass ACL restrictions (bsc#1276819).\n- CVE-2026-40205: OAuth2 `passdb` scope enforcement bypass via OR semantics in remote validation path (bsc#1276820).\n- CVE-2026-42007: `sieve` `editheader` RCE (bsc#1276817).\n- CVE-2026-42008: `XCLIENT FORWARD= bare` token not namespaced (bsc#1276824).\n- CVE-2026-42391: `imap`: pre-login memory/CPU growth with `ID` command (bsc#1276835).\n- CVE-2026-42392: `imap-urlauth` leaks memory into user-visible error messages (bsc#1276829).\n- CVE-2026-42393: `doveadm_password` or api key length can be leaked with timing comparisons (bsc#1276827).\n- CVE-2026-52687: `imap`: `COMPRESS ZSTD` can cause excessive memory usage (bsc#1276837).\n- CVE-2026-42395: single NUL-byte `XCLIENT FORWARD` payload crashes (bsc#1276826).\n- CVE-2026-52681: `sieve` resource usage tracking lost when active script changes (bsc#1276828).\n- CVE-2026-73208: `auth`: `db-oauth2`: `aud` claim used as fallback for missing scope claim (bsc#1276830).\n- CVE-2026-73209: `imap-login` crash due to self-recursion on zero-output decompress chunks (bsc#1276833).\n","modified":"2026-09-29T18:23:18.714105294Z","published":"2026-09-01T14:12:16Z","related":["CVE-2026-27852","CVE-2026-33263","CVE-2026-33604","CVE-2026-33605","CVE-2026-33606","CVE-2026-33607","CVE-2026-40013","CVE-2026-40014","CVE-2026-40015","CVE-2026-40017","CVE-2026-40018","CVE-2026-40203","CVE-2026-40204","CVE-2026-40205","CVE-2026-42007","CVE-2026-42008","CVE-2026-42391","CVE-2026-42392","CVE-2026-42393","CVE-2026-42395","CVE-2026-52681","CVE-2026-52687","CVE-2026-73208","CVE-2026-73209"],"upstream":["CVE-2026-27852","CVE-2026-33263","CVE-2026-33604","CVE-2026-33605","CVE-2026-33606","CVE-2026-33607","CVE-2026-40013","CVE-2026-40014","CVE-2026-40015","CVE-2026-40017","CVE-2026-40018","CVE-2026-40203","CVE-2026-40204","CVE-2026-40205","CVE-2026-42007","CVE-2026-42008","CVE-2026-42391","CVE-2026-42392","CVE-2026-42393","CVE-2026-42395","CVE-2026-52681","CVE-2026-52687","CVE-2026-73208","CVE-2026-73209"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623595-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276794"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276795"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276799"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276800"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276802"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276804"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276807"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276809"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276810"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276812"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276813"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276815"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276817"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276819"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276820"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276824"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276826"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276827"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276828"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276829"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276830"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276833"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276835"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276837"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27852"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33263"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33604"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33605"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33606"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33607"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40013"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40014"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40015"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40017"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40018"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40203"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40204"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40205"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42007"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42008"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42391"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42392"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42393"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42395"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52687"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73208"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73209"}],"affected":[{"package":{"name":"dovecot24","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/dovecot24&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.4-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"dovecot24-backend-sqlite":"2.4.4-160000.2.1","dovecot24-devel":"2.4.4-160000.2.1","dovecot24-fts":"2.4.4-160000.2.1","dovecot24-fts-solr":"2.4.4-160000.2.1","dovecot24":"2.4.4-160000.2.1","dovecot24-backend-mysql":"2.4.4-160000.2.1","dovecot24-backend-pgsql":"2.4.4-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23595-1.json"}},{"package":{"name":"dovecot24","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/dovecot24&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.4-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"dovecot24":"2.4.4-160000.2.1","dovecot24-backend-mysql":"2.4.4-160000.2.1","dovecot24-backend-pgsql":"2.4.4-160000.2.1","dovecot24-backend-sqlite":"2.4.4-160000.2.1","dovecot24-devel":"2.4.4-160000.2.1","dovecot24-fts":"2.4.4-160000.2.1","dovecot24-fts-solr":"2.4.4-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23595-1.json"}}],"schema_version":"1.9.0"}