{"id":"SUSE-SU-2026:3919-1","summary":"Security update for dovecot22","details":"This update for dovecot22 fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2026-27852: DoS by sending mail with bad header (bsc#1276799).\n- CVE-2026-33604: SMTP smuggling via missing dot-stuffing after bare carriage return (bsc#1276802).\n- CVE-2026-33605: `managesieve-login`: pre-auth crash (bsc#1276809).\n- CVE-2026-33606: `dsync`: mail content can cause `dsync` protocol injection (bsc#1276800).\n- CVE-2026-33607: IMAP `LIST` `match_sub()` exponential backtracking leading to CPU denial of service (bsc#1276795).\n- CVE-2026-40014: CPU DoS via crafted references header (bsc#1276804).\n- CVE-2026-40015: `imap-hibernate` can be crashed (bsc#1276812).\n- CVE-2026-40019: `managesieve-login` pre-auth infinite loop (bsc#1276811).\n- CVE-2026-40203: IMAP compression can reveal whether a small synced email body matches sender-chosen text\n  (bsc#1276815).\n- CVE-2026-42007: `sieve` `editheader` RCE (bsc#1276817).\n- CVE-2026-42391: `imap`: pre-login memory/CPU growth with `ID` command (bsc#1276835).\n- CVE-2026-42393: `doveadm_password` or api key length can be leaked with timing comparisons (bsc#1276827).\n- CVE-2026-52687: `imap`: `COMPRESS ZSTD` can cause excessive memory usage (bsc#1276837).\n- CVE-2026-73209: `imap-login` crash due to self-recursion on zero-output decompress chunks (bsc#1276833).\n- multiple security fixes (bsc#1276792).\n\nOther updates and bugfixes:\n\n- Non-CVE hardening taken from the same upstream release:\n  * `sieve`: requiring the same extension repeatedly grew the default argument override chain, which is walked\n    recursively - a crafted script could overflow the stack\n  * `sieve`: `${unicode:...}` hex values could overflow an `unsigned int` and wrap back into the valid Unicode range;\n    the hex parser also read one byte past the end of the buffer\n  * `sieve` variables: the `${1234...}` numeric index overflowed a `signed int`\n  * `sieve enotify`: a single script could emit an unlimited number of notification messages; limited to 10 as upstream\n    does\n","modified":"2026-09-10T18:23:19.872899569Z","published":"2026-09-02T07:31:54Z","related":["CVE-2026-27852","CVE-2026-33604","CVE-2026-33605","CVE-2026-33606","CVE-2026-33607","CVE-2026-40014","CVE-2026-40015","CVE-2026-40019","CVE-2026-40203","CVE-2026-42007","CVE-2026-42391","CVE-2026-42393","CVE-2026-52687","CVE-2026-73209"],"upstream":["CVE-2026-27852","CVE-2026-33604","CVE-2026-33605","CVE-2026-33606","CVE-2026-33607","CVE-2026-40014","CVE-2026-40015","CVE-2026-40019","CVE-2026-40203","CVE-2026-42007","CVE-2026-42391","CVE-2026-42393","CVE-2026-52687","CVE-2026-73209"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263919-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276792"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276795"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276799"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276800"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276802"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276804"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276809"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276811"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276812"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276815"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276817"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276827"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276833"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276835"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276837"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27852"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33604"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33605"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33606"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33607"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40014"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40015"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40019"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40203"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42007"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42391"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42393"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52687"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73209"}],"affected":[{"package":{"name":"dovecot22","ecosystem":"SUSE:Linux Enterprise Server 12 SP5-LTSS","purl":"pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.31-19.40.1"}]}],"ecosystem_specific":{"binaries":[{"dovecot22-devel":"2.2.31-19.40.1","dovecot22":"2.2.31-19.40.1","dovecot22-backend-mysql":"2.2.31-19.40.1","dovecot22-backend-pgsql":"2.2.31-19.40.1","dovecot22-backend-sqlite":"2.2.31-19.40.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3919-1.json"}},{"package":{"name":"dovecot22","ecosystem":"SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5","purl":"pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.31-19.40.1"}]}],"ecosystem_specific":{"binaries":[{"dovecot22-backend-sqlite":"2.2.31-19.40.1","dovecot22-devel":"2.2.31-19.40.1","dovecot22":"2.2.31-19.40.1","dovecot22-backend-mysql":"2.2.31-19.40.1","dovecot22-backend-pgsql":"2.2.31-19.40.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3919-1.json"}}],"schema_version":"1.9.0"}