{"id":"USN-8136-2","summary":"dovecot regression","details":"USN-8136-1 fixed vulnerabilities in Dovecot. The update caused a regression\non Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. This update fixes the problem.\n\nWe apologize for the inconvenience.\n\nOriginal advisory details:\n\n It was discovered that Dovecot incorrectly handled invalid base64 SASL data.\n An attacker could possibly use this issue to cause a denial of service. This\n issue only affected Ubuntu 25.10. (CVE-2025-59028)\n\n It was discovered that Dovecot script decode2text.sh incorrectly handled zip\n files. An attacker could possibly use this issue to obtain sensitive\n information. (CVE-2025-59031)\n\n It was discovered that Dovecot incorrectly handled certain AUTHENTICATE\n requests. An attacker could possibly use this issue to cause a denial of\n service. (CVE-2025-59032)\n\n It was discovered that Dovecot incorrectly handled certain SQL based\n authentication. An attacker could possibly use this issue to bypass\n authentication. This issue only affected Ubuntu 25.10. (CVE-2026-24031)\n\n It was discovered that Dovecot incorrectly handled certain LDAP based\n authentication. An attacker could possibly use this issue to bypass\n restrictions and allow probing of LDAP structure. This issue only affected\n Ubuntu 25.10. (CVE-2026-27860)\n\n It was discovered that Dovecot is vulnerable to replay attack under\n certain conditions. An attacker could possibly use this issue to bypass\n authentication. (CVE-2026-27855)\n\n It was discovered that Dovecot is vulnerable to a timing attack under\n certain conditions. An attacker could possibly use this issue to bypass\n authentication. (CVE-2026-27856)\n\n It was discovered that Dovecot incorrectly handled certain IMAP login\n requests. An attacker could possibly use this issue to cause a denial of\n service. (CVE-2026-27857)\n\n It was discovered that Dovecot incorrectly handled certain specially\n crafted messages. An attacker could possibly use this issue to cause a\n denial of service. (CVE-2026-27858)\n\n It was discovered that Dovecot incorrectly handled certain specially\n crafted mail messages. An attacker could possibly use this issue to\n cause a denial of service. (CVE-2026-27859)\n\n It was discovered that Dovecot incorrectly handles file paths. A attacker\n could possibly use this issue to perform a path traversal and obtain or\n modify arbitrary files. This issue only affected Ubuntu 22.04 LTS and\n Ubuntu 24.04 LTS. (CVE-2026-0394)","modified":"2026-04-29T10:03:04.698276700Z","published":"2026-04-28T12:52:01Z","related":["UBUNTU-CVE-2026-0394"],"upstream":["CVE-2026-0394","UBUNTU-CVE-2026-0394"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8136-2"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-0394"},{"type":"REPORT","url":"https://launchpad.net/bugs/2150116"}],"affected":[{"package":{"name":"dovecot","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/dovecot@1:2.3.16+dfsg1-3ubuntu2.8?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.3.16+dfsg1-3ubuntu2.8"}]}],"versions":["1:2.3.13+dfsg1-1ubuntu3","1:2.3.16+dfsg1-3ubuntu1","1:2.3.16+dfsg1-3ubuntu2","1:2.3.16+dfsg1-3ubuntu2.1","1:2.3.16+dfsg1-3ubuntu2.2","1:2.3.16+dfsg1-3ubuntu2.4","1:2.3.16+dfsg1-3ubuntu2.6","1:2.3.16+dfsg1-3ubuntu2.7"],"ecosystem_specific":{"binaries":[{"binary_name":"dovecot-auth-lua","binary_version":"1:2.3.16+dfsg1-3ubuntu2.8"},{"binary_name":"dovecot-core","binary_version":"1:2.3.16+dfsg1-3ubuntu2.8"},{"binary_name":"dovecot-gssapi","binary_version":"1:2.3.16+dfsg1-3ubuntu2.8"},{"binary_name":"dovecot-imapd","binary_version":"1:2.3.16+dfsg1-3ubuntu2.8"},{"binary_name":"dovecot-ldap","binary_version":"1:2.3.16+dfsg1-3ubuntu2.8"},{"binary_name":"dovecot-lmtpd","binary_version":"1:2.3.16+dfsg1-3ubuntu2.8"},{"binary_name":"dovecot-lucene","binary_version":"1:2.3.16+dfsg1-3ubuntu2.8"},{"binary_name":"dovecot-managesieved","binary_version":"1:2.3.16+dfsg1-3ubuntu2.8"},{"binary_name":"dovecot-mysql","binary_version":"1:2.3.16+dfsg1-3ubuntu2.8"},{"binary_name":"dovecot-pgsql","binary_version":"1:2.3.16+dfsg1-3ubuntu2.8"},{"binary_name":"dovecot-pop3d","binary_version":"1:2.3.16+dfsg1-3ubuntu2.8"},{"binary_name":"dovecot-sieve","binary_version":"1:2.3.16+dfsg1-3ubuntu2.8"},{"binary_name":"dovecot-solr","binary_version":"1:2.3.16+dfsg1-3ubuntu2.8"},{"binary_name":"dovecot-sqlite","binary_version":"1:2.3.16+dfsg1-3ubuntu2.8"},{"binary_name":"dovecot-submissiond","binary_version":"1:2.3.16+dfsg1-3ubuntu2.8"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8136-2.json","cves_map":{"ecosystem":"Ubuntu:22.04:LTS","cves":[{"id":"CVE-2026-0394","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}]}}},{"package":{"name":"dovecot","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/dovecot@1:2.3.21+dfsg1-2ubuntu6.4?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.3.21+dfsg1-2ubuntu6.4"}]}],"versions":["1:2.3.20+dfsg1-1ubuntu3","1:2.3.21+dfsg1-2ubuntu1","1:2.3.21+dfsg1-2ubuntu2","1:2.3.21+dfsg1-2ubuntu4","1:2.3.21+dfsg1-2ubuntu5","1:2.3.21+dfsg1-2ubuntu6","1:2.3.21+dfsg1-2ubuntu6.1","1:2.3.21+dfsg1-2ubuntu6.2","1:2.3.21+dfsg1-2ubuntu6.3"],"ecosystem_specific":{"binaries":[{"binary_name":"dovecot-auth-lua","binary_version":"1:2.3.21+dfsg1-2ubuntu6.4"},{"binary_name":"dovecot-core","binary_version":"1:2.3.21+dfsg1-2ubuntu6.4"},{"binary_name":"dovecot-gssapi","binary_version":"1:2.3.21+dfsg1-2ubuntu6.4"},{"binary_name":"dovecot-imapd","binary_version":"1:2.3.21+dfsg1-2ubuntu6.4"},{"binary_name":"dovecot-ldap","binary_version":"1:2.3.21+dfsg1-2ubuntu6.4"},{"binary_name":"dovecot-lmtpd","binary_version":"1:2.3.21+dfsg1-2ubuntu6.4"},{"binary_name":"dovecot-managesieved","binary_version":"1:2.3.21+dfsg1-2ubuntu6.4"},{"binary_name":"dovecot-mysql","binary_version":"1:2.3.21+dfsg1-2ubuntu6.4"},{"binary_name":"dovecot-pgsql","binary_version":"1:2.3.21+dfsg1-2ubuntu6.4"},{"binary_name":"dovecot-pop3d","binary_version":"1:2.3.21+dfsg1-2ubuntu6.4"},{"binary_name":"dovecot-sieve","binary_version":"1:2.3.21+dfsg1-2ubuntu6.4"},{"binary_name":"dovecot-solr","binary_version":"1:2.3.21+dfsg1-2ubuntu6.4"},{"binary_name":"dovecot-sqlite","binary_version":"1:2.3.21+dfsg1-2ubuntu6.4"},{"binary_name":"dovecot-submissiond","binary_version":"1:2.3.21+dfsg1-2ubuntu6.4"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8136-2.json","cves_map":{"ecosystem":"Ubuntu:24.04:LTS","cves":[{"id":"CVE-2026-0394","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}]}}}],"schema_version":"1.7.5"}