critical Security update for dovecot23
SUSE-SLE-Module-Server-Applications-15-SP7-2026-4139


This update for dovecot23 fixes the following issues: - CVE-2024-23184: parsing of messages containing many address headers (From, To, Cc, Bcc, etc.) could be excessively CPU intensive (bsc#1229184). - CVE-2024-23185: large headers can cause resource exhaustion when parsing message (bsc#1229183). - CVE-2025-59028: Invalid base64 authentication can cause DoS for other logins (bsc#1260894). - CVE-2025-59031: decode2text.sh OOXML extraction may follow symlinks and read unintended files during indexing (bsc#1260895). - CVE-2025-59032: pigeonhole: ManageSieve panic occurs with sieve-connect as a client (bsc#1260902). - CVE-2026-27852: DoS by sending mail with bad header (bsc#1276799). - CVE-2026-27855: OTP driver vulnerable to replay attack (bsc#1260900). - CVE-2026-27856: Doveadm credentials were not checked using timing-safe checking function (bsc#1260899). - CVE-2026-27857: sending excessive parenthesis causes imap-login to use excessive memory (bsc#1260898). - CVE-2026-27858: pigeonhole: managesieve-login can allocate large amount of memory during authentication (bsc#1260901). - CVE-2026-27859: excessive RFC 2231 MIME parameters in email would can excessive CPU usage (bsc#1260897). - CVE-2026-33263: submission-login: Panic when mail_max_userip_connections is reached (bsc#1276794). - CVE-2026-33603: login: base64 input can contain tabs that bypass IPC protection (bsc#1265147). - CVE-2026-33604: SMTP Smuggling via Missing Dot-Stuffing (bsc#1276802). - CVE-2026-33605: managesieve-login: Pre-auth crash (bsc#1276809). - CVE-2026-33606: dsync: Mail content can cause dsync protocol injection (bsc#1276800). - CVE-2026-33607: IMAP LIST match_sub() Exponential Backtracking -- CPU Denial of Service (bsc#1276795). - CVE-2026-40014: CPU DoS via Crafted References Header (bsc#1276804). - CVE-2026-40015: imap-hibernate can be crashed (bsc#1276812). - CVE-2026-40016: Sieve :contains/:matches O(NxM) substring match bypasses sieve_max_cpu_time limit (bsc#1265148). - CVE-2026-40019: managesieve-login pre-auth infinite loop (bsc#1276811). - CVE-2026-40020: IMAP folders can be shared-spammed to everyone (bsc#1265149). - CVE-2026-40203: IMAP Compression Can Reveal Whether a Small Synced Email Body Matches Sender-Chosen Text (bsc#1276815). - CVE-2026-40205: OAuth2 passdb scope enforcement bypass via OR semantics in remote validation path (bsc#1276820). - CVE-2026-42006: imap-login: uncontrolled memory usage with excessive bracing over IMAP (bsc#1265150). - CVE-2026-42007: editheader RCE (bsc#1276817). - CVE-2026-42008: XCLIENT FORWARD= bare token not namespaced (bsc#1276824). - CVE-2026-42391: imap: Pre-login memory/CPU growth with ID command (bsc#1276835). - CVE-2026-42393: doveadm_password or api key length can still be leaked with timing comparisons (bsc#1276827). - CVE-2026-42395: Single NUL-Byte XCLIENT FORWARD Payload Crashes (bsc#1276826). - CVE-2026-52681: Sieve resource usage tracking lost when active script changes (bsc#1276828). - CVE-2026-52687: IMAP: COMPRESS ZSTD can cause excessive memory usage (bsc#1276837). - CVE-2026-73208: auth: db-oauth2: aud claim used as fallback for missing scope claim (bsc#1276830). - CVE-2026-73209: imap-login crash: Self-recursion on zero-output decompress chunks (bsc#1276833). Changes for dovecot23: - Update to version 2.3.21.1.


cloud_download Downloads

Server Applications Module 15.7 s390x
Server Applications Module 15.7 aarch64
Server Applications Module 15.7 ppc64le
Server Applications Module 15.7 x86_64