ALSA-2026:76763

Source
https://errata.almalinux.org/8/ALSA-2026-76763.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:76763.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2026:76763
Related
Published
2026-10-06T00:00:00Z
Modified
2026-10-07T12:56:52Z
Summary
Important: dovecot security, bug fix, and enhancement update
Details

Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages.

Security Fix(es):

  • dovecot: Dovecot: Denial of Service via IMAP ID command with excessive parameters (CVE-2026-42391)
  • dovecot: Dovecot: Authentication bypass via incorrect OAuth2 token validation (CVE-2026-73208)
  • dovecot: Dovecot: Denial of service via crafted email headers (CVE-2026-27852)
  • dovecot: Dovecot: Denial of Service via truncated quoted argument in ManageSieve (CVE-2026-40019)
  • dovecot: Dovecot: Denial of Service and potential message duplication via connection limit exhaustion (CVE-2026-33263)
  • dovecot: Dovecot: Denial of Service in ManageSieve login process (CVE-2026-33605)
  • dovecot: Dovecot: Arbitrary Code Execution via Sieve editheader use-after-free (CVE-2026-42007)
  • dovecot: Dovecot: MySQL multi-byte escaping wrong (CVE-2026-40018)

Bug Fix(es) and Enhancement(s):

  • Dovecot crashes when accessing mailbox with: "Panic: file mail-user.c: line 229 (mail_user_deinit): assertion failed: ((*user)->refcount == 1)" (JIRA:AlmaLinux-176273)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:8 / dovecot

Package

Name
dovecot
Purl
pkg:rpm/almalinux/dovecot

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1:2.3.16-16.el8_10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:76763.json"

AlmaLinux:8 / dovecot-devel

Package

Name
dovecot-devel
Purl
pkg:rpm/almalinux/dovecot-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1:2.3.16-16.el8_10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:76763.json"

AlmaLinux:8 / dovecot-mysql

Package

Name
dovecot-mysql
Purl
pkg:rpm/almalinux/dovecot-mysql

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1:2.3.16-16.el8_10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:76763.json"

AlmaLinux:8 / dovecot-pgsql

Package

Name
dovecot-pgsql
Purl
pkg:rpm/almalinux/dovecot-pgsql

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1:2.3.16-16.el8_10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:76763.json"

AlmaLinux:8 / dovecot-pigeonhole

Package

Name
dovecot-pigeonhole
Purl
pkg:rpm/almalinux/dovecot-pigeonhole

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1:2.3.16-16.el8_10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:76763.json"