RLSA-2026:76763

Source
https://errata.rockylinux.org/RLSA-2026:76763
Import Source
https://storage.googleapis.com/resf-osv-data/RLSA-2026:76763.json
JSON Data
https://api.osv.dev/v1/vulns/RLSA-2026:76763
Upstream
CVE (8)
  • CVE-2026-27852
  • CVE-2026-33263
  • CVE-2026-33605
  • CVE-2026-40018
  • CVE-2026-40019
  • CVE-2026-42007
  • CVE-2026-42391
  • CVE-2026-73208
Published
2026-10-07T06:01:37Z
Modified
2026-10-07T06:30:02Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H CVSS Calculator
Summary
Important: dovecot security, bug fix, and enhancement update
Details

Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages.

Security Fix(es):

  • dovecot: Dovecot: Denial of Service via IMAP ID command with excessive parameters (CVE-2026-42391)

  • dovecot: Dovecot: Authentication bypass via incorrect OAuth2 token validation (CVE-2026-73208)

  • dovecot: Dovecot: Denial of service via crafted email headers (CVE-2026-27852)

  • dovecot: Dovecot: Denial of Service via truncated quoted argument in ManageSieve (CVE-2026-40019)

  • dovecot: Dovecot: Denial of Service and potential message duplication via connection limit exhaustion (CVE-2026-33263)

  • dovecot: Dovecot: Denial of Service in ManageSieve login process (CVE-2026-33605)

  • dovecot: Dovecot: Arbitrary Code Execution via Sieve editheader use-after-free (CVE-2026-42007)

  • dovecot: Dovecot: MySQL multi-byte escaping wrong (CVE-2026-40018)

Bug Fix(es) and Enhancement(s):

  • Dovecot crashes when accessing mailbox with: "Panic: file mail-user.c: line 229 (mail_user_deinit): assertion failed: ((*user)->refcount == 1)" (JIRA:Rocky Linux-176273)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Database specific
{
    "license": "CC-BY-4.0",
    "license_url": "https://creativecommons.org/licenses/by/4.0/",
    "source_advisory": "RHSA-2026:76763"
}
References
Credits
    • Rocky Enterprise Software Foundation
    • Red Hat

Affected packages

Rocky Linux:8 / dovecot

Package

Name
dovecot
Purl
pkg:rpm/rocky-linux/dovecot?distro=rocky-linux-8&epoch=1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1:2.3.16-16.el8_10
Database specific
Show details
{
    "yum_repository": "AppStream"
}

Database specific

source
"https://storage.googleapis.com/resf-osv-data/RLSA-2026:76763.json"