SUSE-SU-2026:3919-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263919-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3919-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:3919-1
Upstream
CVE (14)
  • CVE-2026-27852
  • CVE-2026-33604
  • CVE-2026-33605
  • CVE-2026-33606
  • CVE-2026-33607
  • CVE-2026-40014
  • CVE-2026-40015
  • CVE-2026-40019
  • CVE-2026-40203
  • CVE-2026-42007
  • CVE-2026-42391
  • CVE-2026-42393
  • CVE-2026-52687
  • CVE-2026-73209
Related
Published
2026-09-02T07:31:54Z
Modified
2026-09-10T18:23:19Z
Summary
Security update for dovecot22
Details

This update for dovecot22 fixes the following issues:

Security issues fixed:

  • CVE-2026-27852: DoS by sending mail with bad header (bsc#1276799).
  • CVE-2026-33604: SMTP smuggling via missing dot-stuffing after bare carriage return (bsc#1276802).
  • CVE-2026-33605: managesieve-login: pre-auth crash (bsc#1276809).
  • CVE-2026-33606: dsync: mail content can cause dsync protocol injection (bsc#1276800).
  • CVE-2026-33607: IMAP LIST match_sub() exponential backtracking leading to CPU denial of service (bsc#1276795).
  • CVE-2026-40014: CPU DoS via crafted references header (bsc#1276804).
  • CVE-2026-40015: imap-hibernate can be crashed (bsc#1276812).
  • CVE-2026-40019: managesieve-login pre-auth infinite loop (bsc#1276811).
  • CVE-2026-40203: IMAP compression can reveal whether a small synced email body matches sender-chosen text (bsc#1276815).
  • CVE-2026-42007: sieve editheader RCE (bsc#1276817).
  • CVE-2026-42391: imap: pre-login memory/CPU growth with ID command (bsc#1276835).
  • CVE-2026-42393: doveadm_password or api key length can be leaked with timing comparisons (bsc#1276827).
  • CVE-2026-52687: imap: COMPRESS ZSTD can cause excessive memory usage (bsc#1276837).
  • CVE-2026-73209: imap-login crash due to self-recursion on zero-output decompress chunks (bsc#1276833).
  • multiple security fixes (bsc#1276792).

Other updates and bugfixes:

  • Non-CVE hardening taken from the same upstream release:
    • sieve: requiring the same extension repeatedly grew the default argument override chain, which is walked recursively - a crafted script could overflow the stack
    • sieve: ${unicode:...} hex values could overflow an unsigned int and wrap back into the valid Unicode range; the hex parser also read one byte past the end of the buffer
    • sieve variables: the ${1234...} numeric index overflowed a signed int
    • sieve enotify: a single script could emit an unlimited number of notification messages; limited to 10 as upstream does
References

Affected packages

SUSE:Linux Enterprise Server 12 SP5-LTSS / dovecot22

Package

Name
dovecot22
Purl
pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.31-19.40.1

Ecosystem specific

{
    "binaries":  [
        {
            "dovecot22":  "2.2.31-19.40.1",
            "dovecot22-backend-mysql":  "2.2.31-19.40.1",
            "dovecot22-backend-pgsql":  "2.2.31-19.40.1",
            "dovecot22-backend-sqlite":  "2.2.31-19.40.1",
            "dovecot22-devel":  "2.2.31-19.40.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3919-1.json"

SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5 / dovecot22

Package

Name
dovecot22
Purl
pkg:rpm/suse/dovecot22&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.31-19.40.1

Ecosystem specific

{
    "binaries":  [
        {
            "dovecot22":  "2.2.31-19.40.1",
            "dovecot22-backend-mysql":  "2.2.31-19.40.1",
            "dovecot22-backend-pgsql":  "2.2.31-19.40.1",
            "dovecot22-backend-sqlite":  "2.2.31-19.40.1",
            "dovecot22-devel":  "2.2.31-19.40.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3919-1.json"