SUSE-SU-2026:4139-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264139-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4139-1
Upstream
CVE (34)
Related
Published
2026-09-14T07:22:32Z
Modified
2026-09-28T18:23:12Z
Summary
Security update for dovecot23
Details

This update for dovecot23 fixes the following issues:

  • CVE-2024-23184: parsing of messages containing many address headers (From, To, Cc, Bcc, etc.) could be excessively CPU intensive (bsc#1229184).
  • CVE-2024-23185: large headers can cause resource exhaustion when parsing message (bsc#1229183).
  • CVE-2025-59028: Invalid base64 authentication can cause DoS for other logins (bsc#1260894).
  • CVE-2025-59031: decode2text.sh OOXML extraction may follow symlinks and read unintended files during indexing (bsc#1260895).
  • CVE-2025-59032: pigeonhole: ManageSieve panic occurs with sieve-connect as a client (bsc#1260902).
  • CVE-2026-27852: DoS by sending mail with bad header (bsc#1276799).
  • CVE-2026-27855: OTP driver vulnerable to replay attack (bsc#1260900).
  • CVE-2026-27856: Doveadm credentials were not checked using timing-safe checking function (bsc#1260899).
  • CVE-2026-27857: sending excessive parenthesis causes imap-login to use excessive memory (bsc#1260898).
  • CVE-2026-27858: pigeonhole: managesieve-login can allocate large amount of memory during authentication (bsc#1260901).
  • CVE-2026-27859: excessive RFC 2231 MIME parameters in email would can excessive CPU usage (bsc#1260897).
  • CVE-2026-33263: submission-login: Panic when mail_max_userip_connections is reached (bsc#1276794).
  • CVE-2026-33603: login: base64 input can contain tabs that bypass IPC protection (bsc#1265147).
  • CVE-2026-33604: SMTP Smuggling via Missing Dot-Stuffing (bsc#1276802).
  • CVE-2026-33605: managesieve-login: Pre-auth crash (bsc#1276809).
  • CVE-2026-33606: dsync: Mail content can cause dsync protocol injection (bsc#1276800).
  • CVE-2026-33607: IMAP LIST match_sub() Exponential Backtracking -- CPU Denial of Service (bsc#1276795).
  • CVE-2026-40014: CPU DoS via Crafted References Header (bsc#1276804).
  • CVE-2026-40015: imap-hibernate can be crashed (bsc#1276812).
  • CVE-2026-40016: Sieve :contains/:matches O(NxM) substring match bypasses sieve_max_cpu_time limit (bsc#1265148).
  • CVE-2026-40019: managesieve-login pre-auth infinite loop (bsc#1276811).
  • CVE-2026-40020: IMAP folders can be shared-spammed to everyone (bsc#1265149).
  • CVE-2026-40203: IMAP Compression Can Reveal Whether a Small Synced Email Body Matches Sender-Chosen Text (bsc#1276815).
  • CVE-2026-40205: OAuth2 passdb scope enforcement bypass via OR semantics in remote validation path (bsc#1276820).
  • CVE-2026-42006: imap-login: uncontrolled memory usage with excessive bracing over IMAP (bsc#1265150).
  • CVE-2026-42007: editheader RCE (bsc#1276817).
  • CVE-2026-42008: XCLIENT FORWARD= bare token not namespaced (bsc#1276824).
  • CVE-2026-42391: imap: Pre-login memory/CPU growth with ID command (bsc#1276835).
  • CVE-2026-42393: doveadm_password or api key length can still be leaked with timing comparisons (bsc#1276827).
  • CVE-2026-42395: Single NUL-Byte XCLIENT FORWARD Payload Crashes (bsc#1276826).
  • CVE-2026-52681: Sieve resource usage tracking lost when active script changes (bsc#1276828).
  • CVE-2026-52687: IMAP: COMPRESS ZSTD can cause excessive memory usage (bsc#1276837).
  • CVE-2026-73208: auth: db-oauth2: aud claim used as fallback for missing scope claim (bsc#1276830).
  • CVE-2026-73209: imap-login crash: Self-recursion on zero-output decompress chunks (bsc#1276833).

Changes for dovecot23:

  • Update to version 2.3.21.1.
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
dovecot23

Package

Name
dovecot23
Purl
pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.3.21.1-150200.76.1

Ecosystem specific

{
    "binaries":  [
        {
            "dovecot23":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-mysql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-pgsql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-sqlite":  "2.3.21.1-150200.76.1",
            "dovecot23-devel":  "2.3.21.1-150200.76.1",
            "dovecot23-fts":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-lucene":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-solr":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-squat":  "2.3.21.1-150200.76.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
dovecot23

Package

Name
dovecot23
Purl
pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.3.21.1-150200.76.1

Ecosystem specific

{
    "binaries":  [
        {
            "dovecot23":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-mysql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-pgsql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-sqlite":  "2.3.21.1-150200.76.1",
            "dovecot23-devel":  "2.3.21.1-150200.76.1",
            "dovecot23-fts":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-lucene":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-solr":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-squat":  "2.3.21.1-150200.76.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
dovecot23

Package

Name
dovecot23
Purl
pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.3.21.1-150200.76.1

Ecosystem specific

{
    "binaries":  [
        {
            "dovecot23":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-mysql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-pgsql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-sqlite":  "2.3.21.1-150200.76.1",
            "dovecot23-devel":  "2.3.21.1-150200.76.1",
            "dovecot23-fts":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-lucene":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-solr":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-squat":  "2.3.21.1-150200.76.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
dovecot23

Package

Name
dovecot23
Purl
pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.3.21.1-150200.76.1

Ecosystem specific

{
    "binaries":  [
        {
            "dovecot23":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-mysql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-pgsql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-sqlite":  "2.3.21.1-150200.76.1",
            "dovecot23-devel":  "2.3.21.1-150200.76.1",
            "dovecot23-fts":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-lucene":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-solr":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-squat":  "2.3.21.1-150200.76.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"
SUSE:Linux Enterprise Module for Server Applications 15 SP7
dovecot23

Package

Name
dovecot23
Purl
pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.3.21.1-150200.76.1

Ecosystem specific

{
    "binaries":  [
        {
            "dovecot23":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-mysql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-pgsql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-sqlite":  "2.3.21.1-150200.76.1",
            "dovecot23-devel":  "2.3.21.1-150200.76.1",
            "dovecot23-fts":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-lucene":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-solr":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-squat":  "2.3.21.1-150200.76.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
dovecot23

Package

Name
dovecot23
Purl
pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.3.21.1-150200.76.1

Ecosystem specific

{
    "binaries":  [
        {
            "dovecot23":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-mysql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-pgsql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-sqlite":  "2.3.21.1-150200.76.1",
            "dovecot23-devel":  "2.3.21.1-150200.76.1",
            "dovecot23-fts":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-lucene":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-solr":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-squat":  "2.3.21.1-150200.76.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
dovecot23

Package

Name
dovecot23
Purl
pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.3.21.1-150200.76.1

Ecosystem specific

{
    "binaries":  [
        {
            "dovecot23":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-mysql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-pgsql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-sqlite":  "2.3.21.1-150200.76.1",
            "dovecot23-devel":  "2.3.21.1-150200.76.1",
            "dovecot23-fts":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-lucene":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-solr":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-squat":  "2.3.21.1-150200.76.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
dovecot23

Package

Name
dovecot23
Purl
pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.3.21.1-150200.76.1

Ecosystem specific

{
    "binaries":  [
        {
            "dovecot23":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-mysql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-pgsql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-sqlite":  "2.3.21.1-150200.76.1",
            "dovecot23-devel":  "2.3.21.1-150200.76.1",
            "dovecot23-fts":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-lucene":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-solr":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-squat":  "2.3.21.1-150200.76.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
dovecot23

Package

Name
dovecot23
Purl
pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.3.21.1-150200.76.1

Ecosystem specific

{
    "binaries":  [
        {
            "dovecot23":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-mysql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-pgsql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-sqlite":  "2.3.21.1-150200.76.1",
            "dovecot23-devel":  "2.3.21.1-150200.76.1",
            "dovecot23-fts":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-lucene":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-solr":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-squat":  "2.3.21.1-150200.76.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
dovecot23

Package

Name
dovecot23
Purl
pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.3.21.1-150200.76.1

Ecosystem specific

{
    "binaries":  [
        {
            "dovecot23":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-mysql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-pgsql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-sqlite":  "2.3.21.1-150200.76.1",
            "dovecot23-devel":  "2.3.21.1-150200.76.1",
            "dovecot23-fts":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-lucene":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-solr":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-squat":  "2.3.21.1-150200.76.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
dovecot23

Package

Name
dovecot23
Purl
pkg:rpm/suse/dovecot23&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.3.21.1-150200.76.1

Ecosystem specific

{
    "binaries":  [
        {
            "dovecot23":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-mysql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-pgsql":  "2.3.21.1-150200.76.1",
            "dovecot23-backend-sqlite":  "2.3.21.1-150200.76.1",
            "dovecot23-devel":  "2.3.21.1-150200.76.1",
            "dovecot23-fts":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-lucene":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-solr":  "2.3.21.1-150200.76.1",
            "dovecot23-fts-squat":  "2.3.21.1-150200.76.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4139-1.json"