openSUSE-SU-2026:21720-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21720-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21720-1
Upstream
  • CVE-2026-27852
  • CVE-2026-33263
  • CVE-2026-33604
  • CVE-2026-33605
  • CVE-2026-33606
  • CVE-2026-33607
  • CVE-2026-40013
  • CVE-2026-40014
  • CVE-2026-40015
  • CVE-2026-40017
  • CVE-2026-40018
  • CVE-2026-40203
  • CVE-2026-40204
  • CVE-2026-40205
  • CVE-2026-42007
  • CVE-2026-42008
  • CVE-2026-42391
  • CVE-2026-42392
  • CVE-2026-42393
  • CVE-2026-42395
  • CVE-2026-52681
  • CVE-2026-52687
  • CVE-2026-73208
  • CVE-2026-73209
Related
  • CVE-2026-27852
  • CVE-2026-33263
  • CVE-2026-33604
  • CVE-2026-33605
  • CVE-2026-33606
  • CVE-2026-33607
  • CVE-2026-40013
  • CVE-2026-40014
  • CVE-2026-40015
  • CVE-2026-40017
  • CVE-2026-40018
  • CVE-2026-40203
  • CVE-2026-40204
  • CVE-2026-40205
  • CVE-2026-42007
  • CVE-2026-42008
  • CVE-2026-42391
  • CVE-2026-42392
  • CVE-2026-42393
  • CVE-2026-42395
  • CVE-2026-52681
  • CVE-2026-52687
  • CVE-2026-73208
  • CVE-2026-73209
Published
2026-09-01T14:18:02Z
Modified
2026-09-02T18:00:03Z
Summary
Security update for dovecot24
Details

This update for dovecot24 fixes the following issues:

Update to 2.4.5.

  • CVE-2026-33263: submission-login: panic when mail_max_userip_connections is reached (bsc#1276794).
  • CVE-2026-27852: DoS by sending mail with bad header (bsc#1276799).
  • CVE-2026-33604: SMTP smuggling via missing dot-stuffing after bare carriage return (bsc#1276802).
  • CVE-2026-33605: managesieve-login: pre-auth crash (bsc#1276809).
  • CVE-2026-33606: dsync: mail content can cause dsync protocol injection (bsc#1276800).
  • CVE-2026-33607: IMAP LIST match_sub() exponential backtracking leading to CPU denial of service (bsc#1276795).
  • CVE-2026-40013: stack buffer underflow in pigeonhole ManageSieve CHECKSCRIPT/PUTSCRIPT (bsc#1276807).
  • CVE-2026-40014: CPU DoS via crafted references header (bsc#1276804).
  • CVE-2026-40015: imap-hibernate can be crashed (bsc#1276812).
  • CVE-2026-40017: CPU DoS via CRC32 hash collision in strmap (bsc#1276813).
  • CVE-2026-40018: MySQL multi-byte escaping performed incorrectly (bsc#1276810).
  • CVE-2026-40203: IMAP compression can reveal whether a small synced email body matches sender-chosen text (bsc#1276815).
  • CVE-2026-40204: lda_mailbox_autocreate can bypass ACL restrictions (bsc#1276819).
  • CVE-2026-40205: OAuth2 passdb scope enforcement bypass via OR semantics in remote validation path (bsc#1276820).
  • CVE-2026-42007: sieve editheader RCE (bsc#1276817).
  • CVE-2026-42008: XCLIENT FORWARD= bare token not namespaced (bsc#1276824).
  • CVE-2026-42391: imap: pre-login memory/CPU growth with ID command (bsc#1276835).
  • CVE-2026-42392: imap-urlauth leaks memory into user-visible error messages (bsc#1276829).
  • CVE-2026-42393: doveadm_password or api key length can be leaked with timing comparisons (bsc#1276827).
  • CVE-2026-52687: imap: COMPRESS ZSTD can cause excessive memory usage (bsc#1276837).
  • CVE-2026-42395: single NUL-byte XCLIENT FORWARD payload crashes (bsc#1276826).
  • CVE-2026-52681: sieve resource usage tracking lost when active script changes (bsc#1276828).
  • CVE-2026-73208: auth: db-oauth2: aud claim used as fallback for missing scope claim (bsc#1276830).
  • CVE-2026-73209: imap-login crash due to self-recursion on zero-output decompress chunks (bsc#1276833).
References

Affected packages

openSUSE:Leap 16.0 / dovecot24

Package

Name
dovecot24
Purl
pkg:rpm/opensuse/dovecot24&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.4-160000.2.1

Ecosystem specific

{
    "binaries": [
        {
            "dovecot24": "2.4.4-160000.2.1",
            "dovecot24-backend-mysql": "2.4.4-160000.2.1",
            "dovecot24-backend-pgsql": "2.4.4-160000.2.1",
            "dovecot24-backend-sqlite": "2.4.4-160000.2.1",
            "dovecot24-devel": "2.4.4-160000.2.1",
            "dovecot24-fts": "2.4.4-160000.2.1",
            "dovecot24-fts-flatcurve": "2.4.4-160000.2.1",
            "dovecot24-fts-solr": "2.4.4-160000.2.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21720-1.json"