This update for dovecot24 fixes the following issues:
Update to 2.4.5.
submission-login: panic when mail_max_userip_connections is reached (bsc#1276794).managesieve-login: pre-auth crash (bsc#1276809).dsync: mail content can cause dsync protocol injection (bsc#1276800).LIST match_sub() exponential backtracking leading to CPU denial of service (bsc#1276795).pigeonhole ManageSieve CHECKSCRIPT/PUTSCRIPT (bsc#1276807).imap-hibernate can be crashed (bsc#1276812).strmap (bsc#1276813).lda_mailbox_autocreate can bypass ACL restrictions (bsc#1276819).passdb scope enforcement bypass via OR semantics in remote validation path (bsc#1276820).sieve editheader RCE (bsc#1276817).XCLIENT FORWARD= bare token not namespaced (bsc#1276824).imap: pre-login memory/CPU growth with ID command (bsc#1276835).imap-urlauth leaks memory into user-visible error messages (bsc#1276829).doveadm_password or api key length can be leaked with timing comparisons (bsc#1276827).imap: COMPRESS ZSTD can cause excessive memory usage (bsc#1276837).XCLIENT FORWARD payload crashes (bsc#1276826).sieve resource usage tracking lost when active script changes (bsc#1276828).auth: db-oauth2: aud claim used as fallback for missing scope claim (bsc#1276830).imap-login crash due to self-recursion on zero-output decompress chunks (bsc#1276833).{
"binaries": [
{
"dovecot24": "2.4.4-160000.2.1",
"dovecot24-backend-mysql": "2.4.4-160000.2.1",
"dovecot24-backend-pgsql": "2.4.4-160000.2.1",
"dovecot24-backend-sqlite": "2.4.4-160000.2.1",
"dovecot24-devel": "2.4.4-160000.2.1",
"dovecot24-fts": "2.4.4-160000.2.1",
"dovecot24-fts-flatcurve": "2.4.4-160000.2.1",
"dovecot24-fts-solr": "2.4.4-160000.2.1"
}
]
}