-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 18 May 2026 16:03:51 -0400 Source: dovecot Binary: dovecot-auth-lua dovecot-auth-lua-dbgsym dovecot-core dovecot-core-dbgsym dovecot-dev dovecot-flatcurve dovecot-flatcurve-dbgsym dovecot-gssapi dovecot-gssapi-dbgsym dovecot-imapd dovecot-imapd-dbgsym dovecot-ldap dovecot-ldap-dbgsym dovecot-lmtpd dovecot-lmtpd-dbgsym dovecot-managesieved dovecot-managesieved-dbgsym dovecot-mysql dovecot-mysql-dbgsym dovecot-pgsql dovecot-pgsql-dbgsym dovecot-pop3d dovecot-pop3d-dbgsym dovecot-sieve dovecot-sieve-dbgsym dovecot-solr dovecot-solr-dbgsym dovecot-sqlite dovecot-sqlite-dbgsym dovecot-submissiond dovecot-submissiond-dbgsym Architecture: amd64 Version: 1:2.4.1+dfsg1-6+deb13u6 Distribution: trixie-security Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: Noah Meyerhans Description: dovecot-auth-lua - secure POP3/IMAP server - Lua authentication plugin dovecot-core - secure POP3/IMAP server - core files dovecot-dev - secure POP3/IMAP server - header files dovecot-flatcurve - secure POP3/IMAP server - Flatcurve support dovecot-gssapi - secure POP3/IMAP server - GSSAPI support dovecot-imapd - secure POP3/IMAP server - IMAP daemon dovecot-ldap - secure POP3/IMAP server - LDAP support dovecot-lmtpd - secure POP3/IMAP server - LMTP server dovecot-managesieved - secure POP3/IMAP server - ManageSieve server dovecot-mysql - secure POP3/IMAP server - MySQL support dovecot-pgsql - secure POP3/IMAP server - PostgreSQL support dovecot-pop3d - secure POP3/IMAP server - POP3 daemon dovecot-sieve - secure POP3/IMAP server - Sieve filters support dovecot-solr - secure POP3/IMAP server - Solr support dovecot-sqlite - secure POP3/IMAP server - SQLite support dovecot-submissiond - secure POP3/IMAP server - mail submission agent Closes: 1136444 Changes: dovecot (1:2.4.1+dfsg1-6+deb13u6) trixie-security; urgency=medium . * Security update (Closes: #1136444) * [76ceed4] CVE-2026-27851: lib-var-expand: Reset safe state when transfer is unset * [4af6fb3] CVE-2026-40016: lib-sieve: Enforce CPU time limit within :contains and :matches matcher loops * [366ef61] CVE-2026-33603: login-common: Only accept base64 in sasl * [26bd41e] CVE-2026-40020: IMAP folders can be shared-spammed to everyone. * [b6f5bac] CVE-2026-42006: imap-login: Excessive memory usage DoS Checksums-Sha1: 2f58f507cef44b279b30727d8b6b4da8abb59ab4 32652 dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 86a78c7112041a738ec07203dc7154db84d3478e 22072 dovecot-auth-lua_2.4.1+dfsg1-6+deb13u6_amd64.deb 3dd501bc0a878b6592c8a2857569c374fd1ec906 11130932 dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb d1fc5d11b8bd55a0c069c27caf8c92ead30d8866 2715988 dovecot-core_2.4.1+dfsg1-6+deb13u6_amd64.deb a4eb67ce6694f3a48ab759ed07f785cc11d732d9 429424 dovecot-dev_2.4.1+dfsg1-6+deb13u6_amd64.deb 922b450ec74624a835a21205c0e32a983b8572e5 190568 dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 599bb3cb8bf45d8c26173e15c3b76a9115bd8d73 42548 dovecot-flatcurve_2.4.1+dfsg1-6+deb13u6_amd64.deb d9d7949d566c9001058d66f3b2c0eab2b9a3bbc8 21212 dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 8cbe178cffa9f340861951baedc7f2f215fc7386 18396 dovecot-gssapi_2.4.1+dfsg1-6+deb13u6_amd64.deb 82e7a07088ad43b40af2c345f8baa388a93ccb5f 825856 dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb a6aa0530ce5b1808bcb8e2223c7ce1807ad036dd 195012 dovecot-imapd_2.4.1+dfsg1-6+deb13u6_amd64.deb aa73ea0f672663286bbc637cb3a9c54dd7fa11e4 195240 dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb b95edde40d53cdce3bb8bda77eebb67cb23bde4f 53876 dovecot-ldap_2.4.1+dfsg1-6+deb13u6_amd64.deb 03a17512622a13c87ddc4c9d32a22cf28644c4d6 101804 dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb f309850c98219d83e29e65cdf57dd5a15c7840a2 36700 dovecot-lmtpd_2.4.1+dfsg1-6+deb13u6_amd64.deb 2f4867cc2317be68160852af1257b5fb608ff52c 127712 dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 0784129f72dedba49e3b224e8fb74c28baf412c3 48636 dovecot-managesieved_2.4.1+dfsg1-6+deb13u6_amd64.deb 125c65875768573c1454eefe8f1cd875aeb38411 35352 dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 95aadd4abc1d1068afed9423f0b35a90df154e67 20992 dovecot-mysql_2.4.1+dfsg1-6+deb13u6_amd64.deb 2a7a4a8f4cddde9e316e3a38b6f0709b9b3cc338 39128 dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 27f084740189a331fef05edfda8c67aec343c1e4 25044 dovecot-pgsql_2.4.1+dfsg1-6+deb13u6_amd64.deb cd3143ca463178717aa7cd3dcffbda927db2c0d1 106880 dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb d36dad1641c0a027db0456f1ad5f46d42aaa532a 45044 dovecot-pop3d_2.4.1+dfsg1-6+deb13u6_amd64.deb f8cbb7631b3b4d1aa8b4a4388798eba6d7573d5f 1767256 dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb d656ffc0e426854ba7d5bb87053356196df38d57 382236 dovecot-sieve_2.4.1+dfsg1-6+deb13u6_amd64.deb c847dc3a00b62fc6687aab19022e5b460584302a 75344 dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb b20ea056fdb6aefc728a5f163ea157fa3deb2d77 38048 dovecot-solr_2.4.1+dfsg1-6+deb13u6_amd64.deb f19843ad6e19f42d3a4819b6ef48d575159d5b1d 24672 dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 66e8f2130b62789ac5f6f3f7ce90fdd606a79512 20068 dovecot-sqlite_2.4.1+dfsg1-6+deb13u6_amd64.deb 9d784c26bd89ece1b33ac3f5d1d8a967ea8c6598 213664 dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 3f95ed7c24e19125d58521edf64b003a6004001c 61520 dovecot-submissiond_2.4.1+dfsg1-6+deb13u6_amd64.deb c63aa161f09371c9bdc24374c965f7b785a6a270 18071 dovecot_2.4.1+dfsg1-6+deb13u6_amd64-buildd.buildinfo Checksums-Sha256: 6a6cd0764487508ae0544f04b60c0833c16fdc333d37578983e6410e9f2c8465 32652 dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 4b97c2651e495fac954bfa682357ad018a65759cbdcdf88cf88386a39399b86d 22072 dovecot-auth-lua_2.4.1+dfsg1-6+deb13u6_amd64.deb c3a1d096fa37db9c3ea6f56efae7bbc726d6927ff660fe7f92ddb0b6064bb34f 11130932 dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 7ff34fbd2268d06614f8d92fd745cb7cf158e3c89b255ca26adb09ac393813ba 2715988 dovecot-core_2.4.1+dfsg1-6+deb13u6_amd64.deb 4878e30634d9911668f76240d332a95b3d6046def8a39b6486f134c77cc518e2 429424 dovecot-dev_2.4.1+dfsg1-6+deb13u6_amd64.deb 4b73bbfc8058ec4c3d19875cf715b2008cc275728939471c6798523885012962 190568 dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 3104844cec58a12ec7583a5a7dd746ea9f162c33af17e91ea11f5100e809beb4 42548 dovecot-flatcurve_2.4.1+dfsg1-6+deb13u6_amd64.deb 6e80dc42f0d1ac7ff7be90b8f03ba42b9f5b9dbe56aa28f6775757bd871b0e89 21212 dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 6903c5c591efb06a5d7722c7a04e8ce42e6d5c640acc7c67283818846a22b3f7 18396 dovecot-gssapi_2.4.1+dfsg1-6+deb13u6_amd64.deb c3b934f3ad43e21bd04da30be0074be9c9b9e4c82149478a9e4292cc2f1aa08f 825856 dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 96ea63acacb22295f495ada3efbc6d900a1d26254cc687dc7fef838f5beabb0d 195012 dovecot-imapd_2.4.1+dfsg1-6+deb13u6_amd64.deb 183c56a631c211f6e5930e681343a077afdbaf6913538e34234df69408efc3fb 195240 dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 1871c7ba36403ce6eefde029d4da97f463959830cdd1164b8db93ec1b9c9761a 53876 dovecot-ldap_2.4.1+dfsg1-6+deb13u6_amd64.deb 65699ca2b8cf9bc6576d096d6299846fc71010bd08c84b9e41149e186b556ca4 101804 dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 215a68eb9bfb9a4415b139c47a4585a28fbba344ebe6a28ea91cefcd759946af 36700 dovecot-lmtpd_2.4.1+dfsg1-6+deb13u6_amd64.deb 6833ddcf313c05e6b7ce0c00f7a14659220c995e3f596b6cd6654cbe8f41623c 127712 dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 30edcc807f9c919770bd3f8ff7db680979a026ec4ef7c4bca05508bb8377f5f9 48636 dovecot-managesieved_2.4.1+dfsg1-6+deb13u6_amd64.deb db5890f6bde10a87fedc5ee399edca421d37ae8c43119e1e5700c27301312cdd 35352 dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 6738f19b80cf8f65e7cd86bd14c25119af8ea2e82f02a6920601258f14fac977 20992 dovecot-mysql_2.4.1+dfsg1-6+deb13u6_amd64.deb 3224c20d1e2d986228584d7cad7b94b7cadbfb2f9a479ae6e9866b4c535ce861 39128 dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 5b410835631f86b42e3b4a623565c73ed31473ac986e7cd3c9292f5a63bc8449 25044 dovecot-pgsql_2.4.1+dfsg1-6+deb13u6_amd64.deb 7a31ebb352595041d445e58c64c245ff2ca3c70c016bf976754a78d401ed63f3 106880 dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 4a11db89cc24ed3727e5886177b2712439c8e09536fdbc59394e20cbd1b7e52f 45044 dovecot-pop3d_2.4.1+dfsg1-6+deb13u6_amd64.deb df30d8b2a10d03364ecb01354f402ec40247eecfc2c8e9c416df7bf9b9ed3ca8 1767256 dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 3d227d630aa5407ab15f86ad594cfcbaeaa931285dcd60803a5a752fc1d61833 382236 dovecot-sieve_2.4.1+dfsg1-6+deb13u6_amd64.deb 5fd41ee023560e4a44afd5a58720ba4215194aebd9cdea566bcce059d8940814 75344 dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 74acb45e4e6ae0fe1cdda1d7861db80e6f096fc0fcc58ab59a783cc5fb2f87bd 38048 dovecot-solr_2.4.1+dfsg1-6+deb13u6_amd64.deb 0a7326279a5ec18073f794aaccc91d2a6ade5ab1200da858ee81d5de4111d9cc 24672 dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb ff0aaf3866702876b11ca15bff4530ee968f2f84413e7aad94c6d290d52fa5e3 20068 dovecot-sqlite_2.4.1+dfsg1-6+deb13u6_amd64.deb d2861a288ced334f1796e07df1154da878cb82baa1fcae608d03746277d1adaa 213664 dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 7710a73e5b700f2ec01e98479894229cbe4c1df88ad5e8e67dccf05275e135ad 61520 dovecot-submissiond_2.4.1+dfsg1-6+deb13u6_amd64.deb cd905936cd686f223b1154b7cc174f13a867a9240bffc81aed5c67c85ff22899 18071 dovecot_2.4.1+dfsg1-6+deb13u6_amd64-buildd.buildinfo Files: e46bcb14b21710840343db08d3b3afa6 32652 debug optional dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 2d9368f0958275da8fde3f0d232b2769 22072 mail optional dovecot-auth-lua_2.4.1+dfsg1-6+deb13u6_amd64.deb 7aa205057323c0f2960eb932959d8e0d 11130932 debug optional dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 2134b2574c73d2d7d3c0663d85d02e4a 2715988 mail optional dovecot-core_2.4.1+dfsg1-6+deb13u6_amd64.deb b8cd15b7e26626629781f0482355a7bc 429424 mail optional dovecot-dev_2.4.1+dfsg1-6+deb13u6_amd64.deb 1c526848ac1278abcccb3f84aed2a467 190568 debug optional dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 130b74b1ece72a9a201cfee7d70592a0 42548 mail optional dovecot-flatcurve_2.4.1+dfsg1-6+deb13u6_amd64.deb e7493df42c8f27ea90d2c0abeea010c1 21212 debug optional dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb ff2297eeab374f33bf577c7c88a4d078 18396 mail optional dovecot-gssapi_2.4.1+dfsg1-6+deb13u6_amd64.deb ce46f0cfb6405d4e4378938cf4486053 825856 debug optional dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb ff6741158797541f204845d772487d49 195012 mail optional dovecot-imapd_2.4.1+dfsg1-6+deb13u6_amd64.deb 52170481f6a45c202510b0b0d770b097 195240 debug optional dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb ec4de8ebb6e814c438753d7d85851c68 53876 mail optional dovecot-ldap_2.4.1+dfsg1-6+deb13u6_amd64.deb 6c40346e32381918e612d56085a8a826 101804 debug optional dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb dc53fd74281548e7e0798f2f1ad20fd1 36700 mail optional dovecot-lmtpd_2.4.1+dfsg1-6+deb13u6_amd64.deb ef03208674c4a063bc73bd13b4c9a4f1 127712 debug optional dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 1993caefe3da606d225bf82c2a15e43c 48636 mail optional dovecot-managesieved_2.4.1+dfsg1-6+deb13u6_amd64.deb 93bff399994daa4f796a8f9daa23f070 35352 debug optional dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 30c3b550d6de61a0b82bd6e0e3754287 20992 mail optional dovecot-mysql_2.4.1+dfsg1-6+deb13u6_amd64.deb 86a10a9df17171cb27bc62375681ef75 39128 debug optional dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb f049d8706c9aa985a1e1103dc214d273 25044 mail optional dovecot-pgsql_2.4.1+dfsg1-6+deb13u6_amd64.deb 87c97e3f015dc8bf9a933cc2745d4766 106880 debug optional dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb aa58a8e5a3911603089b3f1704ca3f72 45044 mail optional dovecot-pop3d_2.4.1+dfsg1-6+deb13u6_amd64.deb 0baca52e40a91a7bc2656c62d4150998 1767256 debug optional dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 4aa0f4bdd186659d7825439bf9ccd8fc 382236 mail optional dovecot-sieve_2.4.1+dfsg1-6+deb13u6_amd64.deb 70e643159e5e7c49a5c50220e2259497 75344 debug optional dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb d8f5a511dd46590021f053143108ba79 38048 mail optional dovecot-solr_2.4.1+dfsg1-6+deb13u6_amd64.deb 5f72dad8bc09fecfedce81c8de702137 24672 debug optional dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 1c91bd0b4b6ff3fe20bc1bf414581a68 20068 mail optional dovecot-sqlite_2.4.1+dfsg1-6+deb13u6_amd64.deb f0dcbc064db198d880a7d41bf5a24533 213664 debug optional dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u6_amd64.deb 022bb54f3f742ef070e910769e919673 61520 mail optional dovecot-submissiond_2.4.1+dfsg1-6+deb13u6_amd64.deb f09c800f77e39030c76d7c2078b59c0a 18071 mail optional dovecot_2.4.1+dfsg1-6+deb13u6_amd64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBDWXQb2umOtH4DRpYg9P9sm2dfEFAmoZ87wACgkQYg9P9sm2 dfFhThAAlGkuBrXgAUuyOnZnCiot7VCC083i9GMegAfxBrpmDd6BYx5IjT5r/rHh 7f7/WgHlAq1g5imzFwuXtIaxJwOqheMtZ5gJRQLqmQaQvrJEMbpTo24fqVVgn1xn 9PrAa3OXW+16QF7RinNEp7y/2DwDwX7cuVJ0Lt7EyVrTd/h8n3TGXroGzJx7nxkw eVWqLUNq0du+sx+/gDRCelqc/CkteLbvX0LL5lSFlO6xVEWcC4Pvmk+UaxfAhbJb RAYOXaGwin8JEfey+YlOyKqbJ0UzVCFLOo8W21rF3aM6lt5qFCiwxXiFEr5s3gHC 6ortDVIumIeIYxYsGTjDErfmoTv0ypKxZuY4CCz+TpcEx66L1G8zwOcAGitoWnZM DDD/8NoJ2CLCWYXuVvY9/QtA/2SmmsilDpgv2afwcxPMhy27/UkBIWTWtF+kYoh1 9tKXy80LLacCX4AdtwESjxkjiqH0oIsh9a4yOwEwnachnsIuBvqo0s/g/cM0+d2h LHAx5JxhB1djb0imr4fHl1jx1ixJQg5uTC+AYut1iuHVLPCNjqXN4pg6Nk80Innd V1BtfrUqTZ77FKGnOqAj3a4KDYWiAP5AgKwUfIDhmL1f2OelOr0Gam1oKDJhGV6r 1ILtpj7Gq5eABMdyOtkbzrwYyTGFZ0PYWWgqXNl4jl9CgLkz7ng= =LuL1 -----END PGP SIGNATURE-----