-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 18 May 2026 16:03:51 -0400 Source: dovecot Binary: dovecot-auth-lua dovecot-auth-lua-dbgsym dovecot-core dovecot-core-dbgsym dovecot-dev dovecot-flatcurve dovecot-flatcurve-dbgsym dovecot-gssapi dovecot-gssapi-dbgsym dovecot-imapd dovecot-imapd-dbgsym dovecot-ldap dovecot-ldap-dbgsym dovecot-lmtpd dovecot-lmtpd-dbgsym dovecot-managesieved dovecot-managesieved-dbgsym dovecot-mysql dovecot-mysql-dbgsym dovecot-pgsql dovecot-pgsql-dbgsym dovecot-pop3d dovecot-pop3d-dbgsym dovecot-sieve dovecot-sieve-dbgsym dovecot-solr dovecot-solr-dbgsym dovecot-sqlite dovecot-sqlite-dbgsym dovecot-submissiond dovecot-submissiond-dbgsym Architecture: armel Version: 1:2.4.1+dfsg1-6+deb13u6 Distribution: trixie-security Urgency: medium Maintainer: armel Build Daemon (arm-conova-02) Changed-By: Noah Meyerhans Description: dovecot-auth-lua - secure POP3/IMAP server - Lua authentication plugin dovecot-core - secure POP3/IMAP server - core files dovecot-dev - secure POP3/IMAP server - header files dovecot-flatcurve - secure POP3/IMAP server - Flatcurve support dovecot-gssapi - secure POP3/IMAP server - GSSAPI support dovecot-imapd - secure POP3/IMAP server - IMAP daemon dovecot-ldap - secure POP3/IMAP server - LDAP support dovecot-lmtpd - secure POP3/IMAP server - LMTP server dovecot-managesieved - secure POP3/IMAP server - ManageSieve server dovecot-mysql - secure POP3/IMAP server - MySQL support dovecot-pgsql - secure POP3/IMAP server - PostgreSQL support dovecot-pop3d - secure POP3/IMAP server - POP3 daemon dovecot-sieve - secure POP3/IMAP server - Sieve filters support dovecot-solr - secure POP3/IMAP server - Solr support dovecot-sqlite - secure POP3/IMAP server - SQLite support dovecot-submissiond - secure POP3/IMAP server - mail submission agent Closes: 1136444 Changes: dovecot (1:2.4.1+dfsg1-6+deb13u6) trixie-security; urgency=medium . * Security update (Closes: #1136444) * [76ceed4] CVE-2026-27851: lib-var-expand: Reset safe state when transfer is unset * [4af6fb3] CVE-2026-40016: lib-sieve: Enforce CPU time limit within :contains and :matches matcher loops * [366ef61] CVE-2026-33603: login-common: Only accept base64 in sasl * [26bd41e] CVE-2026-40020: IMAP folders can be shared-spammed to everyone. * [b6f5bac] CVE-2026-42006: imap-login: Excessive memory usage DoS Checksums-Sha1: c4b4520aceae3bd665af725077b70b7bcca472a2 31984 dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb d5aa451316197e52865156043903d3fbd4d658cf 21480 dovecot-auth-lua_2.4.1+dfsg1-6+deb13u6_armel.deb a5350a7bbf8de0b060b70f82511b37ebdb245907 9680324 dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 8341cc377a849dd11e904e095e1b5b2d3453ed5b 2386284 dovecot-core_2.4.1+dfsg1-6+deb13u6_armel.deb 982d0dce33563359cef5ae0d63ef245f84b423e7 429488 dovecot-dev_2.4.1+dfsg1-6+deb13u6_armel.deb 74f80b9208b44466e869db0b624bd6f5c9fc1da0 185080 dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 76abdd185ba67dba521d23b7ca89815264170afc 38824 dovecot-flatcurve_2.4.1+dfsg1-6+deb13u6_armel.deb afc7fd47908671da024621658a9f32f5e23cedf5 21368 dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb b50c907a84e5ad5d3b7124fbca5955dcb010d4f0 17888 dovecot-gssapi_2.4.1+dfsg1-6+deb13u6_armel.deb 61919e01187d63006e6f0f5709144700149e1958 724740 dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb c5832b5db3be33eff4cb87ad9be9e16a17047091 172568 dovecot-imapd_2.4.1+dfsg1-6+deb13u6_armel.deb b6083216f55164f715f84139dd6de55e5dffedf5 164064 dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb e56b737c09c52b174dbc23473d101b2d312147f3 48592 dovecot-ldap_2.4.1+dfsg1-6+deb13u6_armel.deb aae961ff27be2c7bd06f4dcfb0f76c7a2e3f0e95 99740 dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 59cbb996724905dbc140046fd8bc8caf838f06ad 34556 dovecot-lmtpd_2.4.1+dfsg1-6+deb13u6_armel.deb 32aa90522a255eaaf5a5894ff7e047055564838a 115808 dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 706c8ccce707685af945f1b89f6272c1056002c2 44612 dovecot-managesieved_2.4.1+dfsg1-6+deb13u6_armel.deb 17cef65e926c92ab2b13a33c52a683afe6293791 35380 dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 953891568810cfa83469636ef0bf3224d38ed30f 19832 dovecot-mysql_2.4.1+dfsg1-6+deb13u6_armel.deb 7a461a196b4c800182cc15f15d84be03ca00eaae 38832 dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb d5beb2be5945cc7380acb6353d9a7ec29764c64c 23848 dovecot-pgsql_2.4.1+dfsg1-6+deb13u6_armel.deb 75788bb476248cde295de53d09336312457aa816 101956 dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb ecad1ecc44abcc44412c6974f7eebe93176320c8 41576 dovecot-pop3d_2.4.1+dfsg1-6+deb13u6_armel.deb 79d7815e06c8b8f0279e7616cb0566c16362188b 1651276 dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb de14475386993498ac2894a876c2e5a2464442fc 330836 dovecot-sieve_2.4.1+dfsg1-6+deb13u6_armel.deb 6821ba7c9d8064a667ca32323af5a5d3cbcfbe62 73856 dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 3353b5d6cacc4b8d3bdb9dab7668013318abec7a 36640 dovecot-solr_2.4.1+dfsg1-6+deb13u6_armel.deb dc7d21b1ce27928c5ae0e3dc0a54e6c6f5eae9a5 25112 dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 14718d3fd1ff60f6a7c31c471d29663f3967152a 19252 dovecot-sqlite_2.4.1+dfsg1-6+deb13u6_armel.deb 0f970698b6169250ad0ac20483a08c779d19800c 205196 dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 259c8a9535574e3c6db11a98c43f6c3b81b8e1cf 55856 dovecot-submissiond_2.4.1+dfsg1-6+deb13u6_armel.deb 4247ccddceb0fb4482761a7f91922d0454c8e76b 17917 dovecot_2.4.1+dfsg1-6+deb13u6_armel-buildd.buildinfo Checksums-Sha256: 2c209d78f82b913d7bab3e021677fd01d8e3b9566e48724d9a3f6355837ca900 31984 dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 0435827b8ca2fd3024986cb8c3888a4a9c5df361e38b4c649db4c0884b5793ed 21480 dovecot-auth-lua_2.4.1+dfsg1-6+deb13u6_armel.deb 961756d623d4126a2daab35506359e6001cd6a4ed3d6e752c06fd7ba3e7059b5 9680324 dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 7495ec3a7ef8e312d047709e73e6e2edc4e5385fb41acc1ec4c80489644817c9 2386284 dovecot-core_2.4.1+dfsg1-6+deb13u6_armel.deb 11911b8fba1458bbe726e392ddb230eb3ecdb19043912744c2484b3a51eb875a 429488 dovecot-dev_2.4.1+dfsg1-6+deb13u6_armel.deb c48beda695fa78e3f42e3bf88b9327d1b212e084580e26a4f9b06ea0976318fe 185080 dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 7b53f7ccb87d45b10db7455d41dfc13e5125a3894bb5ce50ade1fc793d05fdc1 38824 dovecot-flatcurve_2.4.1+dfsg1-6+deb13u6_armel.deb ad5209e4b3649fce3d505ee7e8725267c50aff3fff803d16194ebeae92dd3d3a 21368 dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb fcf937436cc80f670814c660e6e7d66bfa883487b866c714c512ff917a2fdc48 17888 dovecot-gssapi_2.4.1+dfsg1-6+deb13u6_armel.deb 17597dd53a61b267541fcdae9e495effd4de56aacf4048412cadcc30e22af3a7 724740 dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 3ab07b0a17d087bfac421a80a18f9061cc17dd9ff960cd1c8326a3807639c3d2 172568 dovecot-imapd_2.4.1+dfsg1-6+deb13u6_armel.deb 1d2b51d357ee52dbe00d702066495c9cc0118280d6888a902f9f2f2a46d583e2 164064 dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 3b8c9814061f8601c5e0cfb37179887d96240ee466c385c71a9e9c6b1f01f209 48592 dovecot-ldap_2.4.1+dfsg1-6+deb13u6_armel.deb 4c8138060b18fb0445a3bf16f8fb8f9cfabbe18551b57b369ed5963f84228aed 99740 dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 9d870506c6bd5247cc9907f9f8a3ed7d63053395f7841514ce3bd05650d0de0c 34556 dovecot-lmtpd_2.4.1+dfsg1-6+deb13u6_armel.deb 4b0fe0734a3b860ee67c075684a994875eada12ec0ca4ea16c5ab3e9bc5fdac4 115808 dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 442460ccd3d7fd9e56a7dfd4d4815165acda54a612b00abf0135ac1c59e02251 44612 dovecot-managesieved_2.4.1+dfsg1-6+deb13u6_armel.deb b5241a65274f1186cf9cc66a657cc3843525c323b2f9085f09410ade745eabdd 35380 dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb f4cf939e336f4e0dfa0f03535a299cbf7d1aa6dd3bc6861b95a8b6911ef24100 19832 dovecot-mysql_2.4.1+dfsg1-6+deb13u6_armel.deb ad2b882204a9c15e2d9e5ab6ee54f934dc03f0682ffaca71c08fdd742e1cc5e7 38832 dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb a40b30f6ff9c60fc3053a6a7fba9eb440c9e15e5471c4151a8b0c3ec08c2e2c6 23848 dovecot-pgsql_2.4.1+dfsg1-6+deb13u6_armel.deb d76aed42156963b3b9306db1d2e068444f77135f073a6eda816735ed76be052f 101956 dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 466673127ec842ca05dbee9a3e71e382bef92c036bad2b7816dd476f350d85db 41576 dovecot-pop3d_2.4.1+dfsg1-6+deb13u6_armel.deb 260dacbab80cc58d86d2d79cfb5abaf03e64427a91f2de07d4c83e03ae3f8ebb 1651276 dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 498642cd34263b9ac3ee1f47f449db7fc9cdd9bcfb3b84dd65130cf74b96aa79 330836 dovecot-sieve_2.4.1+dfsg1-6+deb13u6_armel.deb 425ee3cbf98533df0cf7c9452883ea7a43c7f8258b175d47c60077e0606273b6 73856 dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 55e04c01aa7a063d5c9eb6a61fef8730f5863866a65f7a711e4f570e471d9ab3 36640 dovecot-solr_2.4.1+dfsg1-6+deb13u6_armel.deb c4b150c020b7c496e68a8d450039c3776216f19e725ae1a94bfd0b9f43621ce2 25112 dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 2f2f24e60c1438c4d4f95b846ef073c561b5da49f81439b0499b05a45ae9b4f1 19252 dovecot-sqlite_2.4.1+dfsg1-6+deb13u6_armel.deb d759dd4459ac7a561e52e34cb4877abd9c2532569b92433fbdcfba89f73d3958 205196 dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 3002422dd49bd346d0f4638d557956eb7d40ea0c163eb224e4680f873aa0598e 55856 dovecot-submissiond_2.4.1+dfsg1-6+deb13u6_armel.deb a1a346ad5b9d0a9d61b60d69ca32617c7dd9228ac0c6769b04700d9dd7023a31 17917 dovecot_2.4.1+dfsg1-6+deb13u6_armel-buildd.buildinfo Files: 4919fa9d558b0c72f1ab2754a30bb9a9 31984 debug optional dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 75ed10f1e173624173339b5d424e97b7 21480 mail optional dovecot-auth-lua_2.4.1+dfsg1-6+deb13u6_armel.deb f66d35ac36885de3f9fdc77190d6a1f3 9680324 debug optional dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 6d3cbd2cfa83929a4b5239e10637b424 2386284 mail optional dovecot-core_2.4.1+dfsg1-6+deb13u6_armel.deb 1940b9559878138c659f46613b9e1143 429488 mail optional dovecot-dev_2.4.1+dfsg1-6+deb13u6_armel.deb ecbfd1ad54b25cda665747e67c6daa24 185080 debug optional dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb b1e95cdac63177d24e854b8344863961 38824 mail optional dovecot-flatcurve_2.4.1+dfsg1-6+deb13u6_armel.deb 2558abbe98767766af386034c7638f01 21368 debug optional dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 6a70f4ebcd62867bfdd8ccfb54783202 17888 mail optional dovecot-gssapi_2.4.1+dfsg1-6+deb13u6_armel.deb 86f888e6bdb5848ff88a734afb932ad3 724740 debug optional dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 12597532395dac583ef482ae42362572 172568 mail optional dovecot-imapd_2.4.1+dfsg1-6+deb13u6_armel.deb e69afc3316a0b29d6d1e6762099a9f49 164064 debug optional dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 71498f7738c5678937747a6ef9bdbc5a 48592 mail optional dovecot-ldap_2.4.1+dfsg1-6+deb13u6_armel.deb 40156f452b4480c5152c29a962e2736f 99740 debug optional dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 34ff761434b534a6f06a485739a59e52 34556 mail optional dovecot-lmtpd_2.4.1+dfsg1-6+deb13u6_armel.deb fce30d0676dc59fc8a75fc444a2dac29 115808 debug optional dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 3dba51fd619ad3bf4a5966a38237287a 44612 mail optional dovecot-managesieved_2.4.1+dfsg1-6+deb13u6_armel.deb 6afabd34d5f34ac807e953179e1d029b 35380 debug optional dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb ac805eec2e3ce072d254f0f703eff01b 19832 mail optional dovecot-mysql_2.4.1+dfsg1-6+deb13u6_armel.deb 97b3a7d07921860aaaa88f615d3c6923 38832 debug optional dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 04c1b87b764b6bc1404552cab1324652 23848 mail optional dovecot-pgsql_2.4.1+dfsg1-6+deb13u6_armel.deb 823192200391f928a40c7db60814ce99 101956 debug optional dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb eca70fd9c24cfe1b962b7e7c5ead4050 41576 mail optional dovecot-pop3d_2.4.1+dfsg1-6+deb13u6_armel.deb da45aaa36e1f1f9c6f7267291f4a1da8 1651276 debug optional dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb d7d015c121354eaa21a8a72376907bae 330836 mail optional dovecot-sieve_2.4.1+dfsg1-6+deb13u6_armel.deb 68229429243bba70ce84e143742b5db2 73856 debug optional dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 3e337cfd42a626e90cfd7fa04f78e43e 36640 mail optional dovecot-solr_2.4.1+dfsg1-6+deb13u6_armel.deb 4a766aff6731a7738efa7957c7a45b85 25112 debug optional dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb ce274244c3b1d70f33b9d1decbf8b679 19252 mail optional dovecot-sqlite_2.4.1+dfsg1-6+deb13u6_armel.deb 48b7a06cfbae0d0c32930029f8ea87d6 205196 debug optional dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u6_armel.deb 2855d7738cd5ccf1c80344d2b617bc11 55856 mail optional dovecot-submissiond_2.4.1+dfsg1-6+deb13u6_armel.deb 24d947a56524a90ac00565478ccfab4e 17917 mail optional dovecot_2.4.1+dfsg1-6+deb13u6_armel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEWHj9K9pO9l4btbD1OQKMdMnEH5MFAmoZ9LoACgkQOQKMdMnE H5PGwQ//SUbI/5ebvuyqLmQbewKVUS9EH1Mw/hY2yt2h1HGftEGqCX0O4omKPn7/ JyREMx0kN6aNs5X4JYM07pF/4phdPE3+DS5OVYhdsC+W0FHsKbYb+6+tE5lYEZBF ZyDMFva+EimpXlrkGdkuVc265q3BxttkvtuhfCV/gTBz7PLgmjay+cGotXG+ye4U gZHaMaHDTkWndMjAG/KOT39V1OBiQdEcfqo3Oy8X05dbphb2yDYonRE1WVL+mhe8 QFU6S7kWGIui192uZqLbMyXnioTH7m9IyYhvXfZjJLV70Vh2aWa5EHzGbIDR72l7 lAI0iUa/sTGVj/o/UND4p91ctJnUwgQDONHt7z87vC2VaSGP+cYcso6H9P8fk5E+ W2qcBr4NS9qbJB7lfwiRe/aLKNWCvBSJ2u37mpBh1C3cF1RReWJc0SOLeINsnPPE alaH4R1ysjK8YQz8/vQKwDXS5pkfxe6c9OZlNHVZOFQ+orB3evK5/FEoVgaGMXFh pUCCveEqNrIChAKXiQ+tXJXlkkEQbuCfZtuhcmV+e3jUmvRXqi2KTAUDgBcbD8Vi tgbLFtwpKbzcb9m/dPyaChlc1nWzh17hPLYh4IxSkJZgt9/1UG3ict6yI9Uz39De J5ESlYFT+QUG64SSXxso2yXRRlgQlsbvw+LChEnXbinq/Do/7wo= =cybS -----END PGP SIGNATURE-----