-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 18 May 2026 16:03:51 -0400 Source: dovecot Binary: dovecot-auth-lua dovecot-auth-lua-dbgsym dovecot-core dovecot-core-dbgsym dovecot-dev dovecot-flatcurve dovecot-flatcurve-dbgsym dovecot-gssapi dovecot-gssapi-dbgsym dovecot-imapd dovecot-imapd-dbgsym dovecot-ldap dovecot-ldap-dbgsym dovecot-lmtpd dovecot-lmtpd-dbgsym dovecot-managesieved dovecot-managesieved-dbgsym dovecot-mysql dovecot-mysql-dbgsym dovecot-pgsql dovecot-pgsql-dbgsym dovecot-pop3d dovecot-pop3d-dbgsym dovecot-sieve dovecot-sieve-dbgsym dovecot-solr dovecot-solr-dbgsym dovecot-sqlite dovecot-sqlite-dbgsym dovecot-submissiond dovecot-submissiond-dbgsym Architecture: armhf Version: 1:2.4.1+dfsg1-6+deb13u6 Distribution: trixie-security Urgency: medium Maintainer: armhf Build Daemon (arm-ubc-06) Changed-By: Noah Meyerhans Description: dovecot-auth-lua - secure POP3/IMAP server - Lua authentication plugin dovecot-core - secure POP3/IMAP server - core files dovecot-dev - secure POP3/IMAP server - header files dovecot-flatcurve - secure POP3/IMAP server - Flatcurve support dovecot-gssapi - secure POP3/IMAP server - GSSAPI support dovecot-imapd - secure POP3/IMAP server - IMAP daemon dovecot-ldap - secure POP3/IMAP server - LDAP support dovecot-lmtpd - secure POP3/IMAP server - LMTP server dovecot-managesieved - secure POP3/IMAP server - ManageSieve server dovecot-mysql - secure POP3/IMAP server - MySQL support dovecot-pgsql - secure POP3/IMAP server - PostgreSQL support dovecot-pop3d - secure POP3/IMAP server - POP3 daemon dovecot-sieve - secure POP3/IMAP server - Sieve filters support dovecot-solr - secure POP3/IMAP server - Solr support dovecot-sqlite - secure POP3/IMAP server - SQLite support dovecot-submissiond - secure POP3/IMAP server - mail submission agent Closes: 1136444 Changes: dovecot (1:2.4.1+dfsg1-6+deb13u6) trixie-security; urgency=medium . * Security update (Closes: #1136444) * [76ceed4] CVE-2026-27851: lib-var-expand: Reset safe state when transfer is unset * [4af6fb3] CVE-2026-40016: lib-sieve: Enforce CPU time limit within :contains and :matches matcher loops * [366ef61] CVE-2026-33603: login-common: Only accept base64 in sasl * [26bd41e] CVE-2026-40020: IMAP folders can be shared-spammed to everyone. * [b6f5bac] CVE-2026-42006: imap-login: Excessive memory usage DoS Checksums-Sha1: 82ec52162051406787ff22ad47687460c023c34a 31972 dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 55f9bda3cb05546daa0dc3217d5c8eeaeecad106 20900 dovecot-auth-lua_2.4.1+dfsg1-6+deb13u6_armhf.deb 0af5228721ce5600b816043b351e87b33cdcaff5 9769408 dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 9f9baa42c4cae85b7da0408b3602ec4bfdc3904d 2427028 dovecot-core_2.4.1+dfsg1-6+deb13u6_armhf.deb c57d1bde9e0f28346ee2e9234f41c073c221025e 429488 dovecot-dev_2.4.1+dfsg1-6+deb13u6_armhf.deb 351fc087d4315ccb8c558a2d92cc1e881f200133 185720 dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 5a707cee1713fde60caef0ce207ed94a5d98a388 39056 dovecot-flatcurve_2.4.1+dfsg1-6+deb13u6_armhf.deb becef95a2ca5508b678c2aa0d803520695b4ea96 21384 dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb be3fa23ff12d6877ddb1a70da760b50f6f752c26 17844 dovecot-gssapi_2.4.1+dfsg1-6+deb13u6_armhf.deb 0babfa6e19d34a4f37a5d4b398e674c462bc2d7a 731060 dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 0c6e6a9127a1ef0d591064ae50d8743ca5408a44 175200 dovecot-imapd_2.4.1+dfsg1-6+deb13u6_armhf.deb 052f9abea5515ae485e2ccd11176773d9fbc8276 164392 dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb fa719a5e7bcd706b7faee84cd8f5e5cecc35bd95 49452 dovecot-ldap_2.4.1+dfsg1-6+deb13u6_armhf.deb 2892eff119b379679fc8ec6a2b7e487b94768fa9 100116 dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 2444435e57bafa3874d16dde7aa63d29c86ed01c 34724 dovecot-lmtpd_2.4.1+dfsg1-6+deb13u6_armhf.deb a17bcc143ea1e04ed22821fd4cbbdb66b761bdd2 116492 dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb d621609ea55e22d5e52134f9637ef486b1b833ac 45188 dovecot-managesieved_2.4.1+dfsg1-6+deb13u6_armhf.deb a1d79a13f2361bd99d5db1dfe6ea97b84f5c7d83 35604 dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 40ccb2e5ef434ecf5c1416977722d04a694fb3b5 19796 dovecot-mysql_2.4.1+dfsg1-6+deb13u6_armhf.deb 713ab7d2ef5331ee1beec371d35ef0ca477a17cf 38920 dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 9003f23bca07b2a7a3130c2504c1df4d817198bc 23872 dovecot-pgsql_2.4.1+dfsg1-6+deb13u6_armhf.deb 3567a541e9021bc497e1456891bc31ada4f75e80 102512 dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb d28c0a5885e180f590ac409082fe4432b2a5d34a 41944 dovecot-pop3d_2.4.1+dfsg1-6+deb13u6_armhf.deb 0cb4c6e9a0b1010b23f2533a43a3212de2e7e528 1659444 dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb a76bdb59e99a60ac17edbe109bf5106be15973d2 336508 dovecot-sieve_2.4.1+dfsg1-6+deb13u6_armhf.deb baa9af4a7240e83011a50171a969ae9209d01905 73852 dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb c3e5b9445e3ea65bb506cf49e3c59b95c8fff25d 36500 dovecot-solr_2.4.1+dfsg1-6+deb13u6_armhf.deb d377284177040bfaa5171182bb67c3633d838e0a 25020 dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 9a03e3075c144c9e63b0bc8346d5eccc8a5530dd 19160 dovecot-sqlite_2.4.1+dfsg1-6+deb13u6_armhf.deb ae30e406336d5317a97cb5138b1acc0446e189f1 205648 dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 6d18b26f3ffdf83cbbd92144fad208355fdf4fa3 56068 dovecot-submissiond_2.4.1+dfsg1-6+deb13u6_armhf.deb c863c21f6622c673c264c1a6b4eb75684c4b6134 17934 dovecot_2.4.1+dfsg1-6+deb13u6_armhf-buildd.buildinfo Checksums-Sha256: b87d552e0d297afe10573138e4fab408ad1eace7ef24b12407470ffaabcd37d2 31972 dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb a69c70e58e8595bedea1f13aab89a0f817e5afaee14480f81bf94bba00bea000 20900 dovecot-auth-lua_2.4.1+dfsg1-6+deb13u6_armhf.deb 732ad42371019e84728f97ea8a77cb1bf660a19efebbe7a9930650a24fd01965 9769408 dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 34cd3e131a100633ecdd1e88589f7f27c694f7919ce90e4432a00f56be74932b 2427028 dovecot-core_2.4.1+dfsg1-6+deb13u6_armhf.deb 94fc457a98886c5259f9ad4da475aab7cec2f5491d2395136da48355b6f93e83 429488 dovecot-dev_2.4.1+dfsg1-6+deb13u6_armhf.deb 929bda510ef4fc126448d50b180ef51b79d8ca5e9a181f60b51c41afea233dd4 185720 dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 8ba2849f4eb2059cc1532f9a595bd80b0de0f76cacf3eb95dfdfa586402a43e7 39056 dovecot-flatcurve_2.4.1+dfsg1-6+deb13u6_armhf.deb b648793099b972e8510051317c3daec6a8db2b98c900b3c8cad28a72300f4fe3 21384 dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb dad0c820fff14eedc450a130c6221f5a03e190b70540fc3bb6a4d8af2a2f19aa 17844 dovecot-gssapi_2.4.1+dfsg1-6+deb13u6_armhf.deb 382464083f2de996b0c7d1f88233f4848f6092e178f5129b4c6a780dc9b2f758 731060 dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 4c6b6f158063ea711540cf47fc36048a3bba6409eee5faa627f027a71db58743 175200 dovecot-imapd_2.4.1+dfsg1-6+deb13u6_armhf.deb df898ba44612c871e09f936f78c445a52322dfb157deaf8e67453e820281c8d0 164392 dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 41841b3afe54cebe984011b09ee6ddcf3f5637bf2a86f90a2f7c3cf1d4dda989 49452 dovecot-ldap_2.4.1+dfsg1-6+deb13u6_armhf.deb 012cd2db94114fdcd8859d9d1753121ffb924ccf379a9cbe5921b2d3d9329ea0 100116 dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 1e5899a78a797d5946333bf6318853242aac13649055e709678b251d10badbf0 34724 dovecot-lmtpd_2.4.1+dfsg1-6+deb13u6_armhf.deb 8f88ac1d64ff2d00eac99a07654bef667e5a610b9eb677b70b6af612e4233f26 116492 dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 15fd4d4da915d8e63caa51aca0cb160a7c26b5649f0f020688a15153cf3f1560 45188 dovecot-managesieved_2.4.1+dfsg1-6+deb13u6_armhf.deb b2713124a0598ef3dae8a50f25cec99948ef87969a6712ea3c2fccdaaa93ce72 35604 dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb a17a9afdd3fcdc8280048b9d129a04fef99ff7019613530b5a1c821e8a90e435 19796 dovecot-mysql_2.4.1+dfsg1-6+deb13u6_armhf.deb df2284619c509b8eba410cb9a87eba23a86edf71b9813b21e6c91e389ceca966 38920 dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 4681c1a4b8d180470d26ae46fa25b541e8bbde529fd2c41092dd20ab1ebb76d1 23872 dovecot-pgsql_2.4.1+dfsg1-6+deb13u6_armhf.deb 21cdc626808bd95f62df2c6590f265e66ff7a54d06531618f83c5941fae826ad 102512 dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 7b7b0fdc0a6dac40c9edf774edf908528bf0a5a2ff2393e99fde80b93cf99733 41944 dovecot-pop3d_2.4.1+dfsg1-6+deb13u6_armhf.deb e39725acf82cc9313cfa6cbea856981bdd24d705ac1e3eb4a293fdde9e4c4002 1659444 dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb f6e7ce3e5a457793080255aa65c9c42f2164ef5c0cafb46ee180f498b7cde2f5 336508 dovecot-sieve_2.4.1+dfsg1-6+deb13u6_armhf.deb 40f32f5881344c6d021a5a2b7aadb1a76d92662a9494a3976ea8d8f33808b0d6 73852 dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 46beea838667f2bf20bc7c7a72e1a2f801a64d85cc3e415ae6a3fd63c92bf08a 36500 dovecot-solr_2.4.1+dfsg1-6+deb13u6_armhf.deb 99b50b5efd69173648f04149dd8078183d18e73242833f6227a3b8502ee9d2f5 25020 dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb d5f230fd8a6bd70c1f5c5640da7e9ad78cbeb011b82e2b81bb0b54cc1161bfb3 19160 dovecot-sqlite_2.4.1+dfsg1-6+deb13u6_armhf.deb 7e3fd64f02fdad012af67d62a0c5c16e7c58ea921b17166a7b002457e8767652 205648 dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb d3a466cf613dd928d2ed88b37f8cb426f3fb094a28ca5bbefac981928c5fd224 56068 dovecot-submissiond_2.4.1+dfsg1-6+deb13u6_armhf.deb 45f7b3ecc98f3a412f2cf55142218d68713c9e441797ed02119f469e741f6831 17934 dovecot_2.4.1+dfsg1-6+deb13u6_armhf-buildd.buildinfo Files: f1e64f817961b899d32eae48fa82659a 31972 debug optional dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 83eb7731b74a6ebb4722004b1edbefc6 20900 mail optional dovecot-auth-lua_2.4.1+dfsg1-6+deb13u6_armhf.deb e5bfd81e6f611ebeba18cafa17a7af0a 9769408 debug optional dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 9058c021cdf98da6e23888e2850c5012 2427028 mail optional dovecot-core_2.4.1+dfsg1-6+deb13u6_armhf.deb a06fe9127df5f2563e5540b0a54a57ef 429488 mail optional dovecot-dev_2.4.1+dfsg1-6+deb13u6_armhf.deb 0802dd0eb4896b008a9a9279b2fccec8 185720 debug optional dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 6b113f72bc9a2ef6b4c191cb93d2406f 39056 mail optional dovecot-flatcurve_2.4.1+dfsg1-6+deb13u6_armhf.deb c1368a8b4fcac0857a19f6e86d67108c 21384 debug optional dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb f9cecf9f856cafa4f67afbbc22ef408a 17844 mail optional dovecot-gssapi_2.4.1+dfsg1-6+deb13u6_armhf.deb 3d375efb900054133349f26e87731911 731060 debug optional dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb fef490530c3bb5ac281f4faca429b6ec 175200 mail optional dovecot-imapd_2.4.1+dfsg1-6+deb13u6_armhf.deb 77b42b7d0d8f0e617a8f12226e7822a0 164392 debug optional dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 5118c9d6bd706e78151143c891215386 49452 mail optional dovecot-ldap_2.4.1+dfsg1-6+deb13u6_armhf.deb a23ed4ca667fc5fe93a52e85e8e20342 100116 debug optional dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb d8f0941357568da5bb6a09fdcabebd3a 34724 mail optional dovecot-lmtpd_2.4.1+dfsg1-6+deb13u6_armhf.deb a99c94a8c2ff1f58bb3e5ea0202b9fcc 116492 debug optional dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 27323352fd1614a9c5ad6ed82a209d70 45188 mail optional dovecot-managesieved_2.4.1+dfsg1-6+deb13u6_armhf.deb 0e8f2f3d4d4d6e128886ddb5b7722f70 35604 debug optional dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 8b3be9bc9c67ce257cebb4ff037c901c 19796 mail optional dovecot-mysql_2.4.1+dfsg1-6+deb13u6_armhf.deb a0aadebe86cd0106ee96370ba638311b 38920 debug optional dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb f92ae5bab1962918576f3290ca632e88 23872 mail optional dovecot-pgsql_2.4.1+dfsg1-6+deb13u6_armhf.deb aac166ee644343c09f1cd38714964931 102512 debug optional dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb a5361a0267886ffc93aab2ff288918b2 41944 mail optional dovecot-pop3d_2.4.1+dfsg1-6+deb13u6_armhf.deb daec52df9a2bf64317db8e97131c0ff6 1659444 debug optional dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 8290e449b56dd5f80024fd6c6701ecc6 336508 mail optional dovecot-sieve_2.4.1+dfsg1-6+deb13u6_armhf.deb e2de91936896fcfe6ccbb182f79ca588 73852 debug optional dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb 88ab160c8f24959137b5c98d9534c626 36500 mail optional dovecot-solr_2.4.1+dfsg1-6+deb13u6_armhf.deb e735768845b009b7310d382a7aa1a49f 25020 debug optional dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb c4ddb3d68386931275698a80cc13aa44 19160 mail optional dovecot-sqlite_2.4.1+dfsg1-6+deb13u6_armhf.deb e94c6e6d39c57dc0fac8fa588e22aa00 205648 debug optional dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u6_armhf.deb fe7b738bc9d64085203fa337876e368a 56068 mail optional dovecot-submissiond_2.4.1+dfsg1-6+deb13u6_armhf.deb 2aa760c138d1352ae034af17d76bbfbf 17934 mail optional dovecot_2.4.1+dfsg1-6+deb13u6_armhf-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBOUsBrtd5lcy6oRfutMAkCxKbL0FAmoZ9CcACgkQutMAkCxK bL1m9Q//YyXJNk1B4KFm31JqKSFygVgJnAp03wZKHnPrMbwLN912rqUT2/SAMias NBB4i+F4T1kLj3gNkHVvUf0PeRHX3cA+bJuNJPeXJtksUgIi7jBnKWg3qqSnb6s5 LsRVPGRcOOmWEe4GeKk5y+Xmgs2M+sFOc04KbU1pFxwIFFjCg9tuoUCiSyJ/kd8A gGS4xaEtF0pxg6qFnU9dSyawC1ygERbUU64Mh/KcB4IVXiXnzZJbAnxN7zic83JM nS4aW0ribPQ4SKvy5b9cQbw12PKRK5qtYGKZRDHM9xCLnxpWTrKNEi+8nnHY2nnb jNWOrz8b/5YqBOO1sFCh0bLJ5z521k59uWKPIpRbdE7teHvRPWhwkEJlKfpegbfD nREIzR6F2j6aTSeA996p8hnkQVEecbqADJz4J6ZMEYepNHqNTKnbn+nEuMV4yKgb Q5iuNR/yIGynkk64o4tSoQbblD+8dJuPh7XoyEqQBgtk9fNnGrKw2jtevqefPvDO LnK78f8gM0zPTRlpj4qGyO6QU7yQxxp6GK9Ew0fYZvs9XE4QpQLRf4cgF4ZeKirM C9Df/4+2OrDYGrGh3QlyjedG7OTKh40+CIfzOQf8UceYSbS83gVsaToPe8ngVxv6 +MMIjtudQjbsDaUSVx+FRRBofeNOTymCzDGW7tnPorK1vLBV6Kc= =bpyE -----END PGP SIGNATURE-----