[Apollo] Advisories Statistics light light Login

RLSA-2026:13857

Security Mirrored from RHSA-2026:13857
Issued at: 2026-05-07
Updated at: 2026-05-08

Synopsis

Important: dovecot security update



Description

Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages.

Security Fix(es):

* dovecot: ManageSieve: Denial of Service via crafted SASL initial response in AUTHENTICATE command (CVE-2025-59032)

* dovecot: denial of service via crafted message before authentication (CVE-2026-27858)

* dovecot: denial of service via specially crafted NOOP command (CVE-2026-27857)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 9 aarch64 Rocky Linux 9 ppc64le Rocky Linux 9 s390x Rocky Linux 9 x86_64

Fixes

2452172 2452175 2452179

CVEs

CVE-2025-59032 CVE-2026-27857 CVE-2026-27858

Affected packages

Rocky Linux 9 aarch64 - AppStream

dovecot-1:2.3.16-15.el9_7.1.aarch64.rpm dovecot-1:2.3.16-15.el9_7.1.src.rpm dovecot-debuginfo-1:2.3.16-15.el9_7.1.aarch64.rpm dovecot-debugsource-1:2.3.16-15.el9_7.1.aarch64.rpm dovecot-mysql-1:2.3.16-15.el9_7.1.aarch64.rpm dovecot-mysql-debuginfo-1:2.3.16-15.el9_7.1.aarch64.rpm dovecot-pgsql-1:2.3.16-15.el9_7.1.aarch64.rpm dovecot-pgsql-debuginfo-1:2.3.16-15.el9_7.1.aarch64.rpm dovecot-pigeonhole-1:2.3.16-15.el9_7.1.aarch64.rpm dovecot-pigeonhole-debuginfo-1:2.3.16-15.el9_7.1.aarch64.rpm

Rocky Linux 9 x86_64 - CRB

dovecot-1:2.3.16-15.el9_7.1.i686.rpm dovecot-debuginfo-1:2.3.16-15.el9_7.1.i686.rpm dovecot-debugsource-1:2.3.16-15.el9_7.1.i686.rpm dovecot-devel-1:2.3.16-15.el9_7.1.i686.rpm dovecot-devel-1:2.3.16-15.el9_7.1.x86_64.rpm

Rocky Linux 9 ppc64le - AppStream

dovecot-1:2.3.16-15.el9_7.1.ppc64le.rpm dovecot-1:2.3.16-15.el9_7.1.src.rpm dovecot-debuginfo-1:2.3.16-15.el9_7.1.ppc64le.rpm dovecot-debugsource-1:2.3.16-15.el9_7.1.ppc64le.rpm dovecot-mysql-1:2.3.16-15.el9_7.1.ppc64le.rpm dovecot-mysql-debuginfo-1:2.3.16-15.el9_7.1.ppc64le.rpm dovecot-pgsql-1:2.3.16-15.el9_7.1.ppc64le.rpm dovecot-pgsql-debuginfo-1:2.3.16-15.el9_7.1.ppc64le.rpm dovecot-pigeonhole-1:2.3.16-15.el9_7.1.ppc64le.rpm dovecot-pigeonhole-debuginfo-1:2.3.16-15.el9_7.1.ppc64le.rpm

Rocky Linux 9 s390x - AppStream

dovecot-1:2.3.16-15.el9_7.1.s390x.rpm dovecot-1:2.3.16-15.el9_7.1.src.rpm dovecot-debuginfo-1:2.3.16-15.el9_7.1.s390x.rpm dovecot-debugsource-1:2.3.16-15.el9_7.1.s390x.rpm dovecot-mysql-1:2.3.16-15.el9_7.1.s390x.rpm dovecot-mysql-debuginfo-1:2.3.16-15.el9_7.1.s390x.rpm dovecot-pgsql-1:2.3.16-15.el9_7.1.s390x.rpm dovecot-pgsql-debuginfo-1:2.3.16-15.el9_7.1.s390x.rpm dovecot-pigeonhole-1:2.3.16-15.el9_7.1.s390x.rpm dovecot-pigeonhole-debuginfo-1:2.3.16-15.el9_7.1.s390x.rpm

Rocky Linux 9 x86_64 - AppStream

dovecot-1:2.3.16-15.el9_7.1.src.rpm dovecot-1:2.3.16-15.el9_7.1.x86_64.rpm dovecot-debuginfo-1:2.3.16-15.el9_7.1.x86_64.rpm dovecot-debugsource-1:2.3.16-15.el9_7.1.x86_64.rpm dovecot-mysql-1:2.3.16-15.el9_7.1.x86_64.rpm dovecot-mysql-debuginfo-1:2.3.16-15.el9_7.1.x86_64.rpm dovecot-pgsql-1:2.3.16-15.el9_7.1.x86_64.rpm dovecot-pgsql-debuginfo-1:2.3.16-15.el9_7.1.x86_64.rpm dovecot-pigeonhole-1:2.3.16-15.el9_7.1.x86_64.rpm dovecot-pigeonhole-debuginfo-1:2.3.16-15.el9_7.1.x86_64.rpm

Rocky Linux 9 aarch64 - CRB

dovecot-devel-1:2.3.16-15.el9_7.1.aarch64.rpm

Rocky Linux 9 ppc64le - CRB

dovecot-devel-1:2.3.16-15.el9_7.1.ppc64le.rpm

Rocky Linux 9 s390x - CRB

dovecot-devel-1:2.3.16-15.el9_7.1.s390x.rpm