Issued at: 2026-10-07
Updated at: 2026-10-07
Advisory content derived from Red Hat RHSA-2026:76763, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Important: dovecot security, bug fix, and enhancement update
Description
Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages.
Security Fix(es):
* dovecot: Dovecot: Denial of Service via IMAP ID command with excessive parameters (CVE-2026-42391)
* dovecot: Dovecot: Authentication bypass via incorrect OAuth2 token validation (CVE-2026-73208)
* dovecot: Dovecot: Denial of service via crafted email headers (CVE-2026-27852)
* dovecot: Dovecot: Denial of Service via truncated quoted argument in ManageSieve (CVE-2026-40019)
* dovecot: Dovecot: Denial of Service and potential message duplication via connection limit exhaustion (CVE-2026-33263)
* dovecot: Dovecot: Denial of Service in ManageSieve login process (CVE-2026-33605)
* dovecot: Dovecot: Arbitrary Code Execution via Sieve editheader use-after-free (CVE-2026-42007)
* dovecot: Dovecot: MySQL multi-byte escaping wrong (CVE-2026-40018)
Bug Fix(es) and Enhancement(s):
* Dovecot crashes when accessing mailbox with: "Panic: file mail-user.c: line 229 (mail_user_deinit): assertion failed: ((*user)->refcount == 1)" (JIRA:Rocky Linux-176273)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.