Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-41988

Опубликовано: 20 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-41988: dovecot security update (IMPORTANT)

[1:2.3.21-19.1]

  • fix CVE-2026-42006: fix imap_parser list_count_limit to actually work (RHEL-188477)

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

dovecot

2.3.21-19.el10_2.1

dovecot-devel

2.3.21-19.el10_2.1

dovecot-mysql

2.3.21-19.el10_2.1

dovecot-pgsql

2.3.21-19.el10_2.1

dovecot-pigeonhole

2.3.21-19.el10_2.1

Oracle Linux x86_64

dovecot

2.3.21-19.el10_2.1

dovecot-devel

2.3.21-19.el10_2.1

dovecot-mysql

2.3.21-19.el10_2.1

dovecot-pgsql

2.3.21-19.el10_2.1

dovecot-pigeonhole

2.3.21-19.el10_2.1

Связанные CVE

Связанные уязвимости

CVSS3: 4.3
ubuntu
3 месяца назад

An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.

CVSS3: 7.5
redhat
3 месяца назад

An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.

CVSS3: 4.3
nvd
3 месяца назад

An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.

CVSS3: 4.3
debian
3 месяца назад

An attacker can cause uncontrolled memory usage with excessive bracing ...

rocky
3 дня назад

Important: dovecot security update