Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-46532

Опубликовано: 28 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2026-46532: dovecot security update (IMPORTANT)

[1:2.3.16-8]

  • fix CVE-2026-42006: fix IMAP parser list_count_limit to correctly limit open braces instead of close braces (RHEL-188480)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

dovecot

2.3.16-8.el8_10

dovecot-devel

2.3.16-8.el8_10

dovecot-mysql

2.3.16-8.el8_10

dovecot-pgsql

2.3.16-8.el8_10

dovecot-pigeonhole

2.3.16-8.el8_10

Oracle Linux x86_64

dovecot

2.3.16-8.el8_10

dovecot-devel

2.3.16-8.el8_10

dovecot-mysql

2.3.16-8.el8_10

dovecot-pgsql

2.3.16-8.el8_10

dovecot-pigeonhole

2.3.16-8.el8_10

Связанные CVE

Связанные уязвимости

CVSS3: 4.3
ubuntu
3 месяца назад

An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.

CVSS3: 7.5
redhat
3 месяца назад

An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.

CVSS3: 4.3
nvd
3 месяца назад

An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.

CVSS3: 4.3
debian
3 месяца назад

An attacker can cause uncontrolled memory usage with excessive bracing ...

rocky
3 дня назад

Important: dovecot security update