Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40013

Опубликовано: 28 авг. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when the ManageSieve service compiles the script. This causes memory corruption and an observed crash of the ManageSieve process, resulting in denial of service for script management. This might be able to be used for remote code execution. Disable the ManageSieve service if users do not need remote Sieve script management. Update to non-vulnerable version. No publicly available exploits are known.

A flaw was found in Dovecot. An authenticated attacker can submit a specially crafted Sieve script containing an extreme numeric literal to the ManageSieve service. This action triggers an out-of-bounds write during script compilation, leading to memory corruption and a crash of the ManageSieve process. This vulnerability results in a denial of service for script management and might also be leveraged for remote code execution.

Меры по смягчению последствий

To mitigate this issue, disable the ManageSieve service if remote Sieve script management is not required. This can typically be achieved by removing sieve from the protocols setting in your Dovecot configuration (e.g., in /etc/dovecot/dovecot.conf or a file in /etc/dovecot/conf.d/). For example, change protocols = imap pop3 lmtp sieve to protocols = imap pop3 lmtp. After modifying the configuration, the Dovecot service must be restarted for the changes to take effect using systemctl restart dovecot. Disabling this service will prevent users from remotely managing their Sieve scripts.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dovecotFix deferred
Red Hat Enterprise Linux 6dovecotOut of support scope
Red Hat Enterprise Linux 7dovecotFix deferred
Red Hat Enterprise Linux 8dovecotFix deferred
Red Hat Enterprise Linux 9dovecotFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2525530dovecot: Dovecot: Denial of Service in ManageSieve service via crafted Sieve script

EPSS

Процентиль: 38%
0.00455
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
16 дней назад

An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when the ManageSieve service compiles the script. This causes memory corruption and an observed crash of the ManageSieve process, resulting in denial of service for script management. This might be able to be used for remote code execution. Disable the ManageSieve service if users do not need remote Sieve script management. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 4.3
nvd
16 дней назад

An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when the ManageSieve service compiles the script. This causes memory corruption and an observed crash of the ManageSieve process, resulting in denial of service for script management. This might be able to be used for remote code execution. Disable the ManageSieve service if users do not need remote Sieve script management. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 4.3
debian
16 дней назад

An attacker that has valid credentials can submit a Sieve script conta ...

CVSS3: 4.3
github
16 дней назад

An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when the ManageSieve service compiles the script. This causes memory corruption and an observed crash of the ManageSieve process, resulting in denial of service for script management. This might be able to be used for remote code execution. Disable the ManageSieve service if users do not need remote Sieve script management. Update to non-vulnerable version. No publicly available exploits are known.

suse-cvrf
12 дней назад

Security update for dovecot24

EPSS

Процентиль: 38%
0.00455
Низкий

4.3 Medium

CVSS3