Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40015

Опубликовано: 28 авг. 2026
Источник: redhat
CVSS3: 4.3

Описание

An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process. The crash interrupts hibernated IMAP sessions handled by the affected process, which can cause degradation of service for IMAP. Disable IMAP hibernation. Update to non-vulnerable version. No publicly available exploits are known.

A flaw was found in Dovecot's imap-hibernate service. An authenticated attacker can open numerous connections and send malformed commands, leading to an out-of-bounds read. This can intermittently crash the process, interrupting hibernated IMAP sessions and causing a denial of service for affected users.

Меры по смягчению последствий

To mitigate this issue, disable IMAP hibernation in Dovecot. This can be achieved by setting imap_hibernate_timeout = 0 in the Dovecot configuration. For example, add or modify the following line in /etc/dovecot/local.conf or a relevant configuration file within /etc/dovecot/conf.d/:

imap_hibernate_timeout = 0

After modifying the configuration, restart the Dovecot service for the changes to take effect:

systemctl restart dovecot

Disabling IMAP hibernation may affect the performance or behavior of IMAP sessions that rely on this feature.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dovecotFix deferred
Red Hat Enterprise Linux 6dovecotOut of support scope
Red Hat Enterprise Linux 7dovecotFix deferred
Red Hat Enterprise Linux 8dovecotFix deferred
Red Hat Enterprise Linux 9dovecotFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2525590dovecot: Dovecot: Denial of Service via malformed IMAP commands in imap-hibernate service

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
16 дней назад

An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process. The crash interrupts hibernated IMAP sessions handled by the affected process, which can cause degradation of service for IMAP. Disable IMAP hibernation. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 4.3
nvd
16 дней назад

An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process. The crash interrupts hibernated IMAP sessions handled by the affected process, which can cause degradation of service for IMAP. Disable IMAP hibernation. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 4.3
debian
16 дней назад

An attacker that has valid credentials can open many connections to th ...

CVSS3: 4.3
github
16 дней назад

An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process. The crash interrupts hibernated IMAP sessions handled by the affected process, which can cause degradation of service for IMAP. Disable IMAP hibernation. Update to non-vulnerable version. No publicly available exploits are known.

suse-cvrf
11 дней назад

Security update for dovecot22

4.3 Medium

CVSS3