Описание
An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.
A flaw was found in Dovecot. A remote attacker can exploit this vulnerability by sending excessive open braces over the Internet Message Access Protocol (IMAP), leading to uncontrolled memory usage. This can cause the affected system to consume memory up to its configured limit, resulting in a Denial of Service (DoS).
Отчет
A remote attacker can trigger this flaw simply by sending specially crafted IMAP requests to the Dovecot server, requiring no complex interactions. The vulnerability is strictly limited to a Denial of Service (DoS) via memory exhaustion and does not allow for data exfiltration, privilege escalation, or remote code execution. Furthermore, the impact is contained because the memory consumption is restricted to the process's configured limit, preventing a complete system-wide crash.
Меры по смягчению последствий
To mitigate this issue, administrators can configure the vsz_limit setting for the Dovecot IMAP process to a lower value. This limits the virtual memory size available to the IMAP process, preventing excessive memory consumption.
Example configuration in /etc/dovecot/conf.d/10-master.conf:
After modifying the configuration, restart the Dovecot service for the changes to take effect.
Setting vsz_limit too low may impact legitimate IMAP operations.
*Restarting the dovecot service will temporarily interrupt mail services.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | dovecot | Out of support scope | ||
| Red Hat Enterprise Linux 7 | dovecot | Affected | ||
| Red Hat Enterprise Linux 10 | dovecot | Fixed | RHSA-2026:41988 | 20.07.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | dovecot | Fixed | RHSA-2026:42091 | 20.07.2026 |
| Red Hat Enterprise Linux 8 | dovecot | Fixed | RHSA-2026:46532 | 27.07.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | dovecot | Fixed | RHSA-2026:46380 | 27.07.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | dovecot | Fixed | RHSA-2026:46380 | 27.07.2026 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | dovecot | Fixed | RHSA-2026:46379 | 27.07.2026 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | dovecot | Fixed | RHSA-2026:46379 | 27.07.2026 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | dovecot | Fixed | RHSA-2026:46381 | 27.07.2026 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.
An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.
An attacker can cause uncontrolled memory usage with excessive bracing ...
7.5 High
CVSS3