Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42007

Опубликовано: 28 авг. 2026
Источник: redhat
CVSS3: 9.1

Описание

An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.

A flaw was found in Dovecot. An authenticated attacker can use a Sieve script with the editheader extension to trigger a use-after-free vulnerability in the mail editing code. This can lead to memory corruption, potentially crashing the mail delivery process and allowing for arbitrary code execution in the context of that process.

Отчет

This flaw requires an attacker to authenticate with valid credentials before it can be exploited, and exploitation additionally depends on the Sieve editheader extension being enabled, which is not Dovecot's default configuration. Because the CVSS attack vector requires low-privileged authentication (PR:L) rather than unauthenticated remote access, and the confirmed impact is primarily memory corruption leading to a crash of the mail delivery process, this issue is rated Important rather than Critical. Disabling the Sieve editheader extension fully mitigates the vulnerability without requiring a package update.

Меры по смягчению последствий

To mitigate this vulnerability, disable the Sieve editheader extension in the Dovecot configuration. After modifying the configuration, the Dovecot service must be restarted for the changes to take effect. Disabling this extension will remove its associated functionality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dovecotAffected
Red Hat Enterprise Linux 6dovecotOut of support scope
Red Hat Enterprise Linux 7dovecotAffected
Red Hat Enterprise Linux 8dovecotAffected
Red Hat Enterprise Linux 9dovecotAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2525583dovecot: Dovecot: Arbitrary Code Execution via Sieve editheader use-after-free

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
16 дней назад

An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 9.1
nvd
16 дней назад

An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 9.1
debian
16 дней назад

An attacker that has valid credentials can use a Sieve script with the ...

CVSS3: 9.1
github
16 дней назад

An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.

suse-cvrf
11 дней назад

Security update for dovecot22

9.1 Critical

CVSS3