Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-52681

Опубликовано: 28 авг. 2026
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Compiled script files are also not removed when a script is deleted or renamed. The configured Sieve CPU limit can be bypassed, allowing sustained CPU consumption, and the leftover files increase disk consumption. Both can cause degradation of service for mail delivery. Monitor system for abnormal CPU usage and disk consumption. Update to non-vulnerable version. No publicly available exploits are known.

A flaw was found in dovecot. An authenticated attacker can bypass the configured Sieve CPU limit by repeatedly changing active scripts. This action prevents proper CPU resource accounting and leaves behind compiled script files, leading to sustained CPU and increased disk consumption. The consequence is a degradation of service for mail delivery, potentially causing a Denial of Service (DoS).

Меры по смягчению последствий

Administrators can monitor system resources for abnormal CPU usage and disk consumption related to Dovecot Sieve processes. To prevent exploitation, if Sieve functionality is not required, it can be disabled by removing the sieve plugin from the mail_plugins setting in the Dovecot configuration. Disabling Sieve will impact user mail filtering capabilities. A restart of the Dovecot service is required for configuration changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dovecotFix deferred
Red Hat Enterprise Linux 6dovecotNot affected
Red Hat Enterprise Linux 7dovecotNot affected
Red Hat Enterprise Linux 8dovecotFix deferred
Red Hat Enterprise Linux 9dovecotFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2525582dovecot: Dovecot: Denial of Service via Sieve script manipulation

EPSS

Процентиль: 17%
0.00254
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
10 дней назад

Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Compiled script files are also not removed when a script is deleted or renamed. The configured Sieve CPU limit can be bypassed, allowing sustained CPU consumption, and the leftover files increase disk consumption. Both can cause degradation of service for mail delivery. Monitor system for abnormal CPU usage and disk consumption. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 3.1
nvd
10 дней назад

Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Compiled script files are also not removed when a script is deleted or renamed. The configured Sieve CPU limit can be bypassed, allowing sustained CPU consumption, and the leftover files increase disk consumption. Both can cause degradation of service for mail delivery. Monitor system for abnormal CPU usage and disk consumption. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 3.1
debian
10 дней назад

Sieve CPU resource usage is tracked in the compiled script, so an atta ...

CVSS3: 3.1
github
10 дней назад

Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Compiled script files are also not removed when a script is deleted or renamed. The configured Sieve CPU limit can be bypassed, allowing sustained CPU consumption, and the leftover files increase disk consumption. Both can cause degradation of service for mail delivery. Monitor system for abnormal CPU usage and disk consumption. Update to non-vulnerable version. No publicly available exploits are known.

suse-cvrf
6 дней назад

Security update for dovecot24

EPSS

Процентиль: 17%
0.00254
Низкий

3.1 Low

CVSS3