Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:41988

Опубликовано: 22 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: dovecot security update

Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages.

Security Fix(es):

  • dovecot: Dovecot: Denial of Service via excessive IMAP bracing (CVE-2026-42006)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
dovecotx86_6419.el10_2.1dovecot-2.3.21-19.el10_2.1.x86_64.rpm
dovecot-pgsqlx86_6419.el10_2.1dovecot-pgsql-2.3.21-19.el10_2.1.x86_64.rpm
dovecot-mysqlx86_6419.el10_2.1dovecot-mysql-2.3.21-19.el10_2.1.x86_64.rpm
dovecot-pigeonholex86_6419.el10_2.1dovecot-pigeonhole-2.3.21-19.el10_2.1.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 4.3
ubuntu
3 месяца назад

An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.

CVSS3: 7.5
redhat
3 месяца назад

An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.

CVSS3: 4.3
nvd
3 месяца назад

An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open braces to bypass the limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are known.

CVSS3: 4.3
debian
3 месяца назад

An attacker can cause uncontrolled memory usage with excessive bracing ...

rocky
9 дней назад

Important: dovecot security update