Описание
Security update for cyrus-imapd
This update for cyrus-imapd fixes the following issues:
Changes in cyrus-imapd:
Update to 3.8.8 (bugfix release):
- CVE-2026-61907: JMAP snooze bypasses destination-mailbox ACL (bsc#1279908)
- CVE-2026-61908: JMAP email-header blob ID out-of-bounds index (bsc#1279975)
- CVE-2026-61909: CalDAV/CardDAV multiget bypasses per-href ACL (bsc#1279976)
- CVE-2026-61910: Mailbox/set let sharee change special-use role on shared mailboxes (bsc#1279977)
- CVE-2026-61911: Sieve mailbox existence oracle (bsc#1279978)
- CVE-2026-61915: VPATCH BYPARAM double-free (bsc#1279979)
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1279908
- SUSE Bug 1279975
- SUSE Bug 1279976
- SUSE Bug 1279977
- SUSE Bug 1279978
- SUSE Bug 1279979
- SUSE CVE CVE-2026-61907 page
- SUSE CVE CVE-2026-61908 page
- SUSE CVE CVE-2026-61909 page
- SUSE CVE CVE-2026-61910 page
- SUSE CVE CVE-2026-61911 page
- SUSE CVE CVE-2026-61915 page
Описание
An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.
Затронутые продукты
Ссылки
- CVE-2026-61907
- SUSE Bug 1279908
Описание
An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the end of the internal blob_headers array during download, exposing adjacent heap memory.
Затронутые продукты
Ссылки
- CVE-2026-61908
- SUSE Bug 1279975
Описание
An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT.
Затронутые продукты
Ссылки
- CVE-2026-61909
- SUSE Bug 1279976
Описание
An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This could allow the sharee to change the shared mailbox to perform the archived, snoozed, or other role, which might cause mail mail to be written to the shared mailbox, sharing more content than intended. (This is likely to be an unusual situation, made more unusual because if the target already has an non-shared mailbox with that role, role duplication suppression will prevent the update.)
Затронутые продукты
Ссылки
- CVE-2026-61910
- SUSE Bug 1279977
Описание
An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery.
Затронутые продукты
Ссылки
- CVE-2026-61911
- SUSE Bug 1279978
Описание
An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.
Затронутые продукты
Ссылки
- CVE-2026-61915
- SUSE Bug 1279979