Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21929-1

Опубликовано: 22 сент. 2026
Источник: suse-cvrf

Описание

Security update for cyrus-imapd

This update for cyrus-imapd fixes the following issues:

Changes in cyrus-imapd:

Update to 3.8.8 (bugfix release):

  • CVE-2026-61907: JMAP snooze bypasses destination-mailbox ACL (bsc#1279908)
  • CVE-2026-61908: JMAP email-header blob ID out-of-bounds index (bsc#1279975)
  • CVE-2026-61909: CalDAV/CardDAV multiget bypasses per-href ACL (bsc#1279976)
  • CVE-2026-61910: Mailbox/set let sharee change special-use role on shared mailboxes (bsc#1279977)
  • CVE-2026-61911: Sieve mailbox existence oracle (bsc#1279978)
  • CVE-2026-61915: VPATCH BYPARAM double-free (bsc#1279979)

Список пакетов

openSUSE Leap 16.0
cyradm-3.8.8-bp160.1.1
cyrus-imapd-3.8.8-bp160.1.1
cyrus-imapd-devel-3.8.8-bp160.1.1
cyrus-imapd-snmp-3.8.8-bp160.1.1
cyrus-imapd-snmp-mibs-3.8.8-bp160.1.1
cyrus-imapd-utils-3.8.8-bp160.1.1
libcyrus0-3.8.8-bp160.1.1
perl-Cyrus-Annotator-3.8.8-bp160.1.1
perl-Cyrus-IMAP-3.8.8-bp160.1.1
perl-Cyrus-SIEVE-managesieve-3.8.8-bp160.1.1

Описание

An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.


Затронутые продукты
openSUSE Leap 16.0:cyradm-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-devel-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-snmp-3.8.8-bp160.1.1

Ссылки

Описание

An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the end of the internal blob_headers array during download, exposing adjacent heap memory.


Затронутые продукты
openSUSE Leap 16.0:cyradm-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-devel-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-snmp-3.8.8-bp160.1.1

Ссылки

Описание

An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT.


Затронутые продукты
openSUSE Leap 16.0:cyradm-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-devel-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-snmp-3.8.8-bp160.1.1

Ссылки

Описание

An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This could allow the sharee to change the shared mailbox to perform the archived, snoozed, or other role, which might cause mail mail to be written to the shared mailbox, sharing more content than intended. (This is likely to be an unusual situation, made more unusual because if the target already has an non-shared mailbox with that role, role duplication suppression will prevent the update.)


Затронутые продукты
openSUSE Leap 16.0:cyradm-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-devel-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-snmp-3.8.8-bp160.1.1

Ссылки

Описание

An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery.


Затронутые продукты
openSUSE Leap 16.0:cyradm-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-devel-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-snmp-3.8.8-bp160.1.1

Ссылки

Описание

An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.


Затронутые продукты
openSUSE Leap 16.0:cyradm-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-devel-3.8.8-bp160.1.1
openSUSE Leap 16.0:cyrus-imapd-snmp-3.8.8-bp160.1.1

Ссылки