-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 31 Mar 2026 15:07:17 -0400 Source: dovecot Binary: dovecot-auth-lua dovecot-auth-lua-dbgsym dovecot-core dovecot-core-dbgsym dovecot-dev dovecot-flatcurve dovecot-flatcurve-dbgsym dovecot-gssapi dovecot-gssapi-dbgsym dovecot-imapd dovecot-imapd-dbgsym dovecot-ldap dovecot-ldap-dbgsym dovecot-lmtpd dovecot-lmtpd-dbgsym dovecot-managesieved dovecot-managesieved-dbgsym dovecot-mysql dovecot-mysql-dbgsym dovecot-pgsql dovecot-pgsql-dbgsym dovecot-pop3d dovecot-pop3d-dbgsym dovecot-sieve dovecot-sieve-dbgsym dovecot-solr dovecot-solr-dbgsym dovecot-sqlite dovecot-sqlite-dbgsym dovecot-submissiond dovecot-submissiond-dbgsym Architecture: amd64 Version: 1:2.4.1+dfsg1-6+deb13u4 Distribution: trixie-security Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Noah Meyerhans Description: dovecot-auth-lua - secure POP3/IMAP server - Lua authentication plugin dovecot-core - secure POP3/IMAP server - core files dovecot-dev - secure POP3/IMAP server - header files dovecot-flatcurve - secure POP3/IMAP server - Flatcurve support dovecot-gssapi - secure POP3/IMAP server - GSSAPI support dovecot-imapd - secure POP3/IMAP server - IMAP daemon dovecot-ldap - secure POP3/IMAP server - LDAP support dovecot-lmtpd - secure POP3/IMAP server - LMTP server dovecot-managesieved - secure POP3/IMAP server - ManageSieve server dovecot-mysql - secure POP3/IMAP server - MySQL support dovecot-pgsql - secure POP3/IMAP server - PostgreSQL support dovecot-pop3d - secure POP3/IMAP server - POP3 daemon dovecot-sieve - secure POP3/IMAP server - Sieve filters support dovecot-solr - secure POP3/IMAP server - Solr support dovecot-sqlite - secure POP3/IMAP server - SQLite support dovecot-submissiond - secure POP3/IMAP server - mail submission agent Changes: dovecot (1:2.4.1+dfsg1-6+deb13u4) trixie-security; urgency=medium . * [bc29057] CVE-2025-59028: auth: Don't disconnect auth client when invalid base64 SASL input is received * [fee7a9a] CVE-2025-59031: stop shipping the decode2text shell script * [9a4442e] CVE-2025-59032: managesieve-login: Fix crash when command didn't finish on the first call * [2711b3e] CVE-2026-24031, CVE-2026-27860: auth: fix ldap and sql injection * [d30f1c3] CVE-2026-27855: fix OTP authentication reply vulnerability * [e1b0ff7] CVE-2026-27856: doveadm: fix timing oracle attack * [b8a69bf] CVE-2026-27857: fix resource exhaustion DoS in NOOP command parsing * [85dd068] CVE-2026-27858: fix pre-authentication managesieve memory consumption issue * [880e332] CVE-2026-27859: fix uncontrolled resource allocation when delivering specially crafted email messages Checksums-Sha1: a1182dce5cf7991094e74da702d1b9d1578ef4bc 32656 dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 1a5a5e9723ada1e106c2ddc39bf8cc83b473a911 21784 dovecot-auth-lua_2.4.1+dfsg1-6+deb13u4_amd64.deb b42ccad49d494c6b83a4c08c819c2ec184b67395 11128780 dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 41d3b57979b06938f3580a9ac2fad2de72f1abd0 2717956 dovecot-core_2.4.1+dfsg1-6+deb13u4_amd64.deb e581f1f7c9b95cb7083852c53ba539c94940876a 428904 dovecot-dev_2.4.1+dfsg1-6+deb13u4_amd64.deb ed3c6cca1ddb63287eb422bc5e5115dd6a2831c7 190568 dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 4ae9e8e6f698a3cd209f59d5c6e70be16541d6f4 42324 dovecot-flatcurve_2.4.1+dfsg1-6+deb13u4_amd64.deb dc2411c7b18b9f70c7ac7b0337482616d0c9f174 21216 dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 3205bfdfeb2c8f389a70fe6a8cd3362ea0b3aea4 18084 dovecot-gssapi_2.4.1+dfsg1-6+deb13u4_amd64.deb c90a7e7bcc059b7866c27ccf4c881e9d25f15de5 824580 dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 6e196fc332038f0711c43577d998800a5291783a 195212 dovecot-imapd_2.4.1+dfsg1-6+deb13u4_amd64.deb b6c6668afe3e1f1ef550d89b9ad36bf927eebfd4 195236 dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 382739891adf9a96daa4d01408564a3d6bf10a52 53544 dovecot-ldap_2.4.1+dfsg1-6+deb13u4_amd64.deb 2fdbcdfa1ead1d1e802061347e032eed7cd6e4c3 101764 dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb dc5b58c4fddcebec4fddb30ecf97d9eb1a473dff 36484 dovecot-lmtpd_2.4.1+dfsg1-6+deb13u4_amd64.deb 4e51fb7de92a6d6461095cbd6048ad03c61357b7 127628 dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb dcbc84caa2f91231575300bea0a44d148217d3df 48100 dovecot-managesieved_2.4.1+dfsg1-6+deb13u4_amd64.deb 62f6dbf0c626d82ffae8f5c6c324477c1cc14fbe 35360 dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 4f75fe333aef64d3a80ab3c25cefc2412da37581 20712 dovecot-mysql_2.4.1+dfsg1-6+deb13u4_amd64.deb f52a3fbf6d7ea9011f493c450b3f95224230c07e 39124 dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb e2deca5791e2008177e480c352c7b9ff3183886c 24744 dovecot-pgsql_2.4.1+dfsg1-6+deb13u4_amd64.deb 8c9078d43b5210075941fdb8b6776bcb0a9e5601 106860 dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 433aee67ef98d3728d21b1bd35a5d62835d58847 44608 dovecot-pop3d_2.4.1+dfsg1-6+deb13u4_amd64.deb 532090fabf54b83183c8889b2071bfa34e89cf49 1765904 dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb a5551540ec9f2b2f5e52c7a123ade96f1d73eb1a 381816 dovecot-sieve_2.4.1+dfsg1-6+deb13u4_amd64.deb 2b32f96ac82dfef3d1f839dc197e95467c963d94 75364 dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 1a7a5a108fdffafb79b9cd47cb48bbfdbf403a40 37784 dovecot-solr_2.4.1+dfsg1-6+deb13u4_amd64.deb cb858c146e01afd9d43373d691df8a4bcc363e31 24680 dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb db664ff8ec21c2368640579261947321a4dcba6a 19784 dovecot-sqlite_2.4.1+dfsg1-6+deb13u4_amd64.deb 0c636b548c779d59199b67fc3258bc608559f462 213676 dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 310a4efec8a4ee0b97298fc0d76db8db734f5ab7 61416 dovecot-submissiond_2.4.1+dfsg1-6+deb13u4_amd64.deb 1d0d27623e14c607977e103d53f1656a7d4f808d 17970 dovecot_2.4.1+dfsg1-6+deb13u4_amd64-buildd.buildinfo Checksums-Sha256: 5963a6173f33350358c9e4c8a2c5dddcbb7c0c51529ceeeb61272bbfb8632a57 32656 dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 9f0af79ea8ae40c0be7eec8ef8d96f3124f8dbb6479c3fc5649b3a4e89a80b0b 21784 dovecot-auth-lua_2.4.1+dfsg1-6+deb13u4_amd64.deb f8fee6ab899235b22c210f9695e093415a1033481918f41a9b870369607deddf 11128780 dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb e5d6382910755f4e1fe5e484f454d4470481483a6f1dfa637a714501d7544157 2717956 dovecot-core_2.4.1+dfsg1-6+deb13u4_amd64.deb c95df393e74dd4f54d689189eb1562713c504ed32d225d3f7d22271c276667e5 428904 dovecot-dev_2.4.1+dfsg1-6+deb13u4_amd64.deb 703c24d029022da0f8fa675c5723019e9f389dd7026c17d51e9c7b7e0f318a86 190568 dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 3c0d9526613cb5192edf6a88694547308407305643da5f5bb7b765fc0d882a45 42324 dovecot-flatcurve_2.4.1+dfsg1-6+deb13u4_amd64.deb 20cc845ed718e4b2726285aad415473f4bb68dbef20be55933bfba34971a82e0 21216 dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb e1d8c32b3f0ce8e7b26818f96784c9138ae9b0f1d339ba5d9988a4013a924da8 18084 dovecot-gssapi_2.4.1+dfsg1-6+deb13u4_amd64.deb e98549b3d2496cfb8ecbec5807cc34e3a352773a941d9a35d6fc36cbc27fb893 824580 dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 8c4745e6ce10e96279cefcf39f4374084c673c8114f2985bfe2b141486b0c7df 195212 dovecot-imapd_2.4.1+dfsg1-6+deb13u4_amd64.deb 4d9b58d39e6af23d34da9b9cdfa5531b262ba88fc976f65b997b317fce301c37 195236 dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 9e133dd87ebcac484ced9e86f03091d7fd9241f37ea47f72c8d9bd6a51038e26 53544 dovecot-ldap_2.4.1+dfsg1-6+deb13u4_amd64.deb 4b1af017a862fecd98a1aeaf2ea0e6c0b9e8d81e35985c2eaa67202c5d729ae1 101764 dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 1cd8ce5cc5d7cc6897eee47299181d5f8debaffe69a120f3be0c9546b221cf15 36484 dovecot-lmtpd_2.4.1+dfsg1-6+deb13u4_amd64.deb 29d390296d5b550e36ade1b3f8a320010e4c4a44d774c3fa6bb7573c8a9aaf34 127628 dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb c72322a7f577500cd31dc8a309f132a2b58e07f7d0559bb9d5113f72793e3ecb 48100 dovecot-managesieved_2.4.1+dfsg1-6+deb13u4_amd64.deb 7c910cd992c8d57e2b10a011bba418879b0629216a81ba952fd009a26a14a049 35360 dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb ae6c8f4bddbd5e6c2349ff5712d6c6ca8342c9424f259b7dfcd9b7cb1f0053a1 20712 dovecot-mysql_2.4.1+dfsg1-6+deb13u4_amd64.deb 1c9c1704e6d77094dc6bdfd5d1b2235f8a2e2100c39971c8eddcef663c691b20 39124 dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb b7ff4ba30db5c87a428034a10ab55be801f14351d191463bdf2bf629616ae159 24744 dovecot-pgsql_2.4.1+dfsg1-6+deb13u4_amd64.deb f84ff5588dea852730eb7c2fca7107f17f8ee1ca12542528ffc6bbb3b6340014 106860 dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 5d1234b1b09f84ece77be8f7047c2a2c2a629ff417639ba682023f4fedaa3db3 44608 dovecot-pop3d_2.4.1+dfsg1-6+deb13u4_amd64.deb 924eec271a84139bb11e01077d3c075879782e565689c69c703fac21d0774786 1765904 dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 8059e19f212e73b67f6f634d0488fbc378f59cfe99174b28dec1351c97499bfe 381816 dovecot-sieve_2.4.1+dfsg1-6+deb13u4_amd64.deb 73c0f2626915e69db633702c9927e31a2971957c130c5a9577bf9dd339cec059 75364 dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb ba3dcf08b3259a2b31beee0c88d840e1138c16b7506b364be4c9bdd473dc6e3b 37784 dovecot-solr_2.4.1+dfsg1-6+deb13u4_amd64.deb 45c5033b4539121d2a8553531cb2b9739067e6acf5ae3a1e844c35d7288a263c 24680 dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 7322abbbc1dc7983cfc648d86b4943eb968bfe8459dd746e007e1b1706c11cd3 19784 dovecot-sqlite_2.4.1+dfsg1-6+deb13u4_amd64.deb c4e0e1fa6c5dc4b4599e32c8348dc46908525e3be52f071e9c634199e8f528fb 213676 dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 2607ff3211c2f68b0d3d1ee0b3d04fb3eef7a4ec48dd805018516fd70610cba6 61416 dovecot-submissiond_2.4.1+dfsg1-6+deb13u4_amd64.deb 986c8d6bf4b8ae78400a40960eeb028cef7b59c29f71302665ef44eb42319e98 17970 dovecot_2.4.1+dfsg1-6+deb13u4_amd64-buildd.buildinfo Files: 8ecb110ba6fcbb4579dc4affdcaf48c4 32656 debug optional dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb c2aca7b312e6b68ea1d9174a8d74ceda 21784 mail optional dovecot-auth-lua_2.4.1+dfsg1-6+deb13u4_amd64.deb d8b414bef2ea300e3cd4a5d2ae584add 11128780 debug optional dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 3b6445803b791ff0ffbb72b06a8bb094 2717956 mail optional dovecot-core_2.4.1+dfsg1-6+deb13u4_amd64.deb 24576767ede564d86516acb1e862de9f 428904 mail optional dovecot-dev_2.4.1+dfsg1-6+deb13u4_amd64.deb a2f9703932d23ad3752a92eceb22bdc3 190568 debug optional dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 7593cd2193e2d8b87225900550f7c692 42324 mail optional dovecot-flatcurve_2.4.1+dfsg1-6+deb13u4_amd64.deb 1863f52e70f5cdc7f911158862fbdccc 21216 debug optional dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb d6c35140f01a0f4d11bc45a858a51c66 18084 mail optional dovecot-gssapi_2.4.1+dfsg1-6+deb13u4_amd64.deb 535bb6c028637e4fec0fe9ae66e0b772 824580 debug optional dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb e52aae2d7bb9c2e3aa71e57dada64025 195212 mail optional dovecot-imapd_2.4.1+dfsg1-6+deb13u4_amd64.deb 9e5b703630314edb6f627bd3f141646a 195236 debug optional dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb cb4691e9a451abfd8e5b924156597d27 53544 mail optional dovecot-ldap_2.4.1+dfsg1-6+deb13u4_amd64.deb b57c2981d509fb9bc91b4921a30ffd99 101764 debug optional dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 2d6e8b5e164a52cda700ff2fcacd6196 36484 mail optional dovecot-lmtpd_2.4.1+dfsg1-6+deb13u4_amd64.deb b3b495bdd03d545deb5a073c1cc8a974 127628 debug optional dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 51359b3b825b895c81ab2465adf3fef4 48100 mail optional dovecot-managesieved_2.4.1+dfsg1-6+deb13u4_amd64.deb 1b66cf3cad8c87a62e2da798445e1cb1 35360 debug optional dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 4bc2701695d09c44610eec9aeab62d34 20712 mail optional dovecot-mysql_2.4.1+dfsg1-6+deb13u4_amd64.deb 28560cd8601f0593c1051e3d77787426 39124 debug optional dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 7ca3e287a90583dcbbc170f431f3fcb4 24744 mail optional dovecot-pgsql_2.4.1+dfsg1-6+deb13u4_amd64.deb aa1229fa68c98cec2436a0e202a4dd0a 106860 debug optional dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb f9fb6b1acec0284e11a06837ef2bfe46 44608 mail optional dovecot-pop3d_2.4.1+dfsg1-6+deb13u4_amd64.deb e0950241724ec9202be838187f46afd2 1765904 debug optional dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb af88b68efe586c8db7f370624ab9383b 381816 mail optional dovecot-sieve_2.4.1+dfsg1-6+deb13u4_amd64.deb 5edeba37fa0680e0e98251a8b327471e 75364 debug optional dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb 7f127d479a78fc05f009eef6ce5eabdd 37784 mail optional dovecot-solr_2.4.1+dfsg1-6+deb13u4_amd64.deb cd8b69ba1298affe10d911a7c9d51b4c 24680 debug optional dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb eac0bca671d5d646e122b2cc2e1d455f 19784 mail optional dovecot-sqlite_2.4.1+dfsg1-6+deb13u4_amd64.deb 70fe6dff9da422992fcfa11635f8ba28 213676 debug optional dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u4_amd64.deb ab64a2a1f723e0b94cb33a027b548e69 61416 mail optional dovecot-submissiond_2.4.1+dfsg1-6+deb13u4_amd64.deb b7eea53b05c7ed1031bbbc69bfb10b78 17970 mail optional dovecot_2.4.1+dfsg1-6+deb13u4_amd64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmtr4KUMaso2EQ6NrTwt/65ON6zcFAmnPH5kACgkQTwt/65ON 6zdsTg/+LUlIvvipeTQNUlfOO/xkPWdy/E8LKAcNOBnxjV9FDpTW8ceWIewHx4wj sT2QiowGRhb9/8ppPYHoG1XhhDBP23scjOuNPqcxu9ZoNVFpMWEzvSIi/d2tlnhG IBnJRrZAgpJjxrJvAqifEB7fyZRSIxozaXl2nUY02uG0bSciLssQ7GYb1FbU+Cey Scr8FcJpAIGe9cM2uNYOfDFrJ6eR59J4VtY9q4TlyfRGeTmkJ0FpHueLhQhjsAE6 6e4d3l+DmkfSxdK72xgY/Zi60Uco3KnwMrL+WwbDvceHr3VkzFrb/P9DNqbgXY8F cz33cnpGLaw/X1kyMW4thSALRg/xJz0guu9XJEbvyw9KSEcfB0i60xi3Kn5jHJjc dzHnpci3gMqq5q4iS28rVpwDxpK8yjW9XVxa2ItAAD1X2UBuCqqF+UxZmRChtcyN yMUQ61GonIERKaxmWQQkm8pZb8duhxOJBQnf9JNRcM4zHLfUJhIkXISNAW4AYIZH TWK6E4Oy8xm0dcEr8RoewI+M85Jvs+fHL1WZopOXl6ME+KXdWZhwtbUbM3EVBOyg sJRxU4bpY1xaX/mAeDt04F+S0XIr9+buwvWd1Vz9mwDfjgPRTJ1+2z5g27IYoqtl 580WUu2xW4u/mK1yrVHi+pDpWq27V75JTLRGP6LjGMNplnpjpAQ= =hQSP -----END PGP SIGNATURE-----