-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 31 Mar 2026 15:07:17 -0400 Source: dovecot Binary: dovecot-auth-lua dovecot-auth-lua-dbgsym dovecot-core dovecot-core-dbgsym dovecot-dev dovecot-flatcurve dovecot-flatcurve-dbgsym dovecot-gssapi dovecot-gssapi-dbgsym dovecot-imapd dovecot-imapd-dbgsym dovecot-ldap dovecot-ldap-dbgsym dovecot-lmtpd dovecot-lmtpd-dbgsym dovecot-managesieved dovecot-managesieved-dbgsym dovecot-mysql dovecot-mysql-dbgsym dovecot-pgsql dovecot-pgsql-dbgsym dovecot-pop3d dovecot-pop3d-dbgsym dovecot-sieve dovecot-sieve-dbgsym dovecot-solr dovecot-solr-dbgsym dovecot-sqlite dovecot-sqlite-dbgsym dovecot-submissiond dovecot-submissiond-dbgsym Architecture: arm64 Version: 1:2.4.1+dfsg1-6+deb13u4 Distribution: trixie-security Urgency: medium Maintainer: arm Build Daemon (arm-ubc-01) Changed-By: Noah Meyerhans Description: dovecot-auth-lua - secure POP3/IMAP server - Lua authentication plugin dovecot-core - secure POP3/IMAP server - core files dovecot-dev - secure POP3/IMAP server - header files dovecot-flatcurve - secure POP3/IMAP server - Flatcurve support dovecot-gssapi - secure POP3/IMAP server - GSSAPI support dovecot-imapd - secure POP3/IMAP server - IMAP daemon dovecot-ldap - secure POP3/IMAP server - LDAP support dovecot-lmtpd - secure POP3/IMAP server - LMTP server dovecot-managesieved - secure POP3/IMAP server - ManageSieve server dovecot-mysql - secure POP3/IMAP server - MySQL support dovecot-pgsql - secure POP3/IMAP server - PostgreSQL support dovecot-pop3d - secure POP3/IMAP server - POP3 daemon dovecot-sieve - secure POP3/IMAP server - Sieve filters support dovecot-solr - secure POP3/IMAP server - Solr support dovecot-sqlite - secure POP3/IMAP server - SQLite support dovecot-submissiond - secure POP3/IMAP server - mail submission agent Changes: dovecot (1:2.4.1+dfsg1-6+deb13u4) trixie-security; urgency=medium . * [bc29057] CVE-2025-59028: auth: Don't disconnect auth client when invalid base64 SASL input is received * [fee7a9a] CVE-2025-59031: stop shipping the decode2text shell script * [9a4442e] CVE-2025-59032: managesieve-login: Fix crash when command didn't finish on the first call * [2711b3e] CVE-2026-24031, CVE-2026-27860: auth: fix ldap and sql injection * [d30f1c3] CVE-2026-27855: fix OTP authentication reply vulnerability * [e1b0ff7] CVE-2026-27856: doveadm: fix timing oracle attack * [b8a69bf] CVE-2026-27857: fix resource exhaustion DoS in NOOP command parsing * [85dd068] CVE-2026-27858: fix pre-authentication managesieve memory consumption issue * [880e332] CVE-2026-27859: fix uncontrolled resource allocation when delivering specially crafted email messages Checksums-Sha1: 8bb24cc756b76c3bfc7c4c39bfcd44c8709098b6 31904 dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 74deda64ea518800e872ae01bc2799583f84dbf0 21212 dovecot-auth-lua_2.4.1+dfsg1-6+deb13u4_arm64.deb f592cbfda31b4194e3ccc1ab4bb35c1824ccef38 10737696 dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 43ee9330f82731c98b78b6a4d989eb3630895a89 2501752 dovecot-core_2.4.1+dfsg1-6+deb13u4_arm64.deb a3dc46bec55cac5d8c20d0061cdc5f165f79d31c 428904 dovecot-dev_2.4.1+dfsg1-6+deb13u4_arm64.deb 18a8517d97a1429cd67b6b01c0a6662c75048bf8 185664 dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 878738e44171dc955464475f9b3a50b720001ae2 39824 dovecot-flatcurve_2.4.1+dfsg1-6+deb13u4_arm64.deb 0a63a79435f5bcbcec8678712b43763838962153 20956 dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 3e65d48144b9cfa81749befc2d9d1c31ebdb4ea9 18124 dovecot-gssapi_2.4.1+dfsg1-6+deb13u4_arm64.deb 37a178019dceb99535c41fcabcb2eafc4fe76276 802872 dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 7a9ddcf09956c0a09161d810a4ce9e9ab6181629 182348 dovecot-imapd_2.4.1+dfsg1-6+deb13u4_arm64.deb f7f8a2822eccd334f5675422f8902a82f033e05b 189700 dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 28a94a30a2941036f077b95e591c5b7bc79b7e88 50752 dovecot-ldap_2.4.1+dfsg1-6+deb13u4_arm64.deb 32106366e038c764bcdab5018f7b825d6068af17 99612 dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 392f808a421d6e57a1efa97e57889ecc1a1ef922 35196 dovecot-lmtpd_2.4.1+dfsg1-6+deb13u4_arm64.deb 39f26f5b7e7024dce7ed804110fe7169ec3cdf91 125516 dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 7dbd8bc80fd2e352d489928fc6d42766fb0df585 46552 dovecot-managesieved_2.4.1+dfsg1-6+deb13u4_arm64.deb a004db2a85f5442864acbb8f0b12b0ac162445ae 35192 dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb a7c1809e6f0b29452458edbab3648c4f1a7261d6 20356 dovecot-mysql_2.4.1+dfsg1-6+deb13u4_arm64.deb 46aaa1233aa4df21624800a6a39d38eb1cc85dd3 37776 dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb eef69c380f99bf0d061674d4fa714470c42e83dc 23456 dovecot-pgsql_2.4.1+dfsg1-6+deb13u4_arm64.deb fee8e8940437a8659865c9c64580a336fdf58e50 104904 dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb bbfbaae3d1d51bfb638f08e8c393b871a63a5707 43040 dovecot-pop3d_2.4.1+dfsg1-6+deb13u4_arm64.deb 46bb983a90ab8d0c663baaad6a8b9b3c31f7a8b9 1716056 dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 38cbe50b4e6386f355bab065e8d12d819718e6b2 350808 dovecot-sieve_2.4.1+dfsg1-6+deb13u4_arm64.deb 811e7df0d3a1477ad95dfa9f5cebb000f0b1baa0 73908 dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb d0423a5119aed4650b7043016b4bf7edc6f7bb8f 37072 dovecot-solr_2.4.1+dfsg1-6+deb13u4_arm64.deb 526fcb0ed57907c5cb33ade4619f904598731dad 24456 dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 1e3d39932eb0998b7ab4eccf0cde8d89a5466f4b 19596 dovecot-sqlite_2.4.1+dfsg1-6+deb13u4_arm64.deb 3a4cbbfafa3d840084542aa34b63fe589a0a0c87 208756 dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 940b2fa3e11dce449c9c2cbedc13b5428f76eb24 57972 dovecot-submissiond_2.4.1+dfsg1-6+deb13u4_arm64.deb abcf27582d69b2ae1dbb0b8943d8c14c9d50d791 17954 dovecot_2.4.1+dfsg1-6+deb13u4_arm64-buildd.buildinfo Checksums-Sha256: d75062e1fbea0b933eca0e24888dd696ccaa1a0291fda696d1564733ee00eab3 31904 dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 224db5e17877338c4750b42ded99fa3e1cf690a4229e6b76a29783a8e6a6438d 21212 dovecot-auth-lua_2.4.1+dfsg1-6+deb13u4_arm64.deb 211e2b379942587ffe988cc48d4f25e06d5e0a89f7a620edc1d5a2af511b1585 10737696 dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb e701bcb9c42f9fbdef51fefc46088ac9422a1e283a9e716776d897142039b495 2501752 dovecot-core_2.4.1+dfsg1-6+deb13u4_arm64.deb 2bba340c4c5f9aa981aee8aa3ca67cd114dbebda458cdea2fdb840b18e9084a4 428904 dovecot-dev_2.4.1+dfsg1-6+deb13u4_arm64.deb 8d153d583436895cbe7ed3d42f3e758f39851ca3248561adef3edde65253c4da 185664 dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 8dcfde149c1d89264df0a54327d5d0f76c5f03cdf594f00d5d4c87630b5ab219 39824 dovecot-flatcurve_2.4.1+dfsg1-6+deb13u4_arm64.deb f3afe01d3bce44a8a3e8d25274a6e14e894119c48a54ea889d835eb51f93de5d 20956 dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 5f219d70c69789c08d8b475f27ae266a73d3fef948426d4947751b652aa323eb 18124 dovecot-gssapi_2.4.1+dfsg1-6+deb13u4_arm64.deb ce8d31b3fb07c9046cb70a3aa7697e7221ed1571a76c7ce63a4c40c4ec3237ad 802872 dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb e8dc8b87ccec58b48a4d4f504c4211fa7d13717cf9bcc0f4422d4bc0bda5c7b9 182348 dovecot-imapd_2.4.1+dfsg1-6+deb13u4_arm64.deb 1dee47a4e4c489302965ca71e7726d7957e527b47c0f4849ab08e52c84723051 189700 dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb c078bb60d7f0ebee2d53259f285663994c1aad04e27f0a10dde85157cd7c92e6 50752 dovecot-ldap_2.4.1+dfsg1-6+deb13u4_arm64.deb fccb69b9832e033ae478e31fd7dc09e3822e907a3e917efb0d549bfcda5d8d0b 99612 dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 4e4286b0d7c63c99ddb0f5d806284216531624bfc67930df60ff8bf8323a2d57 35196 dovecot-lmtpd_2.4.1+dfsg1-6+deb13u4_arm64.deb ce06e517ffd234b8dd3ebd1eb1ef5814bef3e23381f7fe04503a362e1f96937a 125516 dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb d7f5f71ca2ab54ca064e6be72153029e8d5e1dc167703e71d46b9f1eb9c92833 46552 dovecot-managesieved_2.4.1+dfsg1-6+deb13u4_arm64.deb 9eecc892ebfda31545220027fda4d7b8d62b6905c441a556465fee9f549224c7 35192 dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 96c09f1b375dc126719febc95d58860d0cae488e6a2dd09f4e3e4cc971707583 20356 dovecot-mysql_2.4.1+dfsg1-6+deb13u4_arm64.deb 3cb323bc2fe24c249ab634f0acc9599bcec58bc5689cfe6b41f3ed01ccea9bcc 37776 dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 96fadd3dc69e989c623624de31fde93d7447534e8664a35de5ee14653e2cb372 23456 dovecot-pgsql_2.4.1+dfsg1-6+deb13u4_arm64.deb 996155d4f917457d1d162312aa42cd656c050c69fa7615ed4d8f37285f198fcb 104904 dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb b51caeb7646b5fc5f589a023f5371e893ffcc477e7130186a54caed955531599 43040 dovecot-pop3d_2.4.1+dfsg1-6+deb13u4_arm64.deb c49ce494cf1bbdb28d5e4aac7dbdb01225d240e981119840584c97c14a456361 1716056 dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 1fe2cd05d9c336a211af04688652c25a14a1ff146f3cbf15230fd85de496baf7 350808 dovecot-sieve_2.4.1+dfsg1-6+deb13u4_arm64.deb 3ed060a197d8b37ed237e1be6df1990d6bdce97ecc020592564d7ceb3b3b0ae6 73908 dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb fef05d11e92240e5a4739042272d52d7045e13734d879b7568a87fdbad812657 37072 dovecot-solr_2.4.1+dfsg1-6+deb13u4_arm64.deb 5271cf25adb56fb931a713e14027ec32b6b2b2352cf9d8185e414b0ffa81e5c1 24456 dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 34b2cc6089c1b1ac57eb81f44862592b05f3ff489bad48a66642725d57631791 19596 dovecot-sqlite_2.4.1+dfsg1-6+deb13u4_arm64.deb 5b128b061d872c6e883c2563faf125b8feb490b0dc019e22c66a0ed1774d63be 208756 dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 50c2389f1c852fe10b3635cd0f5602e7b7fbd8f110671a442203ed13dbc13083 57972 dovecot-submissiond_2.4.1+dfsg1-6+deb13u4_arm64.deb 0b33fcd3fe5366dd6e30a6dab878e304c6f85950f97ad2483877cfc8f5cd7e65 17954 dovecot_2.4.1+dfsg1-6+deb13u4_arm64-buildd.buildinfo Files: 59d1140e79e0c18812378fa15829d548 31904 debug optional dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 92cae08aea9ecac9b12a82766656569c 21212 mail optional dovecot-auth-lua_2.4.1+dfsg1-6+deb13u4_arm64.deb 19a664e629e19e6a96dd2c34ec73e59a 10737696 debug optional dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb d749bba44cd710d3a1fc16632eb51cb5 2501752 mail optional dovecot-core_2.4.1+dfsg1-6+deb13u4_arm64.deb 85de937e749d1c82a1ade725d42b2664 428904 mail optional dovecot-dev_2.4.1+dfsg1-6+deb13u4_arm64.deb 715c18b9c35677da02e3ae4f9c302593 185664 debug optional dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb d65f530bd18b1ab71dbdec5e3f4314ed 39824 mail optional dovecot-flatcurve_2.4.1+dfsg1-6+deb13u4_arm64.deb b5ca560921c87a8638b89b9e80e95fce 20956 debug optional dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 8dffed51f38921059c39df8a8071d90f 18124 mail optional dovecot-gssapi_2.4.1+dfsg1-6+deb13u4_arm64.deb 3d767d152f1107e6d88fa1049de3b172 802872 debug optional dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 20a296c8db6dcb7871ab92d80dd973d3 182348 mail optional dovecot-imapd_2.4.1+dfsg1-6+deb13u4_arm64.deb 12741a0c52a6f144e20f87898c588042 189700 debug optional dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb bedae8960e15c2f8259dcd181df0266a 50752 mail optional dovecot-ldap_2.4.1+dfsg1-6+deb13u4_arm64.deb d82213e92e255097bf76a9de67f48335 99612 debug optional dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 91659fbd782809b0af003cfbeb40c4d3 35196 mail optional dovecot-lmtpd_2.4.1+dfsg1-6+deb13u4_arm64.deb 46dafc35349db5865bd4a56ad16a49e3 125516 debug optional dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 0ddcfb7f89907bf094f43eecee9a711b 46552 mail optional dovecot-managesieved_2.4.1+dfsg1-6+deb13u4_arm64.deb c67679b5ec2831e8d941212db7820654 35192 debug optional dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb cf38a2c6a7b88123f2f6807f0be4c490 20356 mail optional dovecot-mysql_2.4.1+dfsg1-6+deb13u4_arm64.deb 862b6395b8b85d11bf745262b52bfb60 37776 debug optional dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 17616a7da8fc225f55b5b3807f867d94 23456 mail optional dovecot-pgsql_2.4.1+dfsg1-6+deb13u4_arm64.deb 6ef939bcb36560e79674f3717e4e3b7b 104904 debug optional dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 99fe3c89753a06234094548bfe507593 43040 mail optional dovecot-pop3d_2.4.1+dfsg1-6+deb13u4_arm64.deb 1ccbf09e8b0a935ce9fcca32ae186f59 1716056 debug optional dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 8dfbb79b50fd85d1917beb2958511363 350808 mail optional dovecot-sieve_2.4.1+dfsg1-6+deb13u4_arm64.deb f30278385f4bd8052e55607a2d761085 73908 debug optional dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb c0c198a0e8737d31b5e64bfaef86d9d2 37072 mail optional dovecot-solr_2.4.1+dfsg1-6+deb13u4_arm64.deb 138f4fc197a57aa5037f6bd8881235f8 24456 debug optional dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb b119d8a89c4a9f844db9c9f834a6733a 19596 mail optional dovecot-sqlite_2.4.1+dfsg1-6+deb13u4_arm64.deb 7f58665836983d571fa3c1a35f51c31d 208756 debug optional dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u4_arm64.deb 8aad3a124ad620def6ffcab05804d2ca 57972 mail optional dovecot-submissiond_2.4.1+dfsg1-6+deb13u4_arm64.deb 7bf9395715a2e4767fb941d49bffe82e 17954 mail optional dovecot_2.4.1+dfsg1-6+deb13u4_arm64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0Ha//LlsGOpbQ/H4xqCFmsOWgoYFAmnPH6MACgkQxqCFmsOW gobWqhAAgl5hG9aK8Ix7XPkiPrD/9+TnUXKiwwVYK6fMWtQ98GCyOybONyR+KFbp w0KilyV1YSLiBW4SMCVp36AzBApSgZp31D6z4C8jNbc5KtdFQvxhwIO7YMjq5fsf F79I3QDppLI/S5Wxj+cySkQnqZrctbvEnU/UXw6LOFlIqtsAh4TC+hnx0BpCdA5T G53WCPGOncxgaWBU3ykVqJayrcKRph9zPfwX9vZ5bEeTKV7KW91gMgntPBN7DoNb xQ93ontSfsx1VNlBjB7YRlRWGPGo3O8+kifc9eSlaz4tQ0OXqSfSpWhIgfF8dRdL 2wJY3MegjFRErhGR8Jn45XHzDPT8wk1T5G5Ac0wLWd+497P/7LfGM64QjYqpzZpw d3kW1pCXSkzpZd4my9iKs2ktELrnGiK8bvxLq+Mq7sjT19D7OdAVmQCpJD1yrpEe 0HaAu0GHctqHLDCn4NGVCTuRI0nUifi3Y9gQHxmdHlC35rkaENeQeJKeS/C0XAEd jggSmuFgCDCrjomDbtxXZB0sR/tJhO7Aa0gtJjskAQ5ipX/UpEvdidewfsWummuZ hFUbz/Z3BuiCMDnp0z7ED1f/AXBX+8qkrWNd3zL8F8tZRUUmDm9gRHHe17xEmvX0 YYHS+hach1IJGbgHrf+8GOmYe6n9SLUkIfV2oElYehZNh82RPGY= =g8d0 -----END PGP SIGNATURE-----