-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 31 Mar 2026 15:07:17 -0400 Source: dovecot Binary: dovecot-auth-lua dovecot-auth-lua-dbgsym dovecot-core dovecot-core-dbgsym dovecot-dev dovecot-flatcurve dovecot-flatcurve-dbgsym dovecot-gssapi dovecot-gssapi-dbgsym dovecot-imapd dovecot-imapd-dbgsym dovecot-ldap dovecot-ldap-dbgsym dovecot-lmtpd dovecot-lmtpd-dbgsym dovecot-managesieved dovecot-managesieved-dbgsym dovecot-mysql dovecot-mysql-dbgsym dovecot-pgsql dovecot-pgsql-dbgsym dovecot-pop3d dovecot-pop3d-dbgsym dovecot-sieve dovecot-sieve-dbgsym dovecot-solr dovecot-solr-dbgsym dovecot-sqlite dovecot-sqlite-dbgsym dovecot-submissiond dovecot-submissiond-dbgsym Architecture: armel Version: 1:2.4.1+dfsg1-6+deb13u4 Distribution: trixie-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Noah Meyerhans Description: dovecot-auth-lua - secure POP3/IMAP server - Lua authentication plugin dovecot-core - secure POP3/IMAP server - core files dovecot-dev - secure POP3/IMAP server - header files dovecot-flatcurve - secure POP3/IMAP server - Flatcurve support dovecot-gssapi - secure POP3/IMAP server - GSSAPI support dovecot-imapd - secure POP3/IMAP server - IMAP daemon dovecot-ldap - secure POP3/IMAP server - LDAP support dovecot-lmtpd - secure POP3/IMAP server - LMTP server dovecot-managesieved - secure POP3/IMAP server - ManageSieve server dovecot-mysql - secure POP3/IMAP server - MySQL support dovecot-pgsql - secure POP3/IMAP server - PostgreSQL support dovecot-pop3d - secure POP3/IMAP server - POP3 daemon dovecot-sieve - secure POP3/IMAP server - Sieve filters support dovecot-solr - secure POP3/IMAP server - Solr support dovecot-sqlite - secure POP3/IMAP server - SQLite support dovecot-submissiond - secure POP3/IMAP server - mail submission agent Changes: dovecot (1:2.4.1+dfsg1-6+deb13u4) trixie-security; urgency=medium . * [bc29057] CVE-2025-59028: auth: Don't disconnect auth client when invalid base64 SASL input is received * [fee7a9a] CVE-2025-59031: stop shipping the decode2text shell script * [9a4442e] CVE-2025-59032: managesieve-login: Fix crash when command didn't finish on the first call * [2711b3e] CVE-2026-24031, CVE-2026-27860: auth: fix ldap and sql injection * [d30f1c3] CVE-2026-27855: fix OTP authentication reply vulnerability * [e1b0ff7] CVE-2026-27856: doveadm: fix timing oracle attack * [b8a69bf] CVE-2026-27857: fix resource exhaustion DoS in NOOP command parsing * [85dd068] CVE-2026-27858: fix pre-authentication managesieve memory consumption issue * [880e332] CVE-2026-27859: fix uncontrolled resource allocation when delivering specially crafted email messages Checksums-Sha1: 3e952353e6659cd7b28bce0620ec4a9917e0db6d 31984 dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 38fd375c0d4f3a48945e5ce4338cb2e3b673e5ef 21172 dovecot-auth-lua_2.4.1+dfsg1-6+deb13u4_armel.deb d4fe1620e4b6eff83ca8a73928b25adf2d576f01 9681156 dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb b4aa6830091998257bf0a41f497c9078807fb7ef 2388008 dovecot-core_2.4.1+dfsg1-6+deb13u4_armel.deb 1c7a705b84b56e7cdaae6eef1f4cf3ffa023f5d5 428924 dovecot-dev_2.4.1+dfsg1-6+deb13u4_armel.deb eab784ded1c419d19e4616ce94dc4cf5b6ae53ad 185068 dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 34f0e398a98a266760e172cb031d1f54c3f030a1 38456 dovecot-flatcurve_2.4.1+dfsg1-6+deb13u4_armel.deb acd0fd4a0201c36580be712a4e8017f426ee9b13 21364 dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 197f5005a747a8a2723d7f0bbb939927683e8cf8 17608 dovecot-gssapi_2.4.1+dfsg1-6+deb13u4_armel.deb 57ee3b5df5fc302ff426f19d912cf3c9091f43a5 724576 dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 652371789ec31b629942e6f16e597b47af7f8838 172216 dovecot-imapd_2.4.1+dfsg1-6+deb13u4_armel.deb 03603638e156cda7467864bcf28d0322d5a5e08d 164064 dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 6de0d2adb43e091c6fddd84b60541b9686f2e0e0 48272 dovecot-ldap_2.4.1+dfsg1-6+deb13u4_armel.deb 8f4295ca842bb4c3533000b762b43133669bbcee 99768 dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb b46ea621edc4b79d223c39f8aacaa9c207c880aa 34240 dovecot-lmtpd_2.4.1+dfsg1-6+deb13u4_armel.deb c2acd4b3034202996fd092acc73914a399be5206 115820 dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 98676d2778b3498642bf854b6685fc68d94d6cf1 44528 dovecot-managesieved_2.4.1+dfsg1-6+deb13u4_armel.deb 4a8e250e645aeaaf6273cd4acb4768e0e7f0f201 35384 dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb b0abe1c6aee487dc97f1706209f2cd5e0dc1db92 19568 dovecot-mysql_2.4.1+dfsg1-6+deb13u4_armel.deb f25b8d7cced5aa0abb616f9ca6e3cdb0d3fe2aef 38836 dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 9b2c81ceffb900d277b55a1ddcd58591f56412a9 23556 dovecot-pgsql_2.4.1+dfsg1-6+deb13u4_armel.deb 546051d42c5e9f7646e088c0b085063da7851677 101940 dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 3863f8e101cb324d87350c48118a58dcfb949acd 41256 dovecot-pop3d_2.4.1+dfsg1-6+deb13u4_armel.deb da109aa124767a7736c003e32213a958708f2ac3 1649112 dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb e1385f8dacc27edc37bb5dd2ebb57dafba447e37 329792 dovecot-sieve_2.4.1+dfsg1-6+deb13u4_armel.deb 66bd98d8afeae62be3b353b7e0360aa5e301daf8 73856 dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 0c8125d2cc92b5fba6be257844054486e6d5bd6d 36364 dovecot-solr_2.4.1+dfsg1-6+deb13u4_armel.deb bc5083657b42cba985a0a9b8748ee6931a83cdaf 25104 dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 4213886162d0fc8386c4e15590741dc0c7516b7b 19028 dovecot-sqlite_2.4.1+dfsg1-6+deb13u4_armel.deb 0387e7bf2a6039fa013b44b0fd37dae9e7a77b3b 205192 dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 53b258897cb0b00aa95f46d18a934763f3cf2af6 55192 dovecot-submissiond_2.4.1+dfsg1-6+deb13u4_armel.deb 88cc854c5ffe425965de98412337160f869b40bb 17816 dovecot_2.4.1+dfsg1-6+deb13u4_armel-buildd.buildinfo Checksums-Sha256: 880779a9ed46e898e1a19aec5ee87622c4271f13c398e888920b75ec7a663c3a 31984 dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb ef2d2ed270d7a0abdc79c34941ec8bdc2d174a057713d0045a802f177f6ac632 21172 dovecot-auth-lua_2.4.1+dfsg1-6+deb13u4_armel.deb 119ac333422457aeb99da9b53ccfa99a15e581095062dea369296e1c27c74b45 9681156 dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 8687b99e02051ce7d546afa755bae5e03977bf3fc18f9e9c171d503b1b4bbcf1 2388008 dovecot-core_2.4.1+dfsg1-6+deb13u4_armel.deb 7c1f9a5b470e7bee08804e6308149cdc356d0292555d3af850ce0117587f8445 428924 dovecot-dev_2.4.1+dfsg1-6+deb13u4_armel.deb 0146c22588955e554c8c01a27728168c2c75091561a15ae1443b6456f1319a0d 185068 dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 841c8fbcbf1a057339ac0851000a71d3e6925688a2ad9ec9517438edeeece975 38456 dovecot-flatcurve_2.4.1+dfsg1-6+deb13u4_armel.deb 5791059f1f70641ad9bda7744c233dd8a139d6565add3d490072847f6646be51 21364 dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb fbb22fbe74d234da5f0f7c7df21a87fdba689461364e1478e86a654f3234e3eb 17608 dovecot-gssapi_2.4.1+dfsg1-6+deb13u4_armel.deb ed3d75efdade81cd1db4256dd1f8cd862eb43c9d26a1ab9f9f1d89fe54b2f024 724576 dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 9889542dd96036dc1ad410c82ab8fbb5eee222978c5280adccff02990c4a7e5c 172216 dovecot-imapd_2.4.1+dfsg1-6+deb13u4_armel.deb d6c82ed318c06f0345ba5cc0ebbba188b0d672fa9425152fc48c081549d1bedd 164064 dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 452d0a902718f3eda5939d851f2840e6b8ed7d9321cf1def05ba429ddb88d9b9 48272 dovecot-ldap_2.4.1+dfsg1-6+deb13u4_armel.deb a62869ba29ca1806dba861e7c88f333fe43ffc339ffbf4a38765abcbf8920870 99768 dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 94e8c238fb8be41c02b86385de20afdae89533db41b3dd0dd2abc95d1ca82f24 34240 dovecot-lmtpd_2.4.1+dfsg1-6+deb13u4_armel.deb bd40fe14afc7eff8f0b469a651765063e0e772fbd3e735a13a4b41bd7a97e4b4 115820 dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb a56d0091c0152bfa7d6c3af499dfb91a1d3bbedf26e21ed6333b0cf63367e617 44528 dovecot-managesieved_2.4.1+dfsg1-6+deb13u4_armel.deb 1a2f34022deb4d5045ba682e60062ed45dca3371057e178e8b9e4922a22f3d51 35384 dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 0c4c5455a4d15bd24c8d7dce18711af3a66b8422988b87374a14fff4f30780f8 19568 dovecot-mysql_2.4.1+dfsg1-6+deb13u4_armel.deb 26f76cb2cfbd1076b0d46ecab503ab4c6793998a0158f09855f93b627ef3880e 38836 dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 09f76852d40b8dbc5a886f8ac006556b28af1e1761126349f5ef143d8bea13f7 23556 dovecot-pgsql_2.4.1+dfsg1-6+deb13u4_armel.deb 3f9ac47bce1c935269af5e3f57d1705720812d933ce050a6cc1f76f6d56b09e5 101940 dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb c5a802ae4a2874fefa77864f4516cae496888f974743835bff3f473513fe336a 41256 dovecot-pop3d_2.4.1+dfsg1-6+deb13u4_armel.deb 0cdbfb1bd7bf64eff186b0aafb9e6706c9fe15cbc343cf5eec13d040f6165896 1649112 dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb e9e530b73b9812fec10aaf172c213cad9e1528632887478aeb392748e8712360 329792 dovecot-sieve_2.4.1+dfsg1-6+deb13u4_armel.deb 225c65f089f1b2de604ed0efa16a8d24ad3a7817ac8c0e0206aab493504627f4 73856 dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 061d2e3a70fe558472693b5e5c9e5e792078a9a12fad56d11ef86d947495c6c6 36364 dovecot-solr_2.4.1+dfsg1-6+deb13u4_armel.deb 27a89a983a9e016d7bf0fb4f151d4bed83f36abc006b4a6c69ba03a3c7ee3b96 25104 dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 02a917ca098d7e1c2a4aaef9dbde58061d4bd66b67881cc984d7130b3abdb7af 19028 dovecot-sqlite_2.4.1+dfsg1-6+deb13u4_armel.deb 63ea5bb0b51c86196925576ba4fe791b70db7df80ffcc553e5df7d16dd9dfa04 205192 dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb f112e7ae7c661cc2de6f0660862fa9dd13a5cbb303e0b13ab912c79beb10ec47 55192 dovecot-submissiond_2.4.1+dfsg1-6+deb13u4_armel.deb 51bbc8720114488e468941a969344bb64b02c3346b71a5d3e8bfbbd620918f41 17816 dovecot_2.4.1+dfsg1-6+deb13u4_armel-buildd.buildinfo Files: 2babf6801f2113538f5dc87a094c419e 31984 debug optional dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb d11b90e5f9a8db35f328582b9f746ff6 21172 mail optional dovecot-auth-lua_2.4.1+dfsg1-6+deb13u4_armel.deb cba34cdf6fbbb7542616552c455f573b 9681156 debug optional dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 9ac75092dfdb1468af94dda95bcfb396 2388008 mail optional dovecot-core_2.4.1+dfsg1-6+deb13u4_armel.deb 409542a74953d14c49e28e42abc472dd 428924 mail optional dovecot-dev_2.4.1+dfsg1-6+deb13u4_armel.deb ed9989ccf2bf867940c4ef3dd5c9704c 185068 debug optional dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb e7809e3d3fb0b24a2b02d0c9a477fafb 38456 mail optional dovecot-flatcurve_2.4.1+dfsg1-6+deb13u4_armel.deb 2be5b27339bb08e14ddba0a4568f3769 21364 debug optional dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 518cb346a1c530b45c2839f60344d259 17608 mail optional dovecot-gssapi_2.4.1+dfsg1-6+deb13u4_armel.deb ad58ff3c8b9c50fbc9a90c4dd679e929 724576 debug optional dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 37149e77fbadf10e07b1cca7511f38aa 172216 mail optional dovecot-imapd_2.4.1+dfsg1-6+deb13u4_armel.deb 4c5b3864f8e1a30dcbb032c843661708 164064 debug optional dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb ef41d4da8c432f7fe3211b8a429dea93 48272 mail optional dovecot-ldap_2.4.1+dfsg1-6+deb13u4_armel.deb 846dc16711990f76ca9eeec8ff6355ee 99768 debug optional dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb f4d15f458e4ae140c1fc4f9af6e897d2 34240 mail optional dovecot-lmtpd_2.4.1+dfsg1-6+deb13u4_armel.deb dc8915fbc62d2b5c158e542a89b291e8 115820 debug optional dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 54b5daa21ee32a41d1dd30e9a4874e2c 44528 mail optional dovecot-managesieved_2.4.1+dfsg1-6+deb13u4_armel.deb 69783349f7e67802b260ebdfd89e3791 35384 debug optional dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 7acd0d9569a5aec5c58019e45a3bda4c 19568 mail optional dovecot-mysql_2.4.1+dfsg1-6+deb13u4_armel.deb 38f09738fda7669dba0c09201fa9d624 38836 debug optional dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 6efdfd5913fd530ec2839c4a1df0addd 23556 mail optional dovecot-pgsql_2.4.1+dfsg1-6+deb13u4_armel.deb 6aa6596013be8cfbaf8f3d6d6865675b 101940 debug optional dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 4af5bd926984f4da7fb6428f09c308fb 41256 mail optional dovecot-pop3d_2.4.1+dfsg1-6+deb13u4_armel.deb a38bedd01b2a06362c63ba22d589522d 1649112 debug optional dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb cc401ed4b8604fdff3ca2023c1382e2b 329792 mail optional dovecot-sieve_2.4.1+dfsg1-6+deb13u4_armel.deb 088bd2e8ad08e9cd889d96bafab93317 73856 debug optional dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb b352b7b40941dba70c5e2cba8fac8762 36364 mail optional dovecot-solr_2.4.1+dfsg1-6+deb13u4_armel.deb 510b7519d641e60480db813e84ddbac6 25104 debug optional dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 24440021d106cc70d8366073fd96a8c7 19028 mail optional dovecot-sqlite_2.4.1+dfsg1-6+deb13u4_armel.deb 6377d2707e3a132a1d929137ff1b20a4 205192 debug optional dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u4_armel.deb 32c690e1db3b64988ab94fdd6f9bce37 55192 mail optional dovecot-submissiond_2.4.1+dfsg1-6+deb13u4_armel.deb 5f9e99bf6da1ea019783c6a91eee5f8f 17816 mail optional dovecot_2.4.1+dfsg1-6+deb13u4_armel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEWHj9K9pO9l4btbD1OQKMdMnEH5MFAmnPIBkACgkQOQKMdMnE H5NrgxAAotM3WJ1YOmGuKHt5LuRLRiRdAwV37TIH0VsFINPmw2m46WvcR17y0Qx5 IROmstMgOROzMpqYe4e8uC3OhMQNKg8c1RhSVCdD38fe7G0ds2jlNuBY2n+9Ppn0 qgPdL+KYJwf2IonyBrFctyPTPw0WOc1Zbung4nCfbBmvC+PygkejKE2uOIIqEZzV ZtXsmh+tVT37vL4QDBah/bTutm5YCIb7DQ7/4Z60l3XazdcBvFuFdM2ivn9dOcCy T+MS0bLMcjLzw4179gfSjGZGS/S4f9/0d7G2eM1ROlvnUHjrcPAxy+FbscfLxASp GRHnN3lCFDUpKnXhRmFa/eD7FNtCS1attw+7aNnXZP0q7YSK+2egm9/k6OGRPVRI xR+4FhxK4aGHZ6X/A+jCU5eW6jaICry3qbkMLHbngb2TRBmChWMT5wG15v2SW06Z VCpqrwxNNleCK8Wk6IvDYLgJxyrmEkiZRWwIo4oQMgOisxplEg4+1gITYB0TzBWv N5fEZc+zu2MADiaQaicD8/pZV1OdY0FhImBDBi8t7qjRXONGFW4Zsex8tfi0gUPE UV9zUOUcWbKQV5VDbm8BV7qEXgxUSUaZqisyoHaHgbPg4ee7flpHH+4nX72+v0Wj N7jDeNx+AEY68ezvNaqwEt3M1RVr2yiCPRy2eKdKijBjUwnBZSM= =HOtU -----END PGP SIGNATURE-----