-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 18 May 2026 14:11:58 -0400 Source: dovecot Binary: dovecot-auth-lua dovecot-auth-lua-dbgsym dovecot-core dovecot-core-dbgsym dovecot-dev dovecot-gssapi dovecot-gssapi-dbgsym dovecot-imapd dovecot-imapd-dbgsym dovecot-ldap dovecot-ldap-dbgsym dovecot-lmtpd dovecot-lmtpd-dbgsym dovecot-lucene dovecot-lucene-dbgsym dovecot-managesieved dovecot-managesieved-dbgsym dovecot-mysql dovecot-mysql-dbgsym dovecot-pgsql dovecot-pgsql-dbgsym dovecot-pop3d dovecot-pop3d-dbgsym dovecot-sieve dovecot-sieve-dbgsym dovecot-solr dovecot-solr-dbgsym dovecot-sqlite dovecot-sqlite-dbgsym dovecot-submissiond dovecot-submissiond-dbgsym Architecture: arm64 Version: 1:2.3.19.1+dfsg1-2.1+deb12u6 Distribution: bookworm-security Urgency: medium Maintainer: arm64 Build Daemon (arm-ubc-01) Changed-By: Noah Meyerhans Description: dovecot-auth-lua - secure POP3/IMAP server - Lua authentication plugin dovecot-core - secure POP3/IMAP server - core files dovecot-dev - secure POP3/IMAP server - header files dovecot-gssapi - secure POP3/IMAP server - GSSAPI support dovecot-imapd - secure POP3/IMAP server - IMAP daemon dovecot-ldap - secure POP3/IMAP server - LDAP support dovecot-lmtpd - secure POP3/IMAP server - LMTP server dovecot-lucene - secure POP3/IMAP server - Lucene support dovecot-managesieved - secure POP3/IMAP server - ManageSieve server dovecot-mysql - secure POP3/IMAP server - MySQL support dovecot-pgsql - secure POP3/IMAP server - PostgreSQL support dovecot-pop3d - secure POP3/IMAP server - POP3 daemon dovecot-sieve - secure POP3/IMAP server - Sieve filters support dovecot-solr - secure POP3/IMAP server - Solr support dovecot-sqlite - secure POP3/IMAP server - SQLite support dovecot-submissiond - secure POP3/IMAP server - mail submission agent Closes: 1136444 Changes: dovecot (1:2.3.19.1+dfsg1-2.1+deb12u6) bookworm-security; urgency=medium . * Security update (Closes: #1136444) * [1d0162a] autopkgtest: test cram-md5 authentication * [d4eed2a] CVE-2026-40016: Sieve :contains/:matches O(N×M) Substring Match Bypasses sieve_max_cpu_time Limit (130× Overrun) * [898776c] CVE-2026-33603: login: Base64 input can contain tabs that bypass IPC protection * [fe76a7b] CVE-2026-40020: IMAP folders can be shared-spammed to everyone * [ce379ba] CVE-2026-42006: imap-login: Excessive memory usage DoS Checksums-Sha1: 3f5d42c97b11a2407d00cd0facfa6160ad5b4759 33208 dovecot-auth-lua-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 4eb38fa69050052d6577f2a100edb20c60808854 1366832 dovecot-auth-lua_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 14137c80bbc581cb558dbbae2d2d8af155aca5b3 10210784 dovecot-core-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb c7bdb644a1386ac263ed2e3e97f8831d5816c86e 4284600 dovecot-core_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 94dabdf91dd696161ae2c8237b828a9c468d5450 1744080 dovecot-dev_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb b240c5c49c80f7b3bf8d19dc5e9b884b2e28c3dc 21588 dovecot-gssapi-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 8666e78ed95fb754c756d9070b45679af11f7d0e 1363436 dovecot-gssapi_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb d91b26e932b4fdb8d89abe289e19597e9ab29bc8 713256 dovecot-imapd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb fd8204361e2a77e7e9259e26f1a8a63f5d1ecca8 1517368 dovecot-imapd_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 93185d123eeef7d28c6ee653491498f79206dd56 117692 dovecot-ldap-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 4537a6ad004cb92cfe2e47371af47973e1431f49 1391508 dovecot-ldap_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 8ded18d9d99688804809d0fadd9692e68d3c2d30 91952 dovecot-lmtpd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 0892180550807b15ed2958a4541d162095cf3e94 1378020 dovecot-lmtpd_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb ba047f2bc11ac4707c8f93cb3743b59ae77ee035 149360 dovecot-lucene-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb bdf055ed610310f5ba419e777045d7aef2351762 1380428 dovecot-lucene_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 9d60cef5c3175b68cae0d3aab469b9812268441a 161324 dovecot-managesieved-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 8050b6dfea090013201f369824a6be52faacad1f 1397312 dovecot-managesieved_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 6b9eed8045257af3194101fc9bb1870427d9fd72 31564 dovecot-mysql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb d589c385e237ee881d32e8ef5d619f2f2cef229b 1364896 dovecot-mysql_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 5f03cb7fc835cacc01a0a9e248f90f987075ccc8 32504 dovecot-pgsql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 08f1f84a202260ac46add79b197da70243a09c48 1367692 dovecot-pgsql_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 2185831b36da152c9efb7ba3a9676c903889c2e2 93428 dovecot-pop3d-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb e0051139895b91493f2d824a388a02c60f96a070 1385064 dovecot-pop3d_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb d8d1d60402a0a56151d7ba68e741ebb6b85b32d3 1553748 dovecot-sieve-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb cd60d2ce4e538bd6d865e1759dab1016acfab39d 1674116 dovecot-sieve_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 9238d09061530a78f9a1fa5eeaa60f3eb8ae61a7 86052 dovecot-solr-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb e8c8263532de5df73ed2f634bb3a0bcf5e1b27e3 1375148 dovecot-solr_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 6954f50aa810b680f7eef68d5e56fda18e7b5877 18024 dovecot-sqlite-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb e5594ba8956cb0539a6b9a7592f3dbd69ebce85d 1363088 dovecot-sqlite_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb b8940a91dde0ba19e20ce3ad704d7de9e1b5c919 180788 dovecot-submissiond-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb d0efc98a9b1d40dd77887f91cc965a220580950b 1399688 dovecot-submissiond_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb bc7b61943f962de7450ced1abd25f63b9f2c9a8d 18863 dovecot_2.3.19.1+dfsg1-2.1+deb12u6_arm64-buildd.buildinfo Checksums-Sha256: cacb02c1bd028130c6e01f73914a97d66e09ba8284987bf411d508db4f74dfb6 33208 dovecot-auth-lua-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb dfa26ff685a54e72aeb1846dca94bf2fbb71614aa4d71d57bb3dd323177fff67 1366832 dovecot-auth-lua_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb f327f5e8fc193cd026a23ee9a4a3ea81e40f750e11db587a0c7c759f6b08e514 10210784 dovecot-core-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb fd46ff79be2f158f6d12c0414822b400a932ad8903d3e7591306f824ea7027ce 4284600 dovecot-core_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 85d15f6eb68b2a56cffbbb365eada4ab383525b5e8b29854afeb853708dd9bb1 1744080 dovecot-dev_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 6c0a6e4076c29d4e9b072554fb57b993f782eadd5e5302629465942d0fbc33a3 21588 dovecot-gssapi-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb b062f780f914c3b2c7c97d3cc37a6539a25c4cfaf35b03bb49d753b1cf826c47 1363436 dovecot-gssapi_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 787e02dceb4dd197d3afa3ceae4c610444d522684729bfd07b41a4d990af7038 713256 dovecot-imapd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb e654048e6920c10d2a336c7792c69a7f1bee89d951789793b331388a39add47a 1517368 dovecot-imapd_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb ec4ec8afbeaf3145455c2fc190ecdc8bebe602c6fcdf463ecaeac5f5855ca8cb 117692 dovecot-ldap-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb cf5b1995ebec5baa6d89b2255e0dcc085e2422e02d0b76cf7cae2eb55eb6cade 1391508 dovecot-ldap_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 22196bec2dbfa8635b05dfe847e05e920470aa9a5ea51a39dc25f67337dc1271 91952 dovecot-lmtpd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 38fcbdf880efa83e03ae32897f711106bf2ebc33383b7ffa851c115d3d9ddf7e 1378020 dovecot-lmtpd_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 1175b868d8c4296b5833f0e17fa54a0378c334efa96c6d3c1b44c2dc64349ebf 149360 dovecot-lucene-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 183b6d01e804f6615632ff17d66538becb2c31519b6b60daeade0b3ce17cf0f4 1380428 dovecot-lucene_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 02fe34a9cfc8f3bdd5de6a78fa3e0421182faa200ad7d9e7e5087d5fd7ac8824 161324 dovecot-managesieved-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 9af3130cf8244b57b025019409d80fd82f68e74fb1114e62e017ed7e4558375a 1397312 dovecot-managesieved_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 1ca8d1c452b1101e436ac71a3a0ce445a95fe6d1a5bf0ff02f6c561ce4e8f5b1 31564 dovecot-mysql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 78b8525e67fedc244e08eb710a2ffd32c8dd3b650e3166a94d805ea0279e58b2 1364896 dovecot-mysql_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb b7133d5867b605f4ee351c5edcf8dce67dc8560f7507d490f7204a5a12f92471 32504 dovecot-pgsql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 43ac893de08d45af119188ac4dae57b4ef82923b6b431c9221ab4202a90d1ae5 1367692 dovecot-pgsql_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 6a5e3347d2f78d6b48f1690867fabeb258be46201ca3346a95b1c4c18cf781c3 93428 dovecot-pop3d-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 18ff188612e3a0fde2f1e216fe9a88850a50f41e2d78e505058def7898d5d019 1385064 dovecot-pop3d_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 4378038ab05db52014aeebb162be7ba53fdfdded3ca7606c2ce652008aa20f5d 1553748 dovecot-sieve-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb e89c182e5ecb4ec4194b97e9dc2a26e856214d55c51c72edc733c62f82b4a6f3 1674116 dovecot-sieve_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 4ee7afedf5f0763f7d3263551708996ceb0c37d740d12c3adb60f3f229e0c84b 86052 dovecot-solr-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 1264ed58f8cdc31ac170bc51f51ae4a80341023230ecd39a2098e40df3c8a4a6 1375148 dovecot-solr_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb f11cd37e89d1a69f1169e788a897313070d8941a68a8269f16d39c2bf23af65f 18024 dovecot-sqlite-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 807e30c83ab5165a078e80ea6faed8ba0e1aa1629146681669ffb45cd1e58811 1363088 dovecot-sqlite_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 5e877458a2e58f4b771542926ffd3643aa16e9e832f974a761a41a984c789178 180788 dovecot-submissiond-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 8d9dc6cc51310c32cc9ab1727b30fbbcfbc23bbfe88daf0939b16242bf66d4ac 1399688 dovecot-submissiond_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 9c3452d7ed87890310de95c3e6ebaa45d3aaf3d39d74f98090db0fcd1099d9e4 18863 dovecot_2.3.19.1+dfsg1-2.1+deb12u6_arm64-buildd.buildinfo Files: 6c4a17c1e1a39ddcae901798b8ddba30 33208 debug optional dovecot-auth-lua-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 88d788bfdb1aecab3c373f8ef4ba4512 1366832 mail optional dovecot-auth-lua_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb d870ebecdb03dd0243ed6a62648d9184 10210784 debug optional dovecot-core-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 9c43cbd2b7f1c44ae6317289ca1cef4c 4284600 mail optional dovecot-core_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb ca607db83978e83bd213abaddfd6902d 1744080 mail optional dovecot-dev_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 95a76f3453f4b95ad70aaf42f28449df 21588 debug optional dovecot-gssapi-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 33649ac9f6fd699d1fa208b7f2e3a981 1363436 mail optional dovecot-gssapi_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb f329c96dc147fdce158c3d65f122b647 713256 debug optional dovecot-imapd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 2098de5a66ab8d3f4f27928d624379fb 1517368 mail optional dovecot-imapd_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb d884ba5f3a117b9e86c63316774a8af0 117692 debug optional dovecot-ldap-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 2f9c385fa2ec9a3268e29b347920f514 1391508 mail optional dovecot-ldap_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 8014a083b5ba1af28e3156eed34d117a 91952 debug optional dovecot-lmtpd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb e6326e26bd942ae9687d0a787641621f 1378020 mail optional dovecot-lmtpd_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 04fa2f11213e5a54eefefafad9654ec1 149360 debug optional dovecot-lucene-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 312298015f5333a2ae1da7b0160e496c 1380428 mail optional dovecot-lucene_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 3fde9a355a616be2b49834eb1e5814cb 161324 debug optional dovecot-managesieved-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 9d482510d85c64b31e31f83e2e760d0d 1397312 mail optional dovecot-managesieved_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 9b55e1ac0dd29ce2467206d549e77bc6 31564 debug optional dovecot-mysql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 2d4d6142b5649af986bed7169338ee40 1364896 mail optional dovecot-mysql_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb c401daec13e7e4d7d9e8bb01d111235d 32504 debug optional dovecot-pgsql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb f9e36be5031aa155aba61032fc5f6573 1367692 mail optional dovecot-pgsql_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 052e4f2b13f8d4f2aeec74d095238997 93428 debug optional dovecot-pop3d-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 8d6e09b2b1ad63175caac9f1754461a5 1385064 mail optional dovecot-pop3d_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 7c06b6e2e4a4d24979a7bd13fcc7f29c 1553748 debug optional dovecot-sieve-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 75381ef3e4d8cd68ff60758ebd0aabea 1674116 mail optional dovecot-sieve_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb b73ce882aae1e096ae0e751a4c17809e 86052 debug optional dovecot-solr-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 2e805d7b119f299c8c06b1928708c2ad 1375148 mail optional dovecot-solr_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb cdf22bf925a8447a7157c0a32936a233 18024 debug optional dovecot-sqlite-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 4204bcead3873821aa63e12fbb47653c 1363088 mail optional dovecot-sqlite_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 3da68ca15b5db34d9244f28e7a6b230e 180788 debug optional dovecot-submissiond-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb e4a7dd68ac69c961cf79109c9786b563 1399688 mail optional dovecot-submissiond_2.3.19.1+dfsg1-2.1+deb12u6_arm64.deb 4eba94134b73dec8b2eec1800a3ed7d3 18863 mail optional dovecot_2.3.19.1+dfsg1-2.1+deb12u6_arm64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0Ha//LlsGOpbQ/H4xqCFmsOWgoYFAmoZ76gACgkQxqCFmsOW goZxCRAAjAqFSxnMzk0ya1qKfrJnZblAyhtunqpYWEGGi/taT0+xXQk7VmOJI018 KtGAZoOBZ+1IStoiAQpu+BeBvTtimTsyG+xC5HRb98XPEm3DmaNx5kk9GvD0S67j ElojK27p4jtWBoxplO1J0lKtBEibB8abYhoBv1Qg3UsAI7vSsCFjvZ491i3ourLF 77fxvYHlbB6J07N2+mWLZzPThchXYDr5KQRYFGjhkaH+T3kBdFGNKyKsNWQee7fS hnQvFZcWhOtAEho6t+rxEB3qghhtrTyz0t/Bo/8v8oEM10YsE3voxJiY5rJnI3Ls 3JllCFdDZQcLn5fgmsKC0klnJ+QaXj9/WqbJOBe/fqKlRHE1XO9yU77vVQ4k2rvY r7SinvnSe7s34qXMaOI1WsHBy+4fMpiuN92/OZ9XIllOIPxOPxO08C+pjl2kOdSi 3229W1f+vP0WVxzkJSAPTwKOiNdGhU1l+M5OqMr6Pz9tx3G5C/LThMobU/jYZCBY ltDXcwf/U3GKHmyJamWRGa6Dfag/jZpJBy7I4G6VjpgxTyQp3FijMD2yyGpN8n0s 10t4JKjIUbH2P8bA+9XjBl7TnHG2bW7FpQy6CcrUzVwLC+gpEpWqi4tVV9n+M+Hh 5lFxLEVm4CdPZam2ANsqxSZjUD5zpEWdxpy4hhNn85RfuV3xqKY= =GJkD -----END PGP SIGNATURE-----