-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 18 May 2026 14:11:58 -0400 Source: dovecot Binary: dovecot-auth-lua dovecot-auth-lua-dbgsym dovecot-core dovecot-core-dbgsym dovecot-dev dovecot-gssapi dovecot-gssapi-dbgsym dovecot-imapd dovecot-imapd-dbgsym dovecot-ldap dovecot-ldap-dbgsym dovecot-lmtpd dovecot-lmtpd-dbgsym dovecot-lucene dovecot-lucene-dbgsym dovecot-managesieved dovecot-managesieved-dbgsym dovecot-mysql dovecot-mysql-dbgsym dovecot-pgsql dovecot-pgsql-dbgsym dovecot-pop3d dovecot-pop3d-dbgsym dovecot-sieve dovecot-sieve-dbgsym dovecot-solr dovecot-solr-dbgsym dovecot-sqlite dovecot-sqlite-dbgsym dovecot-submissiond dovecot-submissiond-dbgsym Architecture: armel Version: 1:2.3.19.1+dfsg1-2.1+deb12u6 Distribution: bookworm-security Urgency: medium Maintainer: armel Build Daemon (arm-conova-04) Changed-By: Noah Meyerhans Description: dovecot-auth-lua - secure POP3/IMAP server - Lua authentication plugin dovecot-core - secure POP3/IMAP server - core files dovecot-dev - secure POP3/IMAP server - header files dovecot-gssapi - secure POP3/IMAP server - GSSAPI support dovecot-imapd - secure POP3/IMAP server - IMAP daemon dovecot-ldap - secure POP3/IMAP server - LDAP support dovecot-lmtpd - secure POP3/IMAP server - LMTP server dovecot-lucene - secure POP3/IMAP server - Lucene support dovecot-managesieved - secure POP3/IMAP server - ManageSieve server dovecot-mysql - secure POP3/IMAP server - MySQL support dovecot-pgsql - secure POP3/IMAP server - PostgreSQL support dovecot-pop3d - secure POP3/IMAP server - POP3 daemon dovecot-sieve - secure POP3/IMAP server - Sieve filters support dovecot-solr - secure POP3/IMAP server - Solr support dovecot-sqlite - secure POP3/IMAP server - SQLite support dovecot-submissiond - secure POP3/IMAP server - mail submission agent Closes: 1136444 Changes: dovecot (1:2.3.19.1+dfsg1-2.1+deb12u6) bookworm-security; urgency=medium . * Security update (Closes: #1136444) * [1d0162a] autopkgtest: test cram-md5 authentication * [d4eed2a] CVE-2026-40016: Sieve :contains/:matches O(N×M) Substring Match Bypasses sieve_max_cpu_time Limit (130× Overrun) * [898776c] CVE-2026-33603: login: Base64 input can contain tabs that bypass IPC protection * [fe76a7b] CVE-2026-40020: IMAP folders can be shared-spammed to everyone * [ce379ba] CVE-2026-42006: imap-login: Excessive memory usage DoS Checksums-Sha1: 2f2650c6e1f689c42afb388ac4eaec3680ea60be 32272 dovecot-auth-lua-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 13bbfb77e90d2fd64cf7afc6060852bd1d3fc1ad 1366584 dovecot-auth-lua_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb b90b941e3bfe1f2b77a90ab4133ffcab3fd79414 9278992 dovecot-core-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 221eec3484870da7587914b6f8b60c8d4e4d245e 4139804 dovecot-core_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 04fcab149b3f9eb121598b660b1b7ee7068a26cf 1744120 dovecot-dev_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb db192e3556576017789d43f07282a511c466d93f 21868 dovecot-gssapi-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb da54a16997cea85f98a636def965221b1957e9d9 1362804 dovecot-gssapi_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb a6f790886b7c319e11380bb09320501157e8609c 667892 dovecot-imapd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 2f8772ec118df577dbcb69b29a060b23385496d6 1505356 dovecot-imapd_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 43c1ca3f2bc010002f3f9fdf2d5211ab7e69a0dc 115956 dovecot-ldap-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 09dfa0cba43f62436db27bb30577bf61022cd38f 1389520 dovecot-ldap_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 30d4d2876deadbba0895c12ed32f6f0cd87686fa 91528 dovecot-lmtpd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb a5cfc4cb1d348f01a915e73049fe604760ae3ec9 1376784 dovecot-lmtpd_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 1c6221ad65f03f25fc55eb3320d951622e1e1d67 148772 dovecot-lucene-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb c470d0aa6b1328fa1e6aa4e56a72a9a1ca26a27c 1378232 dovecot-lucene_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb b7bb101fd915e912faef0069083cc806bb49169c 145652 dovecot-managesieved-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb afa904758dc230dfb2953dd7f29c250aee4bf045 1394524 dovecot-managesieved_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 8a3a92f561a4578f2dd8638369042f4838e9749c 31512 dovecot-mysql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 35630911367d52b4dbe62ca972967abe33936484 1364068 dovecot-mysql_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 2f13e27e3329482be247a082862a24700f08e0d8 33312 dovecot-pgsql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 5cc348d5432aef61e5bf54bf8a9bed8cc5df2ff1 1367068 dovecot-pgsql_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 9ca33c9d2ad47a562597f9cc24d39a7f353f6554 90008 dovecot-pop3d-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 8524883010865dcf5ab9c24a3d6a3b024c18a968 1383528 dovecot-pop3d_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb e3d27e996b650ca9baf053ddaa1a98c2c2c7215e 1500088 dovecot-sieve-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 1a77161756e5245c9ec032a6058fa7f9555ab879 1653592 dovecot-sieve_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 8ed535e6c1b0b5160829279b7e32bf9c47d5ef72 86676 dovecot-solr-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb a626a893c75dccad2abf5b6a98ec095712b21b3b 1373892 dovecot-solr_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb ac0a80c6f153d4b58f24d809a924e141c9a1bdec 18328 dovecot-sqlite-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 9c5204848975c1bf8079f1b3d22a724f0ccca7bd 1362304 dovecot-sqlite_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb f1a1c3adf4c628d8b9ffe25f9d23a812cbab70d6 176244 dovecot-submissiond-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 4db3ede81b377be3438cc1221cddb936276edcc8 1397016 dovecot-submissiond_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 3aaab82d64fb1807e3c52d3a3514c58acfb22cb7 18702 dovecot_2.3.19.1+dfsg1-2.1+deb12u6_armel-buildd.buildinfo Checksums-Sha256: c9ff3997676b862f1d94d01d02991f017f2250a4141c17b21e7da40263a71efc 32272 dovecot-auth-lua-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 48679e4a8455c177a587d4aca547c0792d1b305722177f8f897e017f0f574522 1366584 dovecot-auth-lua_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 3a78c838541137a1aaf49dc8f5b0ed05dbb4aa5f45fa523f2a6de0df6a8909a9 9278992 dovecot-core-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 055b7e1414e2cb4e411a37ad8bbdc78fd5ec8cad04b598f7ecf74586f8556b3d 4139804 dovecot-core_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb b499f15e57b754110568209c27b94e9c341c7b79d9eedfd58d19056b2b41064c 1744120 dovecot-dev_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 38f2659e5dd0bdc165b3854ac8401e8616d8dba8abf93a926c7026b8f7279dbf 21868 dovecot-gssapi-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb b3a757c680a913021f64276c3c7c427dbee28bce1db730f51e352aaf2f7b0404 1362804 dovecot-gssapi_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 33d6354bae8478a14e4417d57570b1f90a08e1c5f6f7ee995851b53135c867c8 667892 dovecot-imapd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 6a0e4d88540ae8efa5632999f12efe65a22b651b4a4311dc22594dfa2efbb59b 1505356 dovecot-imapd_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb cff2afbb352910c58cf340ecdf6968b8d7894bedb279bd444977f4fec5acaf2c 115956 dovecot-ldap-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb fccc791bb42b5edd9fc890592ff76b840204e71dd48e5678913e5418a3a035b9 1389520 dovecot-ldap_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb feed43ee4f86009158580a6d03e94987c46196e7aa33c0825cb79fad80522df1 91528 dovecot-lmtpd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb d93ee7b392d9f9163975503b90d8115bad655bbc15eed3d8cf9ac302e29159cf 1376784 dovecot-lmtpd_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb e80f6ccbe088fd901f73e31af751e0504f39c2ba432e9bb4c7bc88e24d2a2c27 148772 dovecot-lucene-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 48af12dba14fb6215ea59384518290027c971f4b14a4759f03ee76e1cf225a41 1378232 dovecot-lucene_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb fccbfc7a37c6f44316c7f732f4e447a2e71f66da807eb6f46dc4a1e85de6860b 145652 dovecot-managesieved-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 9b9039ed8d8e9876b6e0841f81aac0166e6abfdd2fdbfac1c747cd27b14630a6 1394524 dovecot-managesieved_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 8aac0d2adf47d1b5e3e45383f9cd1747a5ce02ffb6e3f6805271eafabdacdc91 31512 dovecot-mysql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb eed5511e526ae40a60990bb6215561e7cbf814639f2bd2c11324cc3c6a50edcf 1364068 dovecot-mysql_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb ea9e0df51e46a34e8e702d448541ed94959b651654e0c38b3f37739572fa5290 33312 dovecot-pgsql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb da4636816f0ff145094aff123bd856979837d10d2f2ad32854b9d79969d1bb88 1367068 dovecot-pgsql_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb c07a065ff68a389998a9fe0117e944296128eb575e0eca089ca068a4f6e12acd 90008 dovecot-pop3d-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb a150c1694ef605aa4a537b5bdc4c2aa41cb3d8a881550dc7593f54ec904b0ea8 1383528 dovecot-pop3d_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb e2eddf943a44ffb4cc9954aebb4244e7d0da253f2a039420a12f50e77912b9a2 1500088 dovecot-sieve-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 1fc794b6ecd88e06bc670b24d8e4994f832f2bd92acf2f7328c78dd81d66b05d 1653592 dovecot-sieve_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb f421fd1fea10bc639b33e677936d767fb1130815a1b0424a5b74d6213a86edf6 86676 dovecot-solr-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 12a1b2f45a5520af875ad2911aaeb480e9c92bec97ab599e06d9544903133406 1373892 dovecot-solr_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 4d536056eb11c02ee251748105f62c15dfee1a7e384b3e02f4830df0543c3a61 18328 dovecot-sqlite-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb f3b36d7b8f3d485a2ecbf6aea690dd69fe949bb981c772b2b3468da16262d8ba 1362304 dovecot-sqlite_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 5b7709f72125c122b3cfeca315fc70c2cebfa0857f635ad020febaa129e7ab60 176244 dovecot-submissiond-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 91af9758567bbdab6b877bee23a6aae9236a5f0dff107f2c170b48515e4c0088 1397016 dovecot-submissiond_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 1f6e24628dd04d99f0fc81f96cccade99adf3e176209825d419ba67b518b2788 18702 dovecot_2.3.19.1+dfsg1-2.1+deb12u6_armel-buildd.buildinfo Files: e1297192b259b5f2740cbdfa6cac10df 32272 debug optional dovecot-auth-lua-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 2db35ad8418bb1006ccceca8ea686e62 1366584 mail optional dovecot-auth-lua_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb a05da1b4fb785610a59679df562cad32 9278992 debug optional dovecot-core-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb cbfc957c796f88749f6dd6a082fb751d 4139804 mail optional dovecot-core_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 9724847d1a2cdcce4715d7032c1c71b8 1744120 mail optional dovecot-dev_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 72b1742ae71f0a68342295f8eb0bcddd 21868 debug optional dovecot-gssapi-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb d8471d2a08809c308a2c52bbac17f8b7 1362804 mail optional dovecot-gssapi_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb d7dd84c1c3b11c8396ec556b8f579e4c 667892 debug optional dovecot-imapd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 1bb8aa12375f5bc7118817c41bcd0ef8 1505356 mail optional dovecot-imapd_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 5789feafe1b647c47d042b6a850d2ecc 115956 debug optional dovecot-ldap-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 8a8b80129870546608f7af535c0082db 1389520 mail optional dovecot-ldap_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 3a6e5230aba6fe71944fed6ec810949d 91528 debug optional dovecot-lmtpd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb d42e0253ef2c55335d4d0ee74d8542ff 1376784 mail optional dovecot-lmtpd_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 07ac32979b7a8af76a5573aa8e91244a 148772 debug optional dovecot-lucene-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb f0a383df63aa305b792116f5377ded91 1378232 mail optional dovecot-lucene_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb ce900fdbefc5439d2832928f021b0f6e 145652 debug optional dovecot-managesieved-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb aeb6969bf1419069409a071d4c8de24c 1394524 mail optional dovecot-managesieved_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb d7fad8406d8895cf2d9cc002fab472a9 31512 debug optional dovecot-mysql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 8d884bff7db1ef287ae3a90f8868bbef 1364068 mail optional dovecot-mysql_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 9be595db2999e96d26fbfe950affba58 33312 debug optional dovecot-pgsql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 4f9b1e5149c9ef6c21610b5b70e3136d 1367068 mail optional dovecot-pgsql_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 0649a8abc3dbcce2744dffc768b72a45 90008 debug optional dovecot-pop3d-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb d79bc903d4e3f391c142f66f992b97ce 1383528 mail optional dovecot-pop3d_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 10df7c00a206f8b41c15f772884f4b1e 1500088 debug optional dovecot-sieve-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb f7e44b2b6064d8b5dea85b790650392a 1653592 mail optional dovecot-sieve_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 6ba223475d7d4bd29d7641683c85f4b0 86676 debug optional dovecot-solr-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 94e30305c32c7b264fbc700e6c53086e 1373892 mail optional dovecot-solr_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 4348d3ecf4cac9a702473333986301ca 18328 debug optional dovecot-sqlite-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 9032fc4f6f68e3018835d5b85af2ef8a 1362304 mail optional dovecot-sqlite_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 04e9560277914cc350ec0053452b1667 176244 debug optional dovecot-submissiond-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb 80219a0305684150cf8e7570d61045b0 1397016 mail optional dovecot-submissiond_2.3.19.1+dfsg1-2.1+deb12u6_armel.deb de773c3775519fcc490704f10d2dd251 18702 mail optional dovecot_2.3.19.1+dfsg1-2.1+deb12u6_armel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYxmcRLDHP0tCCM0oScpU3dYulLgFAmoZ7zYACgkQScpU3dYu lLholQ/9H2x3/pm4bPJbEVNpSxxyGYdmH5Wa1n2wLVUC1oCWyl9TaqTJjD9rL07o s6DE76xwh3YI19ARbYCLXAV4OKCw7B4SAqGJ2s9xWk8tjvzG1rbVnOzshyQh98gO TPIaTYcvvs1UPKJ+/6cBAIrj+uzVBhkJFKKyRfSjNlmmFtvIeeR7sw0MHN62rFtR pfdyWHxyjCB7ddVc5RaPAeD5Cb1hgYQFC/eY1DMS+xGHc3tfkOShD9QD732D7DJf Xqk/qQ3sVFlChW7MS/TtL8pnX7qbbkIHkRaHb/kAVlHS+QmOKZuS/KZWBzrlEnny 2H4DfcrzLff4dSICi98Ff9XwNfsonliD7Dchx/7I0QUM8RBxFaudFYP9bl0F9760 jTORpzJZroXBCtQlvOFCFvqSAP4FH31YiPgrRCw7OWdeX6ylwKJ90YwBkwUGg2JX QVj1jIH2aGfq7NjWOdQUGJxRkqqt3RCFS2f/srCKY7eCYoat78Nrq6lt+knWY612 poVT/xeVSrc3Gy55wKRl4D/8gGMUMHc7zXL+u1DWy3XT/SGy9IBtmVoT2QCUijev pblz1iXqdW3om65pfH5Fm16bwXjhzP0YrBvTRys6wKlyfEBgVjxVbRb8x4Lr+S/6 bDsiJcZt6Nf3ukejyW9Nwqbp0RSBYTdOX+loNBLcm0SUyDPm340= =9CUU -----END PGP SIGNATURE-----