-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 18 May 2026 14:11:58 -0400 Source: dovecot Binary: dovecot-auth-lua dovecot-auth-lua-dbgsym dovecot-core dovecot-core-dbgsym dovecot-dev dovecot-gssapi dovecot-gssapi-dbgsym dovecot-imapd dovecot-imapd-dbgsym dovecot-ldap dovecot-ldap-dbgsym dovecot-lmtpd dovecot-lmtpd-dbgsym dovecot-lucene dovecot-lucene-dbgsym dovecot-managesieved dovecot-managesieved-dbgsym dovecot-mysql dovecot-mysql-dbgsym dovecot-pgsql dovecot-pgsql-dbgsym dovecot-pop3d dovecot-pop3d-dbgsym dovecot-sieve dovecot-sieve-dbgsym dovecot-solr dovecot-solr-dbgsym dovecot-sqlite dovecot-sqlite-dbgsym dovecot-submissiond dovecot-submissiond-dbgsym Architecture: i386 Version: 1:2.3.19.1+dfsg1-2.1+deb12u6 Distribution: bookworm-security Urgency: medium Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Noah Meyerhans Description: dovecot-auth-lua - secure POP3/IMAP server - Lua authentication plugin dovecot-core - secure POP3/IMAP server - core files dovecot-dev - secure POP3/IMAP server - header files dovecot-gssapi - secure POP3/IMAP server - GSSAPI support dovecot-imapd - secure POP3/IMAP server - IMAP daemon dovecot-ldap - secure POP3/IMAP server - LDAP support dovecot-lmtpd - secure POP3/IMAP server - LMTP server dovecot-lucene - secure POP3/IMAP server - Lucene support dovecot-managesieved - secure POP3/IMAP server - ManageSieve server dovecot-mysql - secure POP3/IMAP server - MySQL support dovecot-pgsql - secure POP3/IMAP server - PostgreSQL support dovecot-pop3d - secure POP3/IMAP server - POP3 daemon dovecot-sieve - secure POP3/IMAP server - Sieve filters support dovecot-solr - secure POP3/IMAP server - Solr support dovecot-sqlite - secure POP3/IMAP server - SQLite support dovecot-submissiond - secure POP3/IMAP server - mail submission agent Closes: 1136444 Changes: dovecot (1:2.3.19.1+dfsg1-2.1+deb12u6) bookworm-security; urgency=medium . * Security update (Closes: #1136444) * [1d0162a] autopkgtest: test cram-md5 authentication * [d4eed2a] CVE-2026-40016: Sieve :contains/:matches O(N×M) Substring Match Bypasses sieve_max_cpu_time Limit (130× Overrun) * [898776c] CVE-2026-33603: login: Base64 input can contain tabs that bypass IPC protection * [fe76a7b] CVE-2026-40020: IMAP folders can be shared-spammed to everyone * [ce379ba] CVE-2026-42006: imap-login: Excessive memory usage DoS Checksums-Sha1: 2045c4005ec80013fe1089d0ffd7da792f7ecd35 29560 dovecot-auth-lua-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 3969b297031d5d0cfd4c5345d7c316fbcbac83af 1368468 dovecot-auth-lua_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb d795e4042e7cea45f353722ddb09f8d45e8c6128 9521936 dovecot-core-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 945ec354255529b160b5cc2013a4f9933f2aeeea 4736788 dovecot-core_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 5a8672e75e534547a40c24f7ea347c23753ad889 1744124 dovecot-dev_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 17a9d985bcae06555cea446e07dab0dd0849ca0a 19920 dovecot-gssapi-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb ac593690f888a136b641e1db6ffffae4eb3e082b 1363920 dovecot-gssapi_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 78cfc89491cc2b5052b260a101531d67bfb2dc69 668988 dovecot-imapd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb d1350508941cd3c314933f8d056bd82b63bf64ba 1550344 dovecot-imapd_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 88e75491d4cbda2a3b7b96d61aa593fc59e2499e 112072 dovecot-ldap-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 1e38e5de52f0b3b4dd10f1dbf234bb176d654098 1397912 dovecot-ldap_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 3e94c7dba8b71b1ffe9674d09699ad82da1e5f28 86036 dovecot-lmtpd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb e6271404977aa602f4871950aff34cdbf833c23f 1380628 dovecot-lmtpd_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 95d63bb968403f9b3b5fad73f1f21c85d3602b36 146780 dovecot-lucene-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb aacdb2d1bf39715aaf6fbb293338d08d1dba28c9 1385424 dovecot-lucene_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 690f956285febe5745b6392b4d5158d7bf5c12ad 149748 dovecot-managesieved-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb e01439e78b5e28d450d8964d7d43a7a10e6d644f 1403568 dovecot-managesieved_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb cc63aeb64c869a1bc0d97a8ec7e99cd448d10c91 29684 dovecot-mysql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 54a18bc63f99cc93e7f71cf6f8c585e5127d945c 1365996 dovecot-mysql_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 993fcdd96a1ccef2ed7a546863c86bcfa6063602 29592 dovecot-pgsql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 49fa2f13a18a34f3d4b5578b1f321c601caa5d7f 1369992 dovecot-pgsql_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 02dd9f57a9e87cbb104f33a454e48c97f9b12b91 86148 dovecot-pop3d-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 5a8cdb0f2507e6650dca8fa40b965d4bbd2c7b70 1389696 dovecot-pop3d_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 016d1e9f38eea76b5c49b51ad499bce3686f017f 1423976 dovecot-sieve-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb b50b7a1c06b8f36ff87356352c41de7ac3e26c0f 1734524 dovecot-sieve_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb efbccb2d1b1f82fd1d691b4d587d64d6ea04be1f 81132 dovecot-solr-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb e8c2bea5a44f6402dac9daeff67eba29ffa3234a 1378324 dovecot-solr_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb a25aba39c4eedc7d9dbbe8570f55cc4bb399c837 16180 dovecot-sqlite-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb c3226f6552758f4146c74598fadcf6436ab72651 1363680 dovecot-sqlite_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 39fdff5716864b4c3301e39b4d43d8f706e194f3 168272 dovecot-submissiond-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb c97a8cab28440601f1573ca9bcd2b99300da283d 1406896 dovecot-submissiond_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 770cc5787913f821484e9d68ce646ffc55b44ed5 18698 dovecot_2.3.19.1+dfsg1-2.1+deb12u6_i386-buildd.buildinfo Checksums-Sha256: e84179b4ff2a4258e16c79b2bcea909b30c9fca276c56d76b2feaad672811c5b 29560 dovecot-auth-lua-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 73575ac1c3e389183b4be4bc3ea397ae1bcf1ed5bfcdc8b9248c3bc9d72c096b 1368468 dovecot-auth-lua_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 064e120eb9281f2d28e005f082eb39fc3cbc763c000202a55959bb0e3a7eb4d8 9521936 dovecot-core-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 624da894ccec5ef0445bb56c5ab4564a8ee998ae7ed820daa9a5aa0f5f8ff30e 4736788 dovecot-core_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb fd42660b575592c7ec00fba73bc6dd9a2ef577cf83df96976f5497fdc2992c3e 1744124 dovecot-dev_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 586eab896d2e2d16c3e4e3f65d2f5ffda4a49e8e197ceb8bb39c42ee02782a14 19920 dovecot-gssapi-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 96394e076da5f38ab6ae05db9b8565ba2e05ac17f8c4b773f1daf3fd8f4dab40 1363920 dovecot-gssapi_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 0dd25f814a0456cadfd8f20981da0a3ee938eee9447ea8518c30d910082e550b 668988 dovecot-imapd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 28fad463d4c0d0d94bc56f94aeeb6ea14dd670c84a6ba5ddddfdbaae2140eac8 1550344 dovecot-imapd_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 44cc77ae555eeaaee56c11d28ba61e67623c132b9f3df557ebe64d5bfabbe1c2 112072 dovecot-ldap-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 0d75aeefb7fe584359667331a9748ce758818bd241670ecfbdd880dc64d10dd4 1397912 dovecot-ldap_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 97e294e1925ae125a0733b79c6892b2f96821ee6345ac18ccbce206628317fae 86036 dovecot-lmtpd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb eaa2b907a47dc486cbb53c0f52b30f78d02e0c9a9d3f31d4034ccde6bf356f9d 1380628 dovecot-lmtpd_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 1f8b1ef0d3f83f7161610b56b58cb1bb40d2cb7dee7226b67566b63a42e7abb0 146780 dovecot-lucene-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb f4812044e118ecec1283830e4dcd52f407c8c17235aa9ae4be060940dd727712 1385424 dovecot-lucene_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb f1e29a696e0aeda6a27d3dcdd66843ed8069501fcf59de0eda50e4dd186b2e22 149748 dovecot-managesieved-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 1f06354ab8c7a1d7caef4f9b46441e114cb3bcd9f17a710b0bb322a39daba487 1403568 dovecot-managesieved_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 8c79b712f9e687891d24b0d96811712342f3e4e1036afc79111ca3b72d1364f8 29684 dovecot-mysql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb d4c683747f5873ac070430a0e3b9f213cf5eade61a3fd91f12c213674dcfd007 1365996 dovecot-mysql_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 2a7e0253e07ededbd3412f362ec410d767cafc2a602e991fa09ff49f9f99691d 29592 dovecot-pgsql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 5f3337956f0eff1fefdc5214543155ed0abd7860bc863ae768d91a3af2ff3042 1369992 dovecot-pgsql_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb eb294700a42699145234cf27c00bb6c4c0718debecc4402ace007cc104a01694 86148 dovecot-pop3d-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 120e97dbcaed798e06f638a01299845e8571119587c50b3e67b266a649f5bbf7 1389696 dovecot-pop3d_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb ab219010465dbdcbac33e8d958ee71f4775258a56c07a882824e2901e60fc6e2 1423976 dovecot-sieve-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 0ecfa24086a8e028733b7ff8ccfac50386f9cf10c42f2c7648eae72e52e5305f 1734524 dovecot-sieve_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 28f450263195eb96481101ceeca26921bc24ba9eaa6fa4c13a61251ded0fa24b 81132 dovecot-solr-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 837c698c1b07b3d33e325c79b8001bd74506f92d87b2b30bee18cb920d4b0527 1378324 dovecot-solr_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb e7489261416a56ca54f1e26491eb96b6c3bcef987fc082a04312b6aba07ea213 16180 dovecot-sqlite-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb fc53905e7a001355ae3f8f21e9401e28e308644b289a8aec66b3197161b006fd 1363680 dovecot-sqlite_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb d8445533891032a05b1103b73232051ef2b26c501d46806ec234726f712f426c 168272 dovecot-submissiond-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 63ba49f02ec327664aa186dd03fe2a7ce256914c84275b2c018f64873a50db58 1406896 dovecot-submissiond_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb a6374792e623b0121283f7433463f33d421cfc881d4ac5e4e70ff85bcf2538a0 18698 dovecot_2.3.19.1+dfsg1-2.1+deb12u6_i386-buildd.buildinfo Files: 156e98a449df44d9cb7aae42d2f4328d 29560 debug optional dovecot-auth-lua-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 76b25a36e35c0d9c079ace73414fbb1d 1368468 mail optional dovecot-auth-lua_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb a11be9646f82277f8ba1c7b4cc2990a9 9521936 debug optional dovecot-core-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 7d3597e836d1ac28fe2143acae3502b1 4736788 mail optional dovecot-core_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 39593fed7383511fe716beb8fd05f15b 1744124 mail optional dovecot-dev_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 4d1c8f998ec67cb0694f6ade8a2b73fb 19920 debug optional dovecot-gssapi-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 348e957bf689bdad1c95630e04b3d893 1363920 mail optional dovecot-gssapi_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb c7804ae322cafc484ec88ad43faf47ee 668988 debug optional dovecot-imapd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb a56e5f72751dfc85374ce38f02e2c1a6 1550344 mail optional dovecot-imapd_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 9336ecd874a3cc61bc6706d22a0d2602 112072 debug optional dovecot-ldap-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 7b1fd7f293d5c7eab1db5d8c7bbb3e7c 1397912 mail optional dovecot-ldap_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 7bd320c9d5fb098517872e4206023bdc 86036 debug optional dovecot-lmtpd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb de6409d7fd4e22430dc48f0c7f85afe2 1380628 mail optional dovecot-lmtpd_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb c12f2b854f4e3dad9c80019a4b5abbe8 146780 debug optional dovecot-lucene-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 703c020ce412db9dd736a446358a6559 1385424 mail optional dovecot-lucene_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb fc6e62b8b30d35c27799d5dd1c5bd8d6 149748 debug optional dovecot-managesieved-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 322b8d9b28c2292b1170b2afa87d27f9 1403568 mail optional dovecot-managesieved_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb ab7d2b299991b0c07bd000b576b82838 29684 debug optional dovecot-mysql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 9cd514979a9e6e96bd0f796bf5cf7bc2 1365996 mail optional dovecot-mysql_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb e6a33442392d1dd32fb877f19df581a1 29592 debug optional dovecot-pgsql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb aa60b06054f418787a84ecf58cbfe680 1369992 mail optional dovecot-pgsql_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb cb91deaca9ca6950a7bfe4df902364fb 86148 debug optional dovecot-pop3d-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 241bd3d7287d4a2f18a7bc13cdc22147 1389696 mail optional dovecot-pop3d_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 13387c77e313c123c7da5b273d6ff19c 1423976 debug optional dovecot-sieve-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 4b01d09520e320eb93d9da58556077a4 1734524 mail optional dovecot-sieve_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 37e891ba22054a625745223186f031cd 81132 debug optional dovecot-solr-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 098c0c809bff65cf9f1cf9221492bed9 1378324 mail optional dovecot-solr_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 855903accd49c98e0ccb899cc1171515 16180 debug optional dovecot-sqlite-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb c7000b98ddef67b6a3f4a498406b0807 1363680 mail optional dovecot-sqlite_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 9484da1139c7e9b22123312dbe2bc509 168272 debug optional dovecot-submissiond-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb d748a41df1bf3e3d8da2920bf069ad66 1406896 mail optional dovecot-submissiond_2.3.19.1+dfsg1-2.1+deb12u6_i386.deb 30eec30e697336b3d0c0d063e6fae501 18698 mail optional dovecot_2.3.19.1+dfsg1-2.1+deb12u6_i386-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEPAUaMA0H0rOy6qBWf2INRiCdaWIFAmoZ77QACgkQf2INRiCd aWJ0Aw/+NcxTuRe3HFrCPqR/TE3dfaQC8AoYtejDVyhZtOR6xzSqemAbudpFkG8y KRGpjhc9OqY/574pBvHlaUE6Km2WROINOv8Kyhghyc94ZNh+tt7KUHedpm4AmyzP JFKw0+icGjyrrn81TQ9dDajiWjjp92RFzKU8FqZwWbe1xEFva2+1hlaAhI9ZnFgJ hii4md5J4psrVATUZSvwsju8K9MoxtwsFFajhbvv0cY8igB5Kxs2lpiO2OO9gYEL HPNwg7dPknaI+CAGSvLO0GsTciSR91PVEPOvgDyUEZ8lGUsIUTHw8wUrN6r9sGN7 GbQAKQ4qleMs4UwmLyMHoJMVVqPM7U+DAfTqTKnWF1j6g6xx+oVjedpbBfPR4AAs WYw+PUw6otZqdOF09RsA0++ZQGcneWW1oRHBzOqx2wTqRd4Zulj2WM0hQn/GVn5o s+p4O0aBcY2Ty0HKbcjCCQep50dq4jZz7T0ZZVoyJC4TPFTe7iF23IAVEyZ1x8bY aRUyTXeAZWl7R0wkx2HboGbkbPv+JmyQOGE0atGIrDvMqdAkKrfXU7nOtF7RsHAz gbS146SNwZC7qkVWJ4iwXB/PentP56Kra8x04soSMx452IQNrBZPL5dvpgcLpzy0 Nya2HbmRtLlFo3P5zwFxEwl2SBiD9/gJPMgRF+EVKtKsmuBERsM= =l09c -----END PGP SIGNATURE-----