stable

dovecot-2.4.4-1.fc43

FEDORA-2026-693373747f created by mhlavink 3 months ago for Fedora 43
  • CVE-2026-27851: lib-var-expand: Safe filter marks all following pipelines safe.
  • CVE-2026-33603: auth: CRAM-SHA-*-PLUS channel binding could be faked. MITM attacker with a certificate trusted by the client could have bypassed the requirement for channel binding.
  • CVE-2026-40020: IMAP folders can be shared-spammed to everyone.
  • CVE-2026-42006: An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete.
  • indexer-worker, quota-status, script-login, program-client-local: Root privileges are now dropped permanently before serving requests.
  • indexer-worker: Default restart_request_count changed to 1 to work correctly after permanent root privilege drop.
  • lmtp: Add back service_extra_groups=$SET:default_internal_group that was incorrectly removed in v2.4.3.
  • master: inet_listener_reuse_port has been replaced by service_reuse_port. The new setting properly pre-creates all listener sockets at startup and assigns one unique socket per process. Using this allows evenly distributing incoming connections to login processes.

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-693373747f

This update has been submitted for testing by mhlavink.

3 months ago

This update's test gating status has been changed to 'ignored'.

3 months ago
User Icon mschwarz commented & provided feedback 3 months ago
karma
  • update works in general
  • updates fixed bz#2478342

This update has been pushed to testing.

3 months ago

This update can be pushed to stable now if the maintainer wishes

3 months ago

mhlavink edited this update.

3 months ago

This update has been submitted for stable by mhlavink.

2 months ago

This update has been pushed to stable.

2 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
1
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
disabled
Stable by Time
disabled
Dates
submitted
3 months ago
in testing
3 months ago
in stable
2 months ago
modified
3 months ago
approved
3 months ago
BZ#2479583 CVE-2026-33603 dovecot: Dovecot: Information disclosure via SCRAM TLS channel binding bypass [fedora-all]
0
0
BZ#2479588 CVE-2026-40020 dovecot: dovecot: Denial of Service via IMAP SETACL command injection [fedora-all]
0
0
BZ#2481123 CVE-2026-40016 dovecot: Dovecot: Denial of Service due to Sieve script CPU limit bypass [fedora-all]
0
0

Automated Test Results