[PATCH 2/2] managesieve-login: Verify AUTHENTICATE initial response size isn't too...
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Mon, 2 Mar 2026 12:40:57 +0000 (14:40 +0200)
committerNoah Meyerhans <noahm@debian.org>
Mon, 18 May 2026 20:03:51 +0000 (16:03 -0400)
commit56d5d2c346f7a542c801ca5f07806dd8797b4224
treebefde4bcb43345ab4895d0a5e571daa9e732de19
parent7be4f45f686fb38594d314e56fb55493d37f07d7
[PATCH 2/2] managesieve-login: Verify AUTHENTICATE initial response size isn't too large

This prevents DoSing the managesieve-login by sending an excessively large
initial response size, which causes a huge memory allocation.

Gbp-Pq: Name CVE-2026-27858.patch
pigeonhole/src/managesieve-login/client-authenticate.c