[PATCH 14/24] imap-login: Limit the number of open IMAP parser lists
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Fri, 6 Mar 2026 13:35:12 +0000 (15:35 +0200)
committerNoah Meyerhans <noahm@debian.org>
Tue, 31 Mar 2026 19:07:17 +0000 (15:07 -0400)
commitfa177cf16926470add562ba9ac34108457b7b38f
tree3a3dcb7762e87635c3de4cb0f8241637867426c5
parent2bed470f678ba4b042e9b7605cddb48825fa09ab
[PATCH 14/24] imap-login: Limit the number of open IMAP parser lists

This prevents attackers from using a large number of '(' in a command to
grow memory usage excessively.

Gbp-Pq: Name CVE-2026-27857-4.patch
src/imap-login/imap-login-client.c
src/imap-login/imap-login-client.h
src/imap-login/imap-login-cmd-id.c