]> dgit.raspbian.org Git - dovecot.git/commit
[PATCH 6/6] imap: Reset DEFLATE dictionary after every tagged reply
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Thu, 16 Apr 2026 15:38:53 +0000 (17:38 +0200)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
commit54bc55bcec415f0097a4f9de21110a52f4696f70
treed51370dad7b8c4537ffe0859a19dd96e9a6a3d46
parent7ba2f5f938d344aa39c2cf840b967007ab039da5
[PATCH 6/6] imap: Reset DEFLATE dictionary after every tagged reply

Prevents CRIME-style cross-command compression oracle attacks
(CVE-class: compression side-channel).  Without this fix an observer
who can inject chosen plaintext into one IMAP command's response can
measure the compressed size of a subsequent command's response and
determine whether the secret content matches the injected plaintext.

After each tagged response line is sent, the DEFLATE compression
dictionary is reset via Z_FULL_FLUSH so that the compression history
from one command cannot influence the compressed size of the next.

For direct compression (imap_compress_on_proxy=no) the reset is applied
to the local ostream.  For proxy-mode compression
(imap_compress_on_proxy=yes) a "dict_reset" command is sent over the
multiplex side channel to the imap-login process.

Gbp-Pq: Name 0006-imap-Reset-DEFLATE-dictionary-after-every-tagged-rep.patch
src/imap/imap-client.c