[PATCH 14/24] imap-login: Limit the number of open IMAP parser lists
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Fri, 6 Mar 2026 13:35:12 +0000 (15:35 +0200)
committerNoah Meyerhans <noahm@debian.org>
Mon, 18 May 2026 20:03:51 +0000 (16:03 -0400)
commit7e8b42f82c7811fd5901bc7094851d4ceb4f92f2
tree25db96bb575760311aabb20a8671c6fb74f4dba6
parent4c8e663444bd6fa126851940dff0ba925edffc9d
[PATCH 14/24] imap-login: Limit the number of open IMAP parser lists

This prevents attackers from using a large number of '(' in a command to
grow memory usage excessively.

Gbp-Pq: Name CVE-2026-27857-4.patch
src/imap-login/imap-login-client.c
src/imap-login/imap-login-client.h
src/imap-login/imap-login-cmd-id.c