[PATCH 14/24] imap-login: Limit the number of open IMAP parser lists
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Fri, 6 Mar 2026 13:35:12 +0000 (15:35 +0200)
committerNoah Meyerhans <noahm@debian.org>
Wed, 6 May 2026 19:18:43 +0000 (15:18 -0400)
commitb5e9e1c9156becd53f8617e0d4d890d6cc0d275e
tree188908a0c0e9f7cd7998e529906440f0dfb437c5
parentfe1cb7cd3a1129c1c19f1a8373d4f075cbcc236b
[PATCH 14/24] imap-login: Limit the number of open IMAP parser lists

This prevents attackers from using a large number of '(' in a command to
grow memory usage excessively.

Gbp-Pq: Name CVE-2026-27857-4.patch
src/imap-login/imap-login-client.c
src/imap-login/imap-login-client.h
src/imap-login/imap-login-cmd-id.c