[PATCH 2/2] managesieve-login: Verify AUTHENTICATE initial response size isn't too...
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Mon, 2 Mar 2026 12:40:57 +0000 (14:40 +0200)
committerNoah Meyerhans <noahm@debian.org>
Wed, 6 May 2026 19:18:43 +0000 (15:18 -0400)
commitef39a5571031d8a6ba0b66a9cf98bec96a19920e
treeb1b06259f4962f913f59cd829089f5e30b163640
parent9cbee50939ed8e0156a564f31b37b5b644bec268
[PATCH 2/2] managesieve-login: Verify AUTHENTICATE initial response size isn't too large

This prevents DoSing the managesieve-login by sending an excessively large
initial response size, which causes a huge memory allocation.

Gbp-Pq: Name CVE-2026-27858.patch
pigeonhole/src/managesieve-login/client-authenticate.c