- dovecot (1:2.4.1+dfsg1-6+rpi1+deb13u6) trixie-staging; urgency=medium
++dovecot (1:2.4.1+dfsg1-6+rpi1+deb13u7) trixie-staging; urgency=medium
+
+ [changes brought forward from 1:2.3.21+dfsg1-3+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Thu, 20 Jun 2024 17:16:27 +0000]
+ * Disablte testsuite.
+
- -- Raspbian forward porter <root@raspbian.org> Sun, 31 May 2026 20:32:39 +0000
++ -- Raspbian forward porter <root@raspbian.org> Fri, 02 Oct 2026 09:09:32 +0000
++
+ dovecot (1:2.4.1+dfsg1-6+deb13u7) trixie-security; urgency=medium
+
+ * Import upstream fixes for multiple security issues. (Closes: #1146018)
+ - CVE-2026-27852: DoS by sending mail with bad header
+ - CVE-2026-33263: submission-login: Panic when
+ mail_max_userip_connections is reached: Panic: epoll_ctl(del, 8)
+ failed: Bad file descriptor
+ - CVE-2026-33604: SMTP Smuggling via Missing Dot-Stuffing After Bare
+ Carriage Return
+ - CVE-2026-33605: managesieve-login: Pre-auth crash
+ - CVE-2026-33607: Dovecot IMAP LIST match_sub() Exponential
+ Backtracking — CPU Denial of Service
+ - CVE-2026-40013: pigeonhole: Stack Buffer Underflow in Pigeonhole
+ ManageSieve CHECKSCRIPT/PUTSCRIPT
+ - CVE-2026-40014: IMAP THREAD REFERENCES O(N²) CPU DoS via Crafted
+ References Header (index-thread-links.c)
+ - CVE-2026-40015: imap-hibernate can be crashed
+ - CVE-2026-40017: IMAP THREAD O(M³) CPU DoS via CRC32 Hash Collision
+ in strmap (mail-index-strmap.c / hash2.c)
+ - CVE-2026-40018: MySQL multi-byte escaping wrong
+ - CVE-2026-40204: acl: lda_mailbox_autocreate can bypass acl
+ restrictions
+ - CVE-2026-42007: Sieve editheader RCE
+ - CVE-2026-42391: imap: Pre-login memory/CPU growth with ID command
+ - CVE-2026-42394: sieve: symlink traversal flaw could result in
+ arbitrary file disclosure
+ - CVE-2026-52681: Sieve resource usage tracking lost when active
+ script changes
+ - CVE-2026-52687: IMAP: COMPRESS ZSTD can cause excessive memory usage
+ - CVE-2026-73209: imap-login crash: Self-recursion on zero-output
+ decompress chunks
+ - CVE-2026-33606: dsync: Mail content can cause dsync protocol
+ injection
+ - CVE-2026-40203: IMAP Compression Can Reveal Whether a Small Synced
+ Email Body Matches Sender-Chosen Text
+ - CVE-2026-42008: XCLIENT FORWARD= bare token not namespaced, allows
+ nopassword injection via trusted proxy
+ - CVE-2026-42392: imap-urlauth leaks memory into user-visible error
+ messages
+ - CVE-2026-42393: doveadm_password or api key length can still be
+ leaked with timing comparisons
+ - CVE-2026-42395: Single NUL-Byte XCLIENT FORWARD Payload Crashes
+ - CVE-2026-40205: OAuth2 passdb scope enforcement bypass via OR
+ semantics in remote validation path
+ - CVE-2026-73208: auth: db-oauth2: aud claim used as fallback for
+ missing scope claim
+ * lib-mail: istream-header-filter - Fix potential assert-crash
+ (Closes: #1144639)
+ * CI: Disable test-build-twice job, which is known to fail on trixie
+
+ -- Noah Meyerhans <noahm@debian.org> Wed, 16 Sep 2026 15:06:35 -0400
dovecot (1:2.4.1+dfsg1-6+deb13u6) trixie-security; urgency=medium