]> dgit.raspbian.org Git - dovecot.git/commitdiff
Merge version 1:2.4.1+dfsg1-6+rpi1+deb13u6 and 1:2.4.1+dfsg1-6+deb13u7 to produce... trixie-staging archive/raspbian/1%2.4.1+dfsg1-6+rpi1+deb13u7 raspbian/1%2.4.1+dfsg1-6+rpi1+deb13u7
authorRaspbian automatic forward porter <root@raspbian.org>
Fri, 2 Oct 2026 09:09:32 +0000 (10:09 +0100)
committerRaspbian automatic forward porter <root@raspbian.org>
Fri, 2 Oct 2026 09:09:32 +0000 (10:09 +0100)
1  2 
debian/changelog
debian/rules

index 1dd5d97a80c53812f5df85363b9f0b9b041c28e3,84b35de1d6197c33267de40b5f37a821e62c3742..53d113fe8b3e88342ab3e6706cab8e8b3ff9d8a1
@@@ -1,9 -1,54 +1,61 @@@
- dovecot (1:2.4.1+dfsg1-6+rpi1+deb13u6) trixie-staging; urgency=medium
++dovecot (1:2.4.1+dfsg1-6+rpi1+deb13u7) trixie-staging; urgency=medium
 +
 +  [changes brought forward from 1:2.3.21+dfsg1-3+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Thu, 20 Jun 2024 17:16:27 +0000]
 +  * Disablte testsuite.
 +
-  -- Raspbian forward porter <root@raspbian.org>  Sun, 31 May 2026 20:32:39 +0000
++ -- Raspbian forward porter <root@raspbian.org>  Fri, 02 Oct 2026 09:09:32 +0000
++
+ dovecot (1:2.4.1+dfsg1-6+deb13u7) trixie-security; urgency=medium
+ 
+   * Import upstream fixes for multiple security issues. (Closes: #1146018)
+     - CVE-2026-27852: DoS by sending mail with bad header
+     - CVE-2026-33263: submission-login: Panic when
+       mail_max_userip_connections is reached: Panic: epoll_ctl(del, 8)
+       failed: Bad file descriptor
+     - CVE-2026-33604: SMTP Smuggling via Missing Dot-Stuffing After Bare
+       Carriage Return
+     - CVE-2026-33605: managesieve-login: Pre-auth crash
+     - CVE-2026-33607: Dovecot IMAP LIST match_sub() Exponential
+       Backtracking — CPU Denial of Service
+     - CVE-2026-40013: pigeonhole: Stack Buffer Underflow in Pigeonhole
+       ManageSieve CHECKSCRIPT/PUTSCRIPT
+     - CVE-2026-40014: IMAP THREAD REFERENCES O(N²) CPU DoS via Crafted
+       References Header (index-thread-links.c)
+     - CVE-2026-40015: imap-hibernate can be crashed
+     - CVE-2026-40017: IMAP THREAD O(M³) CPU DoS via CRC32 Hash Collision
+       in strmap (mail-index-strmap.c / hash2.c)
+     - CVE-2026-40018: MySQL multi-byte escaping wrong
+     - CVE-2026-40204: acl: lda_mailbox_autocreate can bypass acl
+       restrictions
+     - CVE-2026-42007: Sieve editheader RCE
+     - CVE-2026-42391: imap: Pre-login memory/CPU growth with ID command
+     - CVE-2026-42394: sieve: symlink traversal flaw could result in
+       arbitrary file disclosure
+     - CVE-2026-52681: Sieve resource usage tracking lost when active
+       script changes
+     - CVE-2026-52687: IMAP: COMPRESS ZSTD can cause excessive memory usage
+     - CVE-2026-73209: imap-login crash: Self-recursion on zero-output
+       decompress chunks
+     - CVE-2026-33606: dsync: Mail content can cause dsync protocol
+       injection
+     - CVE-2026-40203: IMAP Compression Can Reveal Whether a Small Synced
+       Email Body Matches Sender-Chosen Text
+     - CVE-2026-42008: XCLIENT FORWARD= bare token not namespaced, allows
+       nopassword injection via trusted proxy
+     - CVE-2026-42392: imap-urlauth leaks memory into user-visible error
+       messages
+     - CVE-2026-42393: doveadm_password or api key length can still be
+       leaked with timing comparisons
+     - CVE-2026-42395: Single NUL-Byte XCLIENT FORWARD Payload Crashes
+     - CVE-2026-40205: OAuth2 passdb scope enforcement bypass via OR
+       semantics in remote validation path
+     - CVE-2026-73208: auth: db-oauth2: aud claim used as fallback for
+       missing scope claim
+   * lib-mail: istream-header-filter - Fix potential assert-crash
+     (Closes: #1144639)
+   * CI: Disable test-build-twice job, which is known to fail on trixie
+ 
+  -- Noah Meyerhans <noahm@debian.org>  Wed, 16 Sep 2026 15:06:35 -0400
  
  dovecot (1:2.4.1+dfsg1-6+deb13u6) trixie-security; urgency=medium
  
diff --cc debian/rules
Simple merge