From: Timo Sirainen Date: Thu, 16 Apr 2026 15:38:53 +0000 (+0200) Subject: [PATCH 6/6] imap: Reset DEFLATE dictionary after every tagged reply X-Git-Tag: archive/raspbian/1%2.4.1+dfsg1-6+rpi1+deb13u7^2~8 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=54bc55bcec415f0097a4f9de21110a52f4696f70;p=dovecot.git [PATCH 6/6] imap: Reset DEFLATE dictionary after every tagged reply Prevents CRIME-style cross-command compression oracle attacks (CVE-class: compression side-channel). Without this fix an observer who can inject chosen plaintext into one IMAP command's response can measure the compressed size of a subsequent command's response and determine whether the secret content matches the injected plaintext. After each tagged response line is sent, the DEFLATE compression dictionary is reset via Z_FULL_FLUSH so that the compression history from one command cannot influence the compressed size of the next. For direct compression (imap_compress_on_proxy=no) the reset is applied to the local ostream. For proxy-mode compression (imap_compress_on_proxy=yes) a "dict_reset" command is sent over the multiplex side channel to the imap-login process. Gbp-Pq: Name 0006-imap-Reset-DEFLATE-dictionary-after-every-tagged-rep.patch --- diff --git a/src/imap/imap-client.c b/src/imap/imap-client.c index 3de9391..8d4a5aa 100644 --- a/src/imap/imap-client.c +++ b/src/imap/imap-client.c @@ -12,6 +12,7 @@ #include "istream-concat.h" #include "ostream.h" #include "ostream-multiplex.h" +#include "ostream-zlib.h" #include "time-util.h" #include "settings.h" #include "master-service.h" @@ -712,6 +713,22 @@ client_default_send_tagline(struct client_command_context *cmd, const char *data } T_END; client->last_output = ioloop_time; + + /* Reset the DEFLATE compression dictionary after every tagged reply so + that cross-command compression correlation attacks (CRIME-style) are + not possible. For proxy-mode compression the reset is forwarded to + the imap-login process via the side channel; for direct compression + it is applied to the local ostream immediately. */ + if (client->compress_handler != NULL) { + if (client->multiplex_output != NULL && + client->set->imap_compress_on_proxy) { + i_assert(client->side_channel_output != NULL); + o_stream_nsend_str(client->side_channel_output, + "dict_reset\n"); + } else { + o_stream_deflate_reset_dict(client->output); + } + } } static int