From: Raspbian automatic forward porter Date: Fri, 2 Oct 2026 09:09:32 +0000 (+0100) Subject: Merge version 1:2.4.1+dfsg1-6+rpi1+deb13u6 and 1:2.4.1+dfsg1-6+deb13u7 to produce... X-Git-Tag: archive/raspbian/1%2.4.1+dfsg1-6+rpi1+deb13u7^0 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=8d754b4c2d859bf4f21bde1d2aba5946c5fe9125;p=dovecot.git Merge version 1:2.4.1+dfsg1-6+rpi1+deb13u6 and 1:2.4.1+dfsg1-6+deb13u7 to produce 1:2.4.1+dfsg1-6+rpi1+deb13u7 --- 8d754b4c2d859bf4f21bde1d2aba5946c5fe9125 diff --cc debian/changelog index 1dd5d97,84b35de..53d113f --- a/debian/changelog +++ b/debian/changelog @@@ -1,9 -1,54 +1,61 @@@ - dovecot (1:2.4.1+dfsg1-6+rpi1+deb13u6) trixie-staging; urgency=medium ++dovecot (1:2.4.1+dfsg1-6+rpi1+deb13u7) trixie-staging; urgency=medium + + [changes brought forward from 1:2.3.21+dfsg1-3+rpi1 by Peter Michael Green at Thu, 20 Jun 2024 17:16:27 +0000] + * Disablte testsuite. + - -- Raspbian forward porter Sun, 31 May 2026 20:32:39 +0000 ++ -- Raspbian forward porter Fri, 02 Oct 2026 09:09:32 +0000 ++ + dovecot (1:2.4.1+dfsg1-6+deb13u7) trixie-security; urgency=medium + + * Import upstream fixes for multiple security issues. (Closes: #1146018) + - CVE-2026-27852: DoS by sending mail with bad header + - CVE-2026-33263: submission-login: Panic when + mail_max_userip_connections is reached: Panic: epoll_ctl(del, 8) + failed: Bad file descriptor + - CVE-2026-33604: SMTP Smuggling via Missing Dot-Stuffing After Bare + Carriage Return + - CVE-2026-33605: managesieve-login: Pre-auth crash + - CVE-2026-33607: Dovecot IMAP LIST match_sub() Exponential + Backtracking — CPU Denial of Service + - CVE-2026-40013: pigeonhole: Stack Buffer Underflow in Pigeonhole + ManageSieve CHECKSCRIPT/PUTSCRIPT + - CVE-2026-40014: IMAP THREAD REFERENCES O(N²) CPU DoS via Crafted + References Header (index-thread-links.c) + - CVE-2026-40015: imap-hibernate can be crashed + - CVE-2026-40017: IMAP THREAD O(M³) CPU DoS via CRC32 Hash Collision + in strmap (mail-index-strmap.c / hash2.c) + - CVE-2026-40018: MySQL multi-byte escaping wrong + - CVE-2026-40204: acl: lda_mailbox_autocreate can bypass acl + restrictions + - CVE-2026-42007: Sieve editheader RCE + - CVE-2026-42391: imap: Pre-login memory/CPU growth with ID command + - CVE-2026-42394: sieve: symlink traversal flaw could result in + arbitrary file disclosure + - CVE-2026-52681: Sieve resource usage tracking lost when active + script changes + - CVE-2026-52687: IMAP: COMPRESS ZSTD can cause excessive memory usage + - CVE-2026-73209: imap-login crash: Self-recursion on zero-output + decompress chunks + - CVE-2026-33606: dsync: Mail content can cause dsync protocol + injection + - CVE-2026-40203: IMAP Compression Can Reveal Whether a Small Synced + Email Body Matches Sender-Chosen Text + - CVE-2026-42008: XCLIENT FORWARD= bare token not namespaced, allows + nopassword injection via trusted proxy + - CVE-2026-42392: imap-urlauth leaks memory into user-visible error + messages + - CVE-2026-42393: doveadm_password or api key length can still be + leaked with timing comparisons + - CVE-2026-42395: Single NUL-Byte XCLIENT FORWARD Payload Crashes + - CVE-2026-40205: OAuth2 passdb scope enforcement bypass via OR + semantics in remote validation path + - CVE-2026-73208: auth: db-oauth2: aud claim used as fallback for + missing scope claim + * lib-mail: istream-header-filter - Fix potential assert-crash + (Closes: #1144639) + * CI: Disable test-build-twice job, which is known to fail on trixie + + -- Noah Meyerhans Wed, 16 Sep 2026 15:06:35 -0400 dovecot (1:2.4.1+dfsg1-6+deb13u6) trixie-security; urgency=medium