From: Aki Tuomi Date: Wed, 11 Mar 2026 10:46:53 +0000 (+0200) Subject: [PATCH 24/24] auth: passdb-sql - Require update_query to be set when used X-Git-Tag: archive/raspbian/1%2.4.1+dfsg1-6+rpi1+deb13u4^2~11 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=fe55a13457f0d9bc21ce65c0525eb4fdb92b88f1;p=dovecot.git [PATCH 24/24] auth: passdb-sql - Require update_query to be set when used Gbp-Pq: Name CVE-2026-27855-4.patch --- diff --git a/src/auth/passdb-sql.c b/src/auth/passdb-sql.c index 2829160..ec160e3 100644 --- a/src/auth/passdb-sql.c +++ b/src/auth/passdb-sql.c @@ -270,6 +270,12 @@ static void sql_set_credentials(struct auth_request *request, return; } + if (*set->update_query == '\0') { + e_error(authdb_event(request), "passdb_sql_update_query is empty"); + callback(FALSE, request); + return; + } + sql_request = i_new(struct passdb_sql_request, 1); sql_request->auth_request = request; sql_request->callback.set_credentials = callback;