-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 18 May 2026 16:03:51 -0400 Source: dovecot Binary: dovecot-auth-lua dovecot-auth-lua-dbgsym dovecot-core dovecot-core-dbgsym dovecot-dev dovecot-flatcurve dovecot-flatcurve-dbgsym dovecot-gssapi dovecot-gssapi-dbgsym dovecot-imapd dovecot-imapd-dbgsym dovecot-ldap dovecot-ldap-dbgsym dovecot-lmtpd dovecot-lmtpd-dbgsym dovecot-managesieved dovecot-managesieved-dbgsym dovecot-mysql dovecot-mysql-dbgsym dovecot-pgsql dovecot-pgsql-dbgsym dovecot-pop3d dovecot-pop3d-dbgsym dovecot-sieve dovecot-sieve-dbgsym dovecot-solr dovecot-solr-dbgsym dovecot-sqlite dovecot-sqlite-dbgsym dovecot-submissiond dovecot-submissiond-dbgsym Architecture: arm64 Version: 1:2.4.1+dfsg1-6+deb13u6 Distribution: trixie-security Urgency: medium Maintainer: arm64 Build Daemon (arm-ubc-01) Changed-By: Noah Meyerhans Description: dovecot-auth-lua - secure POP3/IMAP server - Lua authentication plugin dovecot-core - secure POP3/IMAP server - core files dovecot-dev - secure POP3/IMAP server - header files dovecot-flatcurve - secure POP3/IMAP server - Flatcurve support dovecot-gssapi - secure POP3/IMAP server - GSSAPI support dovecot-imapd - secure POP3/IMAP server - IMAP daemon dovecot-ldap - secure POP3/IMAP server - LDAP support dovecot-lmtpd - secure POP3/IMAP server - LMTP server dovecot-managesieved - secure POP3/IMAP server - ManageSieve server dovecot-mysql - secure POP3/IMAP server - MySQL support dovecot-pgsql - secure POP3/IMAP server - PostgreSQL support dovecot-pop3d - secure POP3/IMAP server - POP3 daemon dovecot-sieve - secure POP3/IMAP server - Sieve filters support dovecot-solr - secure POP3/IMAP server - Solr support dovecot-sqlite - secure POP3/IMAP server - SQLite support dovecot-submissiond - secure POP3/IMAP server - mail submission agent Closes: 1136444 Changes: dovecot (1:2.4.1+dfsg1-6+deb13u6) trixie-security; urgency=medium . * Security update (Closes: #1136444) * [76ceed4] CVE-2026-27851: lib-var-expand: Reset safe state when transfer is unset * [4af6fb3] CVE-2026-40016: lib-sieve: Enforce CPU time limit within :contains and :matches matcher loops * [366ef61] CVE-2026-33603: login-common: Only accept base64 in sasl * [26bd41e] CVE-2026-40020: IMAP folders can be shared-spammed to everyone. * [b6f5bac] CVE-2026-42006: imap-login: Excessive memory usage DoS Checksums-Sha1: 796b1a0e0df24f85a22cc0418b27dcd8571fa101 31908 dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 45b33adde5e0a89190e118bf230897f2792a82b4 21512 dovecot-auth-lua_2.4.1+dfsg1-6+deb13u6_arm64.deb 29c4c24f131c220ba4b2bdce672e3fd9d72128e4 10738952 dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb bd6f5fbbf02343a4ebf2ef55234608530157a195 2503636 dovecot-core_2.4.1+dfsg1-6+deb13u6_arm64.deb b5265e523fbf3f125cd9b7b510226bc49c040906 429432 dovecot-dev_2.4.1+dfsg1-6+deb13u6_arm64.deb c11145d5885e74b152ef68b3f1149c6aeb7f4610 185664 dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 2c50fcd6544e3714ffb38e526cb9e1d225170d00 40124 dovecot-flatcurve_2.4.1+dfsg1-6+deb13u6_arm64.deb c7fa046abda37bc2edb7d8a3e9c48e2693d8c21f 20948 dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 1f7bbfeb96e30a0b8a2034c0d6d4f5863bb3e555 18408 dovecot-gssapi_2.4.1+dfsg1-6+deb13u6_arm64.deb f0e29e83a665dfd629fd9ccbfadd236eeb1b13bb 803032 dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 98b9afeb78cab0eff498f85e8429e6566401778f 182148 dovecot-imapd_2.4.1+dfsg1-6+deb13u6_arm64.deb 1fd717409e8bcc530622be4beee3c48e86f4a81c 189688 dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 242e334a6357f9263b9c6aa74a3b95260e8425cd 51064 dovecot-ldap_2.4.1+dfsg1-6+deb13u6_arm64.deb 5fd24dcc9f6934b6af7e045d42f79e76881b2a1d 99592 dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 16af8d3920229f6f74151798b994a29ae1b3fa69 35368 dovecot-lmtpd_2.4.1+dfsg1-6+deb13u6_arm64.deb 07595777beacd62bfa3bf8540627fc9aef4fbe2b 125460 dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 766354ef272abd4958ead3e6f6a880a3e401f5bb 46704 dovecot-managesieved_2.4.1+dfsg1-6+deb13u6_arm64.deb cf1b27ee95215b911dffc70fec31b7ae52abdd5a 35196 dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 8a83348f57b5133e9bc7fde3e35667786b6e667d 20636 dovecot-mysql_2.4.1+dfsg1-6+deb13u6_arm64.deb 2559c730b80e1ad6ad681feddbcd3935b54bcd89 37772 dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 672850cd2d44aaeb62517ae2c34c1509af5c8ac7 23732 dovecot-pgsql_2.4.1+dfsg1-6+deb13u6_arm64.deb d653dffb304d851b0f32bd71b7b933c9ef51c372 104896 dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 6d4c62fcbec7ae37f6580de2e895e20095047732 43440 dovecot-pop3d_2.4.1+dfsg1-6+deb13u6_arm64.deb 70b2cb79a6767b2ed57e47894e2244cbf7cac216 1718676 dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb dd7e6c13e103c865f389f7acb636ed060a7af5a8 352052 dovecot-sieve_2.4.1+dfsg1-6+deb13u6_arm64.deb 74cdb4bab33577c6ac637c252148578618cfa291 73928 dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 6e33e97b3bfa26f83194d5797161b9e4468c3433 37260 dovecot-solr_2.4.1+dfsg1-6+deb13u6_arm64.deb 2b0fdf0ee9a3f8d02454dded0a401e7db6392aa9 24456 dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb d3144ac434cfc1249084526a1a12dfabb94491a1 19884 dovecot-sqlite_2.4.1+dfsg1-6+deb13u6_arm64.deb 4a5ebf7850616d91224fb547525af773671ddbc6 208756 dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb bd3ec89cba46d89d612c14f73c9c3b57c01c083e 58376 dovecot-submissiond_2.4.1+dfsg1-6+deb13u6_arm64.deb 8f6e4fdddce6fc787e7dd6f2cff581c42cb0b8df 18052 dovecot_2.4.1+dfsg1-6+deb13u6_arm64-buildd.buildinfo Checksums-Sha256: 402b4f7fd32c7cc4dde7c5ccc08fa354e9accb8cf68537529e772115b833c320 31908 dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb a4280c896d1ad9d0ac6404249b9c2b1b1ea56ff9e5e6ea116ceaf51b3774cf29 21512 dovecot-auth-lua_2.4.1+dfsg1-6+deb13u6_arm64.deb 1d1a7161c35eb2eb58f4c2681e287f4a1c7f9d8285737399992816661893d080 10738952 dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 70fbcc1258af0640ee3a8337f1d5e23b486ac5d44c5aa04c5253a1f46e12cf80 2503636 dovecot-core_2.4.1+dfsg1-6+deb13u6_arm64.deb e58a5436fba568a3f187368e4467a485d6a2720805ed33ecf767d812d1767851 429432 dovecot-dev_2.4.1+dfsg1-6+deb13u6_arm64.deb 28d59fa1751ef9366370a1ae63f72fa6a43a46fb9cb7607ad31f0d5c963c07fa 185664 dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 2dc72f863c4b24dddc2c648fe37dac3788906efc48c55cb2a5b3580981e0587c 40124 dovecot-flatcurve_2.4.1+dfsg1-6+deb13u6_arm64.deb e457f37b084d6ce9d4d6d5ca5de2b920ad7b2175b056b614b76bf271b4a3a538 20948 dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 6a5776f142616d7b7ee66576cd66c8468403a98488bfc03da146e739e6206a21 18408 dovecot-gssapi_2.4.1+dfsg1-6+deb13u6_arm64.deb c3640f642009d13cda566af2733892fe4b18fc903e9629439b656d64b1a16fd5 803032 dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 3fb9703f8a73fb6028d916818bdf7b611cf92b62c191b4a05acf4b566fd2276f 182148 dovecot-imapd_2.4.1+dfsg1-6+deb13u6_arm64.deb 0f6ad638a3667d4d846cfd59aad0c80436146cf35e3613a281dffb59eeec87ad 189688 dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 23edf3d5a45e3077bd80e0af032b3143596823eb86b2ee2c0ee5ef6d5c7710a9 51064 dovecot-ldap_2.4.1+dfsg1-6+deb13u6_arm64.deb 3f607daedeb0c75fad2abf670ad29f901a293dc8603d6d2039c9729618fb6060 99592 dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 6a87ae728c075e3c6dcb0910411c5cd6efc301cbed9f0edd4f70f7cc039cdc7f 35368 dovecot-lmtpd_2.4.1+dfsg1-6+deb13u6_arm64.deb 02fc80e632eabe46c7d4d2c8a3655c6f18df720befee9d5f37aab844025d0899 125460 dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb d583a794034ebe6d096406524477ad3411106cfdb4a3a9761386604b178ed0a7 46704 dovecot-managesieved_2.4.1+dfsg1-6+deb13u6_arm64.deb 5eac596ab1437da86f0d6cc9c0210206ba7bc6a05e124848d7bfe877cb05f3c6 35196 dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 27945d2d033a190b5b79d617f2499926fd87888cff7a79074e4029a2ea542eff 20636 dovecot-mysql_2.4.1+dfsg1-6+deb13u6_arm64.deb d5c7dac17dc445db17fd842745d75eade4ffa18bf15ff3d805e4b55c71396b10 37772 dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 0efd81eb4aa389ff48166d1ddcdfd9430944407b8d432e7d9df7c7e04ec49fc0 23732 dovecot-pgsql_2.4.1+dfsg1-6+deb13u6_arm64.deb 1f2ba2ac038f49595aa36168811c3c0e733c17aedcecae50a39bbd8da0c6c621 104896 dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb fb8b2827805e0ffb1aa6b586bb59cb18ca6ba200e7dee1f1687b4cbe1c0ec1ce 43440 dovecot-pop3d_2.4.1+dfsg1-6+deb13u6_arm64.deb a5083ea3dece43107f109a094ce462d85777d5be6af688f4d338d8b42dd9baec 1718676 dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb c87b80881eb32db803cd1b0c5fce4298c0a67811e5008a3d568ffed56352ebc7 352052 dovecot-sieve_2.4.1+dfsg1-6+deb13u6_arm64.deb f53aaac32d448fac3e2f3d5df70bda7edac775afc46e43176b4e39e9b5a4a025 73928 dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb c31b5c88cdda5b38ddeb193b4e234f8c8acd8bf179c1354b9cd745f34ca96113 37260 dovecot-solr_2.4.1+dfsg1-6+deb13u6_arm64.deb 3b220d33939aee54365a2f111752a04a921af9c07f46f0c0151e2b8286222a2b 24456 dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 6d5019ad84f5ccbe949785a099cb94a0172adeae669110d9fac2036164a7e79f 19884 dovecot-sqlite_2.4.1+dfsg1-6+deb13u6_arm64.deb e423efb80f523b22101b685d0c22e9a595341f10d58d95e088f199f501c95650 208756 dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb c4e26fc748341b724ff4cb98012f8ad8ce4e7f017dd47a1b36692c8a106ae772 58376 dovecot-submissiond_2.4.1+dfsg1-6+deb13u6_arm64.deb fa690f7494c86a53eda77d94961b586b0b54b7c6490e4443ababebd58e19def8 18052 dovecot_2.4.1+dfsg1-6+deb13u6_arm64-buildd.buildinfo Files: 3191f6629462a02294c5c47799d102bb 31908 debug optional dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb d888e016f6c827c60659b3301d0f01a1 21512 mail optional dovecot-auth-lua_2.4.1+dfsg1-6+deb13u6_arm64.deb a3a1b80e021f74f1c13b98515bb696b1 10738952 debug optional dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb eb7fda62c5ce24dfd897f8a3dd0cf092 2503636 mail optional dovecot-core_2.4.1+dfsg1-6+deb13u6_arm64.deb 6391d47ab6517932707740af559745ee 429432 mail optional dovecot-dev_2.4.1+dfsg1-6+deb13u6_arm64.deb e59ea40871caec811a98f8423e5ef34a 185664 debug optional dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 4c5dde44a0c6a2daf0d85cbecce4374b 40124 mail optional dovecot-flatcurve_2.4.1+dfsg1-6+deb13u6_arm64.deb b81a37550c0cb9b681b03e543381324c 20948 debug optional dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 7a57d7668437ea4a6a35b990900aa581 18408 mail optional dovecot-gssapi_2.4.1+dfsg1-6+deb13u6_arm64.deb b9b5ef7427b07f95277d416ca1782d4d 803032 debug optional dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb ca3c83b52a39a5e71054f388595fe67e 182148 mail optional dovecot-imapd_2.4.1+dfsg1-6+deb13u6_arm64.deb 2e9e622f6f76dd5f59e660c30d1e2e96 189688 debug optional dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 3e96a2ff8bffff56be651295b29dd1f4 51064 mail optional dovecot-ldap_2.4.1+dfsg1-6+deb13u6_arm64.deb 4a7c5311289aeef290f58e1db2228386 99592 debug optional dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb d6873ec80c21e27aa5fb9768b81f6aa9 35368 mail optional dovecot-lmtpd_2.4.1+dfsg1-6+deb13u6_arm64.deb f889e04331b98b9d0824a86881e9b8b0 125460 debug optional dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb e01cf4db50279e3cfe2e1325a0fa4e52 46704 mail optional dovecot-managesieved_2.4.1+dfsg1-6+deb13u6_arm64.deb de30482c22b40745f4fce4b5bf947b5c 35196 debug optional dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 0a67edbf9a6da9f93ab875c6ef36d836 20636 mail optional dovecot-mysql_2.4.1+dfsg1-6+deb13u6_arm64.deb d3e629a399779f97ab4d9408b1ad3d3d 37772 debug optional dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb df0a2f39427900945113ae4fa79c9f2d 23732 mail optional dovecot-pgsql_2.4.1+dfsg1-6+deb13u6_arm64.deb f3416b1b383a247889482e35395e9627 104896 debug optional dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 72c8f1774dea9e138eee74aeac973194 43440 mail optional dovecot-pop3d_2.4.1+dfsg1-6+deb13u6_arm64.deb 031ddc465ac8f34033e5e3423b959c01 1718676 debug optional dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 297ef176610e5209adc07abbb5c3ae8e 352052 mail optional dovecot-sieve_2.4.1+dfsg1-6+deb13u6_arm64.deb 2e2e4efe77354db1145936044c0a49ee 73928 debug optional dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 49ddbaa2f405bee25129e5648981b9f7 37260 mail optional dovecot-solr_2.4.1+dfsg1-6+deb13u6_arm64.deb 8ebd7fa95508a497361a84f91e9b8faf 24456 debug optional dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 9a9f8852c9d2c6c6e7137c0875a32d62 19884 mail optional dovecot-sqlite_2.4.1+dfsg1-6+deb13u6_arm64.deb 7f01ddaa9da031b2c5dbbcc2e861cba4 208756 debug optional dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u6_arm64.deb 31644f77bc78ba2e55bc32e8b7a9fbc2 58376 mail optional dovecot-submissiond_2.4.1+dfsg1-6+deb13u6_arm64.deb 1e497eb72124fb83205e26c9b968dec2 18052 mail optional dovecot_2.4.1+dfsg1-6+deb13u6_arm64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0Ha//LlsGOpbQ/H4xqCFmsOWgoYFAmoZ9AAACgkQxqCFmsOW goaxLQ//WZ2zFmnarLuEli4nzX/F1kKNWLgn7t2CQbmd/VDWnK3B+aBFKHhP2iCa tuARyQzGigbs4SjfRrNxptC0ZNJp/T0cx/ibqoYc0j9OnCfYeDFORrDrN/fzcTEF g+Zc2P9wBurNLCGr381Wo3kEfaC/poma8Ne7FOYohs4d6oaSHkVnlqKMjDNWAben UqzJHWmoij/CxE9VhzxFVvpw2u9JMVkH6TYhWsXFXSMqJtEOKdz7wq/w63BXqDIe nk54IpTjgwWSblN8UEa8H78y7Irni+X+3B1IKfEZBhm+XaG6IWAKZSef1tZGk7oW JNPqdveNwoJ/vvhUzFF8MrPpArO0xFbePRsVgC+iMD7oqg9oGYZCfzQHuspv8CG0 aTdpoBg85IJX1IdoKqK/P4Nk5rqRt7NqqnBJdK3J+jeFmv93qg58S3EAfodbjoHA 7r9qV7xuRf7Js+JUgsY85RKW+sH0rzQf0kOAIe2fNla9dIqRFdyNW4m27WZQ61Yx omVhgMXv6OgLiOmrGx5c0PimUmbHCEErlM89sd9kj+q/aUx6Cp+BYTT3Yme/CKpR +QvebrpwBVx92mKICuAVRWX04TBC+iFNOrlJAZmLiwwNwdQ2GMRHzbdb5BqkxsR7 5P7vrN501Dk2HRU8V6q7Kg4w4MBknDGJS+ZFSEbM1MLbL3ZfbQY= =dP8X -----END PGP SIGNATURE-----