Release date:
2026-08-13 11:12:02 UTC
Description:
* SECURITY UPDATE: managesieve-login pre-auth excessive memory usage
DoS via oversized AUTHENTICATE initial response (ELSCVE-158958)
- debian/patches/CVE-2026-27858.patch: verify the AUTHENTICATE initial
response size is not too large before allocating in
pigeonhole/src/managesieve-login/client-authenticate.c. Backport of
upstream pigeonhole commit 54f645225a8a; hunk context is this tree's
pre-cc1b8988 (unreformatted) layout.
- CVE-2026-27858
Updated packages:
-
dovecot-core_2.2.33.2-1ubuntu4.8+tuxcare.els1_amd64.deb
sha:01466e04bbb3207d566ea4bf4079837f90bb01f9
-
dovecot-dev_2.2.33.2-1ubuntu4.8+tuxcare.els1_amd64.deb
sha:ff12e813b3b900b35c7417730b665ba94d89f216
-
dovecot-gssapi_2.2.33.2-1ubuntu4.8+tuxcare.els1_amd64.deb
sha:60a8ba60245b6bc5f3a0eb997ee45ff73f286473
-
dovecot-imapd_2.2.33.2-1ubuntu4.8+tuxcare.els1_amd64.deb
sha:619661cb44ec2e2eb0d6dd868f636e65b281cc7c
-
dovecot-ldap_2.2.33.2-1ubuntu4.8+tuxcare.els1_amd64.deb
sha:b5bf1abf301bc24a133429adf31a73adf489c1e7
-
dovecot-lmtpd_2.2.33.2-1ubuntu4.8+tuxcare.els1_amd64.deb
sha:a83841e9d3e2a1da7013e42353b2dcab7cc9e998
-
dovecot-managesieved_2.2.33.2-1ubuntu4.8+tuxcare.els1_amd64.deb
sha:8db428fc65384eb42226f6cf805a054f376b877d
-
dovecot-mysql_2.2.33.2-1ubuntu4.8+tuxcare.els1_amd64.deb
sha:7c4039bf0cfb15d2aad8e4462766c10de2acb97b
-
dovecot-pgsql_2.2.33.2-1ubuntu4.8+tuxcare.els1_amd64.deb
sha:d79f54e247bf7a3bdb7ea19bd55c77626034c181
-
dovecot-pop3d_2.2.33.2-1ubuntu4.8+tuxcare.els1_amd64.deb
sha:3f9a6e8f11a3239db56c09ceadaba323c129ba46
-
dovecot-sieve_2.2.33.2-1ubuntu4.8+tuxcare.els1_amd64.deb
sha:b5a9d348796574e4a1b01a185346a642116dad71
-
dovecot-solr_2.2.33.2-1ubuntu4.8+tuxcare.els1_amd64.deb
sha:9a160a4451d87de3d14688c549ea1dc64ad8485d
-
dovecot-sqlite_2.2.33.2-1ubuntu4.8+tuxcare.els1_amd64.deb
sha:489080b67e243c2ec6ec0ee00678256f127d0083
-
mail-stack-delivery_2.2.33.2-1ubuntu4.8+tuxcare.els1_all.deb
sha:56ea463b730907237ba071b6f4482131f6b10282
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.