[CLSA-2026:1778750122] Fix CVE(s): CVE-2026-27857
Type:
security
Severity:
Important
Release date:
2026-05-14 09:15:27 UTC
Description:
* SECURITY UPDATE: imap-login excessive memory usage DoS (ELSCVE-123445) - debian/patches/CVE-2026-27857.patch: limit IMAP parser open list count via new imap_parser_params struct; cap pre-auth IMAP_LOGIN_LIST_COUNT_LIMIT to 1. Squashes upstream commits 825bc297, d0f67b52, af1fb4da, 3435e0d44. - CVE-2026-27857
Updated packages:
  • dovecot-auth-lua_2.3.7.2-1ubuntu3.7+tuxcare.els1_amd64.deb
    sha:6af4d3c8eb56d952854146c750c6128e0bff2f84
  • dovecot-core_2.3.7.2-1ubuntu3.7+tuxcare.els1_amd64.deb
    sha:56e66f188804af78e11a862839ee8dd59d0a96e2
  • dovecot-dev_2.3.7.2-1ubuntu3.7+tuxcare.els1_amd64.deb
    sha:b9e078c932e6626392f44f6b0e6e08e60c677088
  • dovecot-gssapi_2.3.7.2-1ubuntu3.7+tuxcare.els1_amd64.deb
    sha:f56fda794b8e4d831f5338018727ea6cc4ff01c4
  • dovecot-imapd_2.3.7.2-1ubuntu3.7+tuxcare.els1_amd64.deb
    sha:241418d42b7f9b66c0826ac725d13c37f6fc0a3e
  • dovecot-ldap_2.3.7.2-1ubuntu3.7+tuxcare.els1_amd64.deb
    sha:26b4ccdeac6181b71c92a0decd3b57f350cd2ea7
  • dovecot-lmtpd_2.3.7.2-1ubuntu3.7+tuxcare.els1_amd64.deb
    sha:21e128503439588805af834cce550ad2dd92a408
  • dovecot-lucene_2.3.7.2-1ubuntu3.7+tuxcare.els1_amd64.deb
    sha:8cd0be397556ff370febb94f9df6d13c56ccd6b1
  • dovecot-managesieved_2.3.7.2-1ubuntu3.7+tuxcare.els1_amd64.deb
    sha:1325131603afba4613f5e0c8fd30a2b2329130ed
  • dovecot-mysql_2.3.7.2-1ubuntu3.7+tuxcare.els1_amd64.deb
    sha:fc4cb9b80a5ae261c086723ac35bc499175495d0
  • dovecot-pgsql_2.3.7.2-1ubuntu3.7+tuxcare.els1_amd64.deb
    sha:8fa1f3052fb52426356221a8bcc67d528d69f478
  • dovecot-pop3d_2.3.7.2-1ubuntu3.7+tuxcare.els1_amd64.deb
    sha:db91f362393e594e3e43d6e33833978f1569273c
  • dovecot-sieve_2.3.7.2-1ubuntu3.7+tuxcare.els1_amd64.deb
    sha:ffc0d5fc7e5eb7932f379a337aba0fdca4cf0546
  • dovecot-solr_2.3.7.2-1ubuntu3.7+tuxcare.els1_amd64.deb
    sha:9ec7f8e9296629a68d476fd5dca1cdfe4947da9f
  • dovecot-sqlite_2.3.7.2-1ubuntu3.7+tuxcare.els1_amd64.deb
    sha:4a566c17e92a36503119cba13a34ea40a444bdbe
  • dovecot-submissiond_2.3.7.2-1ubuntu3.7+tuxcare.els1_amd64.deb
    sha:d7a68071dbe462a626d9c7a9b685d3426cad5972
  • mail-stack-delivery_2.3.7.2-1ubuntu3.7+tuxcare.els1_all.deb
    sha:c4d0de74660625cd8d4fbe4f2ed1a8a023c0c879
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.