-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 31 Mar 2026 15:07:17 -0400 Source: dovecot Binary: dovecot-auth-lua dovecot-auth-lua-dbgsym dovecot-core dovecot-core-dbgsym dovecot-dev dovecot-flatcurve dovecot-flatcurve-dbgsym dovecot-gssapi dovecot-gssapi-dbgsym dovecot-imapd dovecot-imapd-dbgsym dovecot-ldap dovecot-ldap-dbgsym dovecot-lmtpd dovecot-lmtpd-dbgsym dovecot-managesieved dovecot-managesieved-dbgsym dovecot-mysql dovecot-mysql-dbgsym dovecot-pgsql dovecot-pgsql-dbgsym dovecot-pop3d dovecot-pop3d-dbgsym dovecot-sieve dovecot-sieve-dbgsym dovecot-solr dovecot-solr-dbgsym dovecot-sqlite dovecot-sqlite-dbgsym dovecot-submissiond dovecot-submissiond-dbgsym Architecture: i386 Version: 1:2.4.1+dfsg1-6+deb13u4 Distribution: trixie-security Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-02) Changed-By: Noah Meyerhans Description: dovecot-auth-lua - secure POP3/IMAP server - Lua authentication plugin dovecot-core - secure POP3/IMAP server - core files dovecot-dev - secure POP3/IMAP server - header files dovecot-flatcurve - secure POP3/IMAP server - Flatcurve support dovecot-gssapi - secure POP3/IMAP server - GSSAPI support dovecot-imapd - secure POP3/IMAP server - IMAP daemon dovecot-ldap - secure POP3/IMAP server - LDAP support dovecot-lmtpd - secure POP3/IMAP server - LMTP server dovecot-managesieved - secure POP3/IMAP server - ManageSieve server dovecot-mysql - secure POP3/IMAP server - MySQL support dovecot-pgsql - secure POP3/IMAP server - PostgreSQL support dovecot-pop3d - secure POP3/IMAP server - POP3 daemon dovecot-sieve - secure POP3/IMAP server - Sieve filters support dovecot-solr - secure POP3/IMAP server - Solr support dovecot-sqlite - secure POP3/IMAP server - SQLite support dovecot-submissiond - secure POP3/IMAP server - mail submission agent Changes: dovecot (1:2.4.1+dfsg1-6+deb13u4) trixie-security; urgency=medium . * [bc29057] CVE-2025-59028: auth: Don't disconnect auth client when invalid base64 SASL input is received * [fee7a9a] CVE-2025-59031: stop shipping the decode2text shell script * [9a4442e] CVE-2025-59032: managesieve-login: Fix crash when command didn't finish on the first call * [2711b3e] CVE-2026-24031, CVE-2026-27860: auth: fix ldap and sql injection * [d30f1c3] CVE-2026-27855: fix OTP authentication reply vulnerability * [e1b0ff7] CVE-2026-27856: doveadm: fix timing oracle attack * [b8a69bf] CVE-2026-27857: fix resource exhaustion DoS in NOOP command parsing * [85dd068] CVE-2026-27858: fix pre-authentication managesieve memory consumption issue * [880e332] CVE-2026-27859: fix uncontrolled resource allocation when delivering specially crafted email messages Checksums-Sha1: b1b314f87ec40c7069bc24b9d0672700e81af274 28992 dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb f0e54b5254c67e0dc0d59cfa4fb279e9363c13dd 22696 dovecot-auth-lua_2.4.1+dfsg1-6+deb13u4_i386.deb b93468d36dd82e4e65e146cbbbf730cb42d0f4c6 9840976 dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 4bb04d084706d679497765215d36f0b526fc2181 2942756 dovecot-core_2.4.1+dfsg1-6+deb13u4_i386.deb 40227c6e5549c75d244fd55673fa796e89bab284 429020 dovecot-dev_2.4.1+dfsg1-6+deb13u4_i386.deb beb1d2c2c65bbb2216e9d995e3084827ba86b1f0 183256 dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb fb7c7fb503f7e6737f2165fd2839baf1bba11c36 45948 dovecot-flatcurve_2.4.1+dfsg1-6+deb13u4_i386.deb f03ff1cceeb7fc6f78b736c7e95a63ddacca7f79 19624 dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb a1ed5ab313f07d60ad846a2fc482735b36e793c9 18488 dovecot-gssapi_2.4.1+dfsg1-6+deb13u4_i386.deb 16534a40f39a6c2e411fa0193c7c2f3ff9bbbf69 746736 dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb e60d6f1ec05eb5ab687413d7673bee859fe71735 215828 dovecot-imapd_2.4.1+dfsg1-6+deb13u4_i386.deb da76eb4cefb0efe54ead929f1408dc61c3449fee 175660 dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb b93de82df0ae6fb0b91e505b9e001c0ffa14368f 57528 dovecot-ldap_2.4.1+dfsg1-6+deb13u4_i386.deb 356d4d24e2c396a9ceb922d68a8b2975006adf72 94000 dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb df2ec1529214646b4e1744c389385214f47b7e71 38760 dovecot-lmtpd_2.4.1+dfsg1-6+deb13u4_i386.deb 249ab77b15652f4d92d25d44c917ecee32e5c8ec 113084 dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb d9ebf473ee6b045f1689b4da513231f81c6a4b4f 50920 dovecot-managesieved_2.4.1+dfsg1-6+deb13u4_i386.deb 0d17c5e6421b962a7e876e084e8cde1d1c4e1daa 33120 dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 177c6a227ca1d83657d99a32341b1b5515aa0a18 21200 dovecot-mysql_2.4.1+dfsg1-6+deb13u4_i386.deb afac54ca86043713eb9e272beafe6c2016e051d9 35000 dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 8be3454a15a896c95fa24b4080c925bb6117af33 26524 dovecot-pgsql_2.4.1+dfsg1-6+deb13u4_i386.deb ceabb8fc3bd7b830c7e7dd4ac7cbb072ae0b3f1b 97976 dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb c13ea8f3cc15c4f814a4b6638116342bd65e3015 47832 dovecot-pop3d_2.4.1+dfsg1-6+deb13u4_i386.deb 78d8c842a50e76ced88ac6fe81a461b2f91ea2c4 1573952 dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb eb17ca18b4b611286f9224b287c90a399905144b 412368 dovecot-sieve_2.4.1+dfsg1-6+deb13u4_i386.deb 5d19ddae7048d1666feb69c6a3fad09513d5a36b 69224 dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 7b47e3e76ce37211ec9e3d108116addf2e1ea296 39080 dovecot-solr_2.4.1+dfsg1-6+deb13u4_i386.deb 9256d1fb09ccadab674b8f6e26231e2c1cc3bed9 22392 dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 859b86ecbf14f73bf7016a22b53a46dec699228f 20364 dovecot-sqlite_2.4.1+dfsg1-6+deb13u4_i386.deb 32ad75a8179097bde946ce9610d84678f762d608 193096 dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 50126f8f3be62d288c88474410a38bb9181bbf87 65720 dovecot-submissiond_2.4.1+dfsg1-6+deb13u4_i386.deb 2ec273f7a209e1bcb96cf0d3ad314150896c00ea 17775 dovecot_2.4.1+dfsg1-6+deb13u4_i386-buildd.buildinfo Checksums-Sha256: d2d537ec4078ea5b635fb7abd6418d705e2ad86e5a3715f1c750ed28943f6296 28992 dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 1731f679c959b573015c5db18abd0a318dab278ff81d86e97584de96ae694d09 22696 dovecot-auth-lua_2.4.1+dfsg1-6+deb13u4_i386.deb 66fb25e3442fba033a82baa10309e4f62dc2762cffee27c3e0fae60597e5c676 9840976 dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 11cf95e26d19b2585cc7f97b8e337800cb8e681906b7361beede5fae468c3432 2942756 dovecot-core_2.4.1+dfsg1-6+deb13u4_i386.deb d8403eb67a17099b916d84a7fb249ec65a6955bbf6adadd2bdc71a2583777d02 429020 dovecot-dev_2.4.1+dfsg1-6+deb13u4_i386.deb f2689feccf9b3b2e3cbeb39a1468d8eba79e4f68d1a731dd292c6c605559767a 183256 dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 3eb5c317ff4b8213719dba1a1f1136be18b6b8b0bf89ec73f004fa4b8611e4c9 45948 dovecot-flatcurve_2.4.1+dfsg1-6+deb13u4_i386.deb c7c69f4231e3d869b9ec7b4a0af9507d8cebd70721bcac14a98042f845156e4b 19624 dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 2a895662e3a50ed518b4bb33f1287ae2a3a542a1e9e5312b7d1136de0f51e0d1 18488 dovecot-gssapi_2.4.1+dfsg1-6+deb13u4_i386.deb db4948823327ba2ce08623315234508f7dd57e3bb082ee4b3c949ca4fbee0503 746736 dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 7bbc3e180b0144b65006f7b9bc8740e6e9d5f980899551bf20113b71d0c1bf97 215828 dovecot-imapd_2.4.1+dfsg1-6+deb13u4_i386.deb 538b4ae2732cebcde613cd5e6031d13c9b1cc431c97e62c2950a9760f036032c 175660 dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb bbade1617e5b9ae3f1604e60bff39ab0d73158670f26bc37dced020b90a64680 57528 dovecot-ldap_2.4.1+dfsg1-6+deb13u4_i386.deb 9b9534fe307eb272551dcfcefe72a50203fb16acd9fe20be002b9bcf54bea955 94000 dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 0e287073766f34af5b6e08255279a0f967016ae8fa55028e1424dc53c54669da 38760 dovecot-lmtpd_2.4.1+dfsg1-6+deb13u4_i386.deb f179d7d1787a21c32acd643f6d5df8a2bfe5618c0498e1c847c56503f9db385d 113084 dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 268dadc5c745fa438a6117ebb6b9ccf5601bdc470dfdcc97d6ca57b97bb2b841 50920 dovecot-managesieved_2.4.1+dfsg1-6+deb13u4_i386.deb 4add6f1a34488a9cd089c842e308bbfba491e9cdda2112d2b0bb18ed4fda7a84 33120 dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb e00cf0d46e612ba6723e78dc9ef4c8a27a2ea702e84bc89e64a5b5e01b3ea633 21200 dovecot-mysql_2.4.1+dfsg1-6+deb13u4_i386.deb 7c9d7fa0da27ce6dcf0e32504ee0d765bdc7c630c4aaac8598330d1eb712dbe5 35000 dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 02ee5c46b15dbcf4335e6cd0a0b5f5c0b800833a99e698fe8340bb083a297440 26524 dovecot-pgsql_2.4.1+dfsg1-6+deb13u4_i386.deb 83dbe17f6aa0894b34bcfba2401def6a81f5db0e693e374a93f2f4cfe84c54bc 97976 dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 76f0c5b165d4fab63abc3712b9181a231f2701669434d9a90f4ee53f6ed415d5 47832 dovecot-pop3d_2.4.1+dfsg1-6+deb13u4_i386.deb eeddcc94ac4d9778b8e13aee98fc4ec7aaf7bdf39b76033093e985e33d08bef1 1573952 dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb e20f5ba58b1262bda92605301ea1f1139a7c919f4f3b6ba361d1e57e9397c9b3 412368 dovecot-sieve_2.4.1+dfsg1-6+deb13u4_i386.deb 24ba04cf26678c3204e66e1476a30bbece7b2a8a837b4ca22d2a74ec64b336c6 69224 dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb f5981ba4d282351ff06bdbab41800140823a148ded807991344d64da1177b679 39080 dovecot-solr_2.4.1+dfsg1-6+deb13u4_i386.deb 3913b53709b177e1c6b88d76f28778f77b12d05f18b29f6e9640065f5cb94ccf 22392 dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb ce3f9965bd48ad0da0b7b4d58b24ca8d5068e65f6d7da1372fa14ce10c6947b6 20364 dovecot-sqlite_2.4.1+dfsg1-6+deb13u4_i386.deb ba5a5f416b30b161bf4f385c3b87f4e15bb831a2e56c9944832e4d6307c5cf7a 193096 dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb cd8a161f47e76f8afbeee59337c6cabd15071d3285f21dd6eec84609e29c3c7f 65720 dovecot-submissiond_2.4.1+dfsg1-6+deb13u4_i386.deb f8944a8ac9ad642311735e91565a59051f1bf225d25e2fb54d83fd5552658c5f 17775 dovecot_2.4.1+dfsg1-6+deb13u4_i386-buildd.buildinfo Files: e52768a25f7d6041c6a16a41f02423f0 28992 debug optional dovecot-auth-lua-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 29afc2f58056bb428688ce8bc657eaaf 22696 mail optional dovecot-auth-lua_2.4.1+dfsg1-6+deb13u4_i386.deb 32bbbeedc6bdbc88b728dbd204f097ae 9840976 debug optional dovecot-core-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 27021525d704a62efda93b166fff7c81 2942756 mail optional dovecot-core_2.4.1+dfsg1-6+deb13u4_i386.deb a1f7e9f89f6ed6f0447ad63a460cef9a 429020 mail optional dovecot-dev_2.4.1+dfsg1-6+deb13u4_i386.deb 713669133864b781f8c71b943209d9d8 183256 debug optional dovecot-flatcurve-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 0e6347818ac947265fc00bf4336b1e28 45948 mail optional dovecot-flatcurve_2.4.1+dfsg1-6+deb13u4_i386.deb 1357392eb810676c8e43ad9c2f7bf22d 19624 debug optional dovecot-gssapi-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 3761f4dd08ad4add60ff7caedff19cb9 18488 mail optional dovecot-gssapi_2.4.1+dfsg1-6+deb13u4_i386.deb 63fb2a7e69fe9b62942686dc9fb95aba 746736 debug optional dovecot-imapd-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 7f497494181b374c44f0baecb4ace73d 215828 mail optional dovecot-imapd_2.4.1+dfsg1-6+deb13u4_i386.deb 1dc1001780552ff226def61a79d83119 175660 debug optional dovecot-ldap-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb f2e883ef233d9082c15e264683b3c55e 57528 mail optional dovecot-ldap_2.4.1+dfsg1-6+deb13u4_i386.deb d50b3fe639f0982fc9ce233b249bbc4a 94000 debug optional dovecot-lmtpd-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 31e07ead433f84e7ff238c93443a291c 38760 mail optional dovecot-lmtpd_2.4.1+dfsg1-6+deb13u4_i386.deb 081c36a27b702851c37a7cc62c8e7447 113084 debug optional dovecot-managesieved-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 581c1bd30d794e01c5281d2ddab71caf 50920 mail optional dovecot-managesieved_2.4.1+dfsg1-6+deb13u4_i386.deb 8632ad8dcf43f1ec547e0540840712e1 33120 debug optional dovecot-mysql-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 547e7ec443c6838c89b0b73ce2707f20 21200 mail optional dovecot-mysql_2.4.1+dfsg1-6+deb13u4_i386.deb 9a1302ab72ddbdd707b5eb0d6193dc16 35000 debug optional dovecot-pgsql-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 0c2fe04acb6b2faff806a0d6536c92ac 26524 mail optional dovecot-pgsql_2.4.1+dfsg1-6+deb13u4_i386.deb 67cad312366a1d33f6d0de22fa7566a8 97976 debug optional dovecot-pop3d-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 27e011b146f9c905c71e0f4b33fa3b93 47832 mail optional dovecot-pop3d_2.4.1+dfsg1-6+deb13u4_i386.deb 82cc502eedf860b8df09558028344f96 1573952 debug optional dovecot-sieve-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb a89124fc40d488cf27cfe27dc78b4fdd 412368 mail optional dovecot-sieve_2.4.1+dfsg1-6+deb13u4_i386.deb 7a116f48780fc925b8959802f6f5e281 69224 debug optional dovecot-solr-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 5e0a285e4808102775dac351adee2b08 39080 mail optional dovecot-solr_2.4.1+dfsg1-6+deb13u4_i386.deb f1944ab390538b63a7bd4dd941f40b50 22392 debug optional dovecot-sqlite-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 04dd7fd598800a6d5cdcecc7cdea6572 20364 mail optional dovecot-sqlite_2.4.1+dfsg1-6+deb13u4_i386.deb 6b15c364b7252132b19e71604b8dc327 193096 debug optional dovecot-submissiond-dbgsym_2.4.1+dfsg1-6+deb13u4_i386.deb 87de64b26b24a0617dda48bbf066c9af 65720 mail optional dovecot-submissiond_2.4.1+dfsg1-6+deb13u4_i386.deb e1405681aaacb00f0893166fad484afc 17775 mail optional dovecot_2.4.1+dfsg1-6+deb13u4_i386-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEb5EwsJvHBEjqIJYIbheoBegwXLIFAmnPHj8ACgkQbheoBegw XLIyKg//arYX1yX9GsKcHiE5T3DjOszWMLmQGYMQR5VvxirLGB8snJXxvtvDGR92 FK9Ud9bvxtDvhy+MRx7hTvSkSVLBXYXMy0cqPU0cmoJlHAohEG1K6pZJwQ+/Nvs6 a9WqCAYRkuyRzNTmOViTVZc2IaSJmTD7xJXBXLcy4Um8eEsB0YzK7o96/bathTG0 7a2qIoacl2WHz9SDpcLxhxQBygzFepyqHLhaldMkTG91wa8XighCRcwnWib8uF+f OGOF2kLpcBifakjSCalCQMtL9jx08rGbwdClBH2yT4VBuuuLx7hJouYdDxPzCi1r SEgItHYtBuPlmOzfNbyuC9Mj+9tLlWUd858QWzw2MbZXY1mNYqX04DDLLapLSHv+ VkP+kKgAnOorUYVrnZ4o3yCoVp/BNiiHQHpgKviZuw0e7ziFKuYcEEvaIlDnSFUc E3kzD/IXnmHAmlnuEMHbX3ishgRGFfg2G1lRzuoTuvWUdnmeJQC+GNcLD4kBANLt PkAb0cA1qQLl2WQkaqO6ruNRPt6PBoPhjJuxuk4YnhlMFjGx4NuoWxrTiCXk3Sgt GlywnVNcOgD77g9lyQj6aTiZNqLIm4KCP3s9HafUqHXx5Nal3GZV2LDQ2vW8ZF3y k1dPTXlC71nC/MB+/YO43phEFY5AO28e9u+TRMHCkSq9+790LzE= =0s2F -----END PGP SIGNATURE-----