-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 18 May 2026 14:11:58 -0400 Source: dovecot Binary: dovecot-auth-lua dovecot-auth-lua-dbgsym dovecot-core dovecot-core-dbgsym dovecot-dev dovecot-gssapi dovecot-gssapi-dbgsym dovecot-imapd dovecot-imapd-dbgsym dovecot-ldap dovecot-ldap-dbgsym dovecot-lmtpd dovecot-lmtpd-dbgsym dovecot-lucene dovecot-lucene-dbgsym dovecot-managesieved dovecot-managesieved-dbgsym dovecot-mysql dovecot-mysql-dbgsym dovecot-pgsql dovecot-pgsql-dbgsym dovecot-pop3d dovecot-pop3d-dbgsym dovecot-sieve dovecot-sieve-dbgsym dovecot-solr dovecot-solr-dbgsym dovecot-sqlite dovecot-sqlite-dbgsym dovecot-submissiond dovecot-submissiond-dbgsym Architecture: armhf Version: 1:2.3.19.1+dfsg1-2.1+deb12u6 Distribution: bookworm-security Urgency: medium Maintainer: armhf Build Daemon (arm-ubc-05) Changed-By: Noah Meyerhans Description: dovecot-auth-lua - secure POP3/IMAP server - Lua authentication plugin dovecot-core - secure POP3/IMAP server - core files dovecot-dev - secure POP3/IMAP server - header files dovecot-gssapi - secure POP3/IMAP server - GSSAPI support dovecot-imapd - secure POP3/IMAP server - IMAP daemon dovecot-ldap - secure POP3/IMAP server - LDAP support dovecot-lmtpd - secure POP3/IMAP server - LMTP server dovecot-lucene - secure POP3/IMAP server - Lucene support dovecot-managesieved - secure POP3/IMAP server - ManageSieve server dovecot-mysql - secure POP3/IMAP server - MySQL support dovecot-pgsql - secure POP3/IMAP server - PostgreSQL support dovecot-pop3d - secure POP3/IMAP server - POP3 daemon dovecot-sieve - secure POP3/IMAP server - Sieve filters support dovecot-solr - secure POP3/IMAP server - Solr support dovecot-sqlite - secure POP3/IMAP server - SQLite support dovecot-submissiond - secure POP3/IMAP server - mail submission agent Closes: 1136444 Changes: dovecot (1:2.3.19.1+dfsg1-2.1+deb12u6) bookworm-security; urgency=medium . * Security update (Closes: #1136444) * [1d0162a] autopkgtest: test cram-md5 authentication * [d4eed2a] CVE-2026-40016: Sieve :contains/:matches O(N×M) Substring Match Bypasses sieve_max_cpu_time Limit (130× Overrun) * [898776c] CVE-2026-33603: login: Base64 input can contain tabs that bypass IPC protection * [fe76a7b] CVE-2026-40020: IMAP folders can be shared-spammed to everyone * [ce379ba] CVE-2026-42006: imap-login: Excessive memory usage DoS Checksums-Sha1: f90cc53aabf8272390dca6490f2dede7d671a608 32408 dovecot-auth-lua-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb b642807e26fc5e6c18beea805e7e04270334d806 1366072 dovecot-auth-lua_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 68676d205e6183cc7b58f9ad5f32da9b8fab79c5 9370408 dovecot-core-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 4e820fe87c61dc4e121e7d7cf20d7b33614498ca 4193384 dovecot-core_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb c6dc84c98270ba47590b69ca86616418a2042999 1744124 dovecot-dev_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 66456c0ad29e38a19604cfd6350bef6382f93910 21944 dovecot-gssapi-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 5faa60923a80eaccf02a00198d203dca9a98b3d9 1362784 dovecot-gssapi_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb d44b5cf1fd536815e9d105c60fc87f484a9aa70e 673024 dovecot-imapd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 04c5399cfaf82d71c930c1f739706b41276baa1f 1509292 dovecot-imapd_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb bda730620502aec95060478bb42c9fb84d3a3049 116744 dovecot-ldap-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb ca0284aa5983a4cfbcba0db4f8d58f845723f0d3 1389712 dovecot-ldap_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb c895a441ac8c3d367410b93dc74412ebfb588706 91864 dovecot-lmtpd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 8e19943ba62ba25b5ceb32cc419c0bbbd78a6e6b 1376768 dovecot-lmtpd_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 1483edff0cec874c63b61f93490f318a2e65909b 149200 dovecot-lucene-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 6ca346584dcd89d0d0d0354e4320309f1d2e8525 1378440 dovecot-lucene_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 94960b56fff94d527a2abcb154d247b87e556847 146284 dovecot-managesieved-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 6b994c2a71edce0b5ef67908a2a6ebad28e22f5a 1395360 dovecot-managesieved_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 06b47c50bc416ddff6b2ad94a60671778749e4d7 31732 dovecot-mysql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 35decf7d2904250959fcce389635156b33bba953 1364048 dovecot-mysql_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb b17b81acbd0821b3773b2d6d96c2d3bae5bbd736 33496 dovecot-pgsql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb bc699ae8e73d2feb62e0793045b18ed684a8dfb3 1367056 dovecot-pgsql_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 8f3f7bb269179789a28aeaad7213d2b8e56d17d2 90720 dovecot-pop3d-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb a75e9a3b1c6a9c02a20fc65a00755e927865c04c 1383884 dovecot-pop3d_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 159beeb0d9bebcf240e00e88c1206c7fd9249727 1505868 dovecot-sieve-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 26fbc03961fd04d867df5e2331ecee5320891dc5 1658632 dovecot-sieve_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb a86a2c6383be7f90e3d96c2668d36ddd664c8174 86364 dovecot-solr-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 7ed0bc88c11dc79c0f90374f33a895e86ae896ee 1373716 dovecot-solr_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb aca9bc2c1d2b9ca459f058e8cf0d7e22ab6ff9f7 18456 dovecot-sqlite-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb d55ed88d4d5947e61385b0399ed97b82725ce50a 1362332 dovecot-sqlite_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 7664365f9f0dc900d0ae93864aad99b55a291538 177416 dovecot-submissiond-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb f71929b76e7d661bfffc8186f3f926f88b3b9bc6 1397600 dovecot-submissiond_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 9c172ba0521650d5fb5419f70c8a861356a1f670 18704 dovecot_2.3.19.1+dfsg1-2.1+deb12u6_armhf-buildd.buildinfo Checksums-Sha256: 24b0a9bae08ca6821cc8d95b39d2595eb5436f52d52722402d970c45a7c0ccde 32408 dovecot-auth-lua-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb fa7625a180a5e818ed63abaf9161018404963949443a9b58671dfaa0f37f055b 1366072 dovecot-auth-lua_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 29b3b1a7d2c0c685440c195322d8c3117e933c0e0c20f815f74742c62914a90f 9370408 dovecot-core-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 6d33331869c73801a1d963b26e004d9740ea2d2a8c3ab7eb837d53f1d4ff9b65 4193384 dovecot-core_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 0533be8e3fb7a76c514d4290fbf22b72b7b8cd560f946b84d831e84251b9e912 1744124 dovecot-dev_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 71034201aab372bac5ff8426bf6975d61cd32184fc10fedc20fc9e215f820e2a 21944 dovecot-gssapi-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 0ca5027b40eb7513b0623c5aef4b964cc1aa1e9b2cde24a7331b53de70e7c53d 1362784 dovecot-gssapi_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 1fe2d9a918dcac799660686733774acb6f8c2327455f83d2b51aee2e58b67c05 673024 dovecot-imapd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 801ff7626d2e097e9a850efcb9ade7b60ba9799d0ac59cf6a197e3b4a26435c3 1509292 dovecot-imapd_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 443b5c2e51131457327d04a7c3a767640be946e75e2a228361091e514962a48f 116744 dovecot-ldap-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 5a91ab31bbfec2d2d98be983623efce95de82d8d3d2aff22da8accc096afc26a 1389712 dovecot-ldap_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 86ae5b4acb4b88acda775fb55c86d978fe88e121c4ac9156df44be59285e7900 91864 dovecot-lmtpd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 98ab045d05a1b0ca15cf84b96e068cd71edf94a7ba3ce49be132a64e74ed44df 1376768 dovecot-lmtpd_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb a5ca7a4dc068fb24aa79985f4ab8671f4910cb19df69aff7617ba731114b1ccd 149200 dovecot-lucene-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 4b1fcdb73e2bab10b66e0b8acdb711595e42b674818551daedba01e3490de766 1378440 dovecot-lucene_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb db99d59e7cc943fd0fed827756f5dfbe6d9d6e0bcb95e6dfc3e0ca8b4a9f3fb6 146284 dovecot-managesieved-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 926a3205a427487b2b0468c6c383cf1968d05035ee6ae1b8c755e623f5cb508b 1395360 dovecot-managesieved_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 9706f0a5d56738850d15239505d15d6b0893e2d4a514e5b3388dfb860a047535 31732 dovecot-mysql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb cd89e17b876771bc5f13223fbc1d43561171f94e3fdcbac44f426ce7c10d9a6b 1364048 dovecot-mysql_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 27e12f038036dd76710d7e07a4cadd6d6e4b6a01fcee972c88af720e44195a29 33496 dovecot-pgsql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb b8685fa86d552ee04bfe0bc85c08db6a447086063119d02f170267116c507389 1367056 dovecot-pgsql_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 9bc7fffba4e007f8d327736fa4b7fc0e00f939c5cb2943e2536a45c63941dd6c 90720 dovecot-pop3d-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb b93b80b18545c20603548c1d789e44726c1bfb153877e10f0e1015d0be368a29 1383884 dovecot-pop3d_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 5ba40c133d280f265d34a04a78be09dcd7f0ade60882ef2b7bf3567539f8107e 1505868 dovecot-sieve-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb a9f5d27c7b9e66debe3834fcd77373dca7f0fcc096a1a9e2f3e046f7cf802151 1658632 dovecot-sieve_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 8d62f07047484f8cfb03bbc7fbe3ec3cbd2cd168b4ea5b0ea8dfa259ea8f1aaa 86364 dovecot-solr-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 8e48b2457bab95499c27a0c05e4490eed04a0b17a8abfc2406be46ddd7f91ba7 1373716 dovecot-solr_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 613bb4d58979a478b94dc81dfd81dd525197b5ee673eaf6853d91258cba72e0e 18456 dovecot-sqlite-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 7d4aee61f8e9d823522f87e06667c0a589ad853e3e42f726af747425b8794a68 1362332 dovecot-sqlite_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 374020c54bb6450ab678482ada73ca7be6c3043512161fdd2802fe0c9a7d6833 177416 dovecot-submissiond-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 88853c14f8131990daf1d0985789832e1d14881cbaf3119fddd8119a5455dc8c 1397600 dovecot-submissiond_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 8c1ab3a506fa2c43970770a2e4a0703f254328ac5a1a48f1637eca12a0626a44 18704 dovecot_2.3.19.1+dfsg1-2.1+deb12u6_armhf-buildd.buildinfo Files: ba8c2f318f8cd332ac2532e46bb8157d 32408 debug optional dovecot-auth-lua-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb d348eb87ff226b18684d40bc6ef39ede 1366072 mail optional dovecot-auth-lua_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 0bef638f7757771dc87c56b7868cf720 9370408 debug optional dovecot-core-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb e5c6d8ec182eb4f69c16cf092e036df7 4193384 mail optional dovecot-core_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 823ed38fc4e1dc0bf2f1f6bf246efb3b 1744124 mail optional dovecot-dev_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 9ff38b73f1a3fc82dbf49bc8c3c18be7 21944 debug optional dovecot-gssapi-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 8d77ff56c0bd7771220e4d903e270fd6 1362784 mail optional dovecot-gssapi_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 7a202480042f3be2859f3c9741685cd3 673024 debug optional dovecot-imapd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 7fa735b784425599a1ba5cd834bf292d 1509292 mail optional dovecot-imapd_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 56417f7218ef4fd21c4e7381bc2357f0 116744 debug optional dovecot-ldap-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 1a9ee1fe46ecfe54b61203c76130c8b7 1389712 mail optional dovecot-ldap_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 8ffb546795b9b53d695b6041a1d92aa2 91864 debug optional dovecot-lmtpd-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 49b17f6474a071be13ebd158f7c1877d 1376768 mail optional dovecot-lmtpd_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 669bb4b768ebd8233d67c4fb601c4f9b 149200 debug optional dovecot-lucene-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 483e90c39adca9cc8ee744c53740b4a1 1378440 mail optional dovecot-lucene_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 9544fa741b49974c4defaf5c098c6138 146284 debug optional dovecot-managesieved-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb e1f0f7831d825217c1bc984d8c0df043 1395360 mail optional dovecot-managesieved_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb e89ace7ae7fdfa4696acccc8202d631b 31732 debug optional dovecot-mysql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 9005b378222ee5dd2a3bd280233e2330 1364048 mail optional dovecot-mysql_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 932054bde97646a21bf867379a01e66c 33496 debug optional dovecot-pgsql-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 3bb3fd21814e88e63154ba4917ac5d81 1367056 mail optional dovecot-pgsql_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 4d56709cddcf21a43399de7b54410a6a 90720 debug optional dovecot-pop3d-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 66171fb1350c9b3e35523f5deba2fd83 1383884 mail optional dovecot-pop3d_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 5ce689758e30533dfa8da72a6348b909 1505868 debug optional dovecot-sieve-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb e501075b6939a6365076dbd68363550a 1658632 mail optional dovecot-sieve_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 8b56431b767d0cf3b4552631673e165e 86364 debug optional dovecot-solr-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 11ab30baca37e6d87d0797e93fd04635 1373716 mail optional dovecot-solr_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 6711468c0dacdcd7e5f7b1ac4e3ea7e4 18456 debug optional dovecot-sqlite-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 3a4d16faaa7582914413f5df4c4c6ac8 1362332 mail optional dovecot-sqlite_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 32b9bab97eb9b0b3b42e15e55c6ea8e3 177416 debug optional dovecot-submissiond-dbgsym_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb a0bef70f3de4dd4ac22bd1686fc7e778 1397600 mail optional dovecot-submissiond_2.3.19.1+dfsg1-2.1+deb12u6_armhf.deb 5c39758c16fc2462e6cbb480e2175592 18704 mail optional dovecot_2.3.19.1+dfsg1-2.1+deb12u6_armhf-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7rv+l3KtZdQea77lnwznazfjXToFAmoZ7wcACgkQnwznazfj XTrK0xAAuhMcNj0oZec9AYRpIffJhZz8Yt8aJRoNLC57RvpDjmnqxLAe59nlgGBU EiEyMaJPhBfITVPVj5uSWd0i1XPKJ+zWW5+yaD7o1MgLziudjiza9TNXGLxwFaHv lRYS+ZN4CPUuhG324YcnHpFaPWlwD4G1JAIWt5LnS3o5z3HDg7POMJ2DQlJvAHeT Spn6s3Q2QWJ3tEZxDgTx7C8PjaBwngXf3TfwrzdrLK8b6w9Aofto2wUL0UWhULJj QMrwH+sOsCo2G1I8r9JXyuGv69EaIeOdkDrxby+x+KUizIyH1W2+pS9lJlf78pSu Ff94qFYNzRTX3S05m1waqz3m7MPTJRPJ9yudo34Mb/lokAJ7RwNvhbdOOd2Rm24v ylIcCFSAeQ+asnZagAYUY/NZJIUPEl4RT+uY8YrO4e7WoQQi2t6wF4znVk+DDfIq BT/GVZKf2I01/QP9oiG0/rAjJoRT19pFCqDhHTf0Y1+l1YTmpTNTl+dr2vJQH4Zy 0y3YUm0Ov+i9DaESmqzNjmnuJEjWTcQL4NWNL9dUpXoFe0ZYuF4XtliEXedSbrBw A9Wg0GbLRbsSe6C6RCRQ4q8ncKTOiTanbsc/HF0qR1I2Vt3yQCnPScs2IDnnmlko Wwc+iUgGJDIA1KTbzxeU6kmjz2SihuBwgCzYdtn+1RF7Uf38JWQ= =LrgF -----END PGP SIGNATURE-----