[CLSA-2026:1779360288] dovecot: Fix of CVE-2026-42006
Type:
security
Severity:
Low
Release date:
2026-05-21 10:44:52 UTC
Description:
- CVE-2026-42006: fix imap-login list_count_limit to actually limit open '(' characters; the previous fix limited closing ')' instead, leaving the bracing memory exhaustion vector open
Updated packages:
  • dovecot-2.3.16-5.el8.tuxcare.els3.i686.rpm
    sha:71955c56d1ad9665dbeb7e0258d4184b00bb1c890c167add1cbcdefa8cdf6987
  • dovecot-2.3.16-5.el8.tuxcare.els3.x86_64.rpm
    sha:258b0f2c029ccf627aec91ae7df8bc62935a39673f5a3b0517c399587fa488fc
  • dovecot-devel-2.3.16-5.el8.tuxcare.els3.i686.rpm
    sha:faca80d00eb36db49230e7146c3ffa4ff370b33cc68612a142b262a6aa6ba9ed
  • dovecot-devel-2.3.16-5.el8.tuxcare.els3.x86_64.rpm
    sha:2ce9c90c5ec4e829b45a9d23025a9e314c675ae1b7ce096d6b84db686ed2a632
  • dovecot-mysql-2.3.16-5.el8.tuxcare.els3.x86_64.rpm
    sha:177c431c51162545f63499a5623ed65dea7a4102d48836a9d0a6be3771a03302
  • dovecot-pgsql-2.3.16-5.el8.tuxcare.els3.x86_64.rpm
    sha:eb4d0867559fd8ae135f704c1c19c052409c0889dbb7c0fe4a374dc27cb60e34
  • dovecot-pigeonhole-2.3.16-5.el8.tuxcare.els3.x86_64.rpm
    sha:7907562fc8d5c26ebc6b5351ecb831f2e7371dfc73843912e5ebeb3733f37486
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.