[CLSA-2026:1779378574] dovecot: Fix of 2 CVEs
Type:
security
Severity:
Low
Release date:
2026-05-21 15:49:38 UTC
Description:
- CVE-2026-42006: lib-imap: fix list_count_limit to actually count open '(' instead of close ')', preventing an imap-login memory-exhaustion DoS that bypassed the CVE-2026-27857 fix
Updated packages:
  • dovecot-2.0.9-23.el6.tuxcare.els5.i686.rpm
    sha:e1e7911136572321568081e6b5bd2c52c062adbb25129945c92da438eea0d666
  • dovecot-2.0.9-23.el6.tuxcare.els5.x86_64.rpm
    sha:dadde11c2fa4340eb9694309cfb5750b7968c234733875d85e0b536982e40aa7
  • dovecot-devel-2.0.9-23.el6.tuxcare.els5.i686.rpm
    sha:272f30a4076a78b2a45569a002e7fa9fe53afbba2b42d6e4eba7f5345faa4a00
  • dovecot-devel-2.0.9-23.el6.tuxcare.els5.x86_64.rpm
    sha:df69e42848edf38958978e2540a9566f3e8e46d0a86ade3366f2645dbc3deef9
  • dovecot-mysql-2.0.9-23.el6.tuxcare.els5.x86_64.rpm
    sha:d28fe81a148dfacb6ec92ea94ad457e6db7437ba284373e3102c314cbb2815e8
  • dovecot-pgsql-2.0.9-23.el6.tuxcare.els5.x86_64.rpm
    sha:5a5150cf6ed9d90ed1944d40c8027d9e4ea59b540caaccee3704d0668190e1c4
  • dovecot-pigeonhole-2.0.9-23.el6.tuxcare.els5.x86_64.rpm
    sha:b9b4a33ce5a21a340aa5af9c2e73107b87ac745d6443413040ae22e6b053687f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.