Home / mailingsPDF  

[SECURITY] [DSA 6526-1] dovecot security update

Posted on 28 September 2026
Debian Security Advisory

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6526-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
September 28, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : dovecot
CVE ID : CVE-2026-27852 CVE-2026-33263 CVE-2026-33604 CVE-2026-33605
CVE-2026-33606 CVE-2026-33607 CVE-2026-40013 CVE-2026-40014
CVE-2026-40015 CVE-2026-40017 CVE-2026-40018 CVE-2026-40203
CVE-2026-40204 CVE-2026-40205 CVE-2026-42007 CVE-2026-42008
CVE-2026-42391 CVE-2026-42392 CVE-2026-42393 CVE-2026-42394
CVE-2026-42395 CVE-2026-52681 CVE-2026-52687 CVE-2026-73208
CVE-2026-73209
Debian Bug : 1144639

Multiple vulnerabilities have been discovered in the Dovecot IMAP server
which could result in denial of service, SMTP smuggling, information
disclosure, code injection via malformed Sieve scripts or bypass of ACL
restrictions.

For the stable distribution (trixie), these problems have been fixed in
version 1:2.4.1+dfsg1-6+deb13u7.

We recommend that you upgrade your dovecot packages.

For the detailed security status of dovecot please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/dovecot

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

 

TOP