ELBA-2026-65602

ELBA-2026-65602 - neomutt Bug Fix update

Type:BUG
Impact:NA
Release Date:2026-05-14

Description


[20260504-1]
- Security
- Fix GSSAPI buffer underflow on short unwrapped tokens
- Reject percent-encoded NUL bytes in URL decoding
- Skip CN fallback when SAN dNSName entries exist (RFC6125)
- Cap POP3 UIDL responses to prevent OOM from a malicious server
- Harden POP host URL copy
- Bug Fixes
- #4836 imap: fix memory leak in msg_parse_flags
- #4849 Fix memmove in mutt_str_expand_tabs
- #4850 IMAP: enhance stability with re-entrancy protection and reconnection fixes
- #4852 Say which mailcap field we are looking for
- #4853 Don't overwrite content_type
- pager: fix crash on uncolor *
- pager: fix wrong line index in signature syntax realloc
- pager: fix OOB read on short log lines in display_line()
- pager: fix off-by-one in newline restoration
- imap: fix sort for missing emails
- imap: fix crash when syncing mailbox on exit
- Fix crash in cmd_parse_fetch() when edata is NULL
- log: fix missing errors on startup
- Force cursor to be visible on exit




Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (x86_64) neomutt-20260504-1.el9.src.rpm9179fe2ad738f22222eb33de8eb549af677ba88b60cedee916dedaf91c140173-ol9_x86_64_developer_EPEL
neomutt-20260504-1.el9.x86_64.rpmf3e1166e3217d1d92f1db00c4074b77b843c54750976a05bcfe3a1fd7586dd26-ol9_x86_64_developer_EPEL



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete