ELSA-2026-79371

ELSA-2026-79371 - dovecot security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-10-08

Description


[1:2.3.21-19.8]
- fix CVE-2026-33605: ManageSieve: denial of service via lone CR
character causing protocol deadlock (RHEL-251984)

[1:2.3.21-19.7]
- fix CVE-2026-42007: fix use-after-free and info leak in sieve
editheader extension (RHEL-251945)

[1:2.3.21-19.6]
- fix CVE-2026-40018: incorrect escaping of multi-byte strings in SQL commands (RHEL-252058)

[1:2.3.21-19.5]
- fix CVE-2026-42391: fix excessive memory growth with pre-login ID
command (RHEL-252072)

[1:2.3.21-19.4]
- fix CVE-2026-73208: OAuth2 scope check requires all configured scopes, add oauth2_audience setting (RHEL-251900)

[1:2.3.21-19.3]
- fix CVE-2026-27852: limit parsed message data to prevent memory exhaustion (RHEL-251564)

[1:2.3.21-19.2]
- fix CVE-2026-33263: submission-login epoll panic at
mail_max_userip_connections limit (RHEL-251917)


Related CVEs


CVE-2026-27852
CVE-2026-33263
CVE-2026-33605
CVE-2026-40018
CVE-2026-40019
CVE-2026-42007
CVE-2026-42391
CVE-2026-73208

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 10 (aarch64) dovecot-2.3.21-19.el10_2.8.src.rpmc02ec47e66f06d96e3f5551842bdda0545fd8171b38740ca068251a74911fd17-ol10_aarch64_appstream
dovecot-2.3.21-19.el10_2.8.src.rpmc02ec47e66f06d96e3f5551842bdda0545fd8171b38740ca068251a74911fd17-ol10_aarch64_codeready_builder
dovecot-2.3.21-19.el10_2.8.aarch64.rpm3a839c94976c4c59d04412388296c5e6f3823b0f590ca11c214a737c8f389191-ol10_aarch64_appstream
dovecot-devel-2.3.21-19.el10_2.8.aarch64.rpm27ed9e78706500dadad68d38095f245676e0f1457e76d18214e8137edfdd1ebb-ol10_aarch64_codeready_builder
dovecot-mysql-2.3.21-19.el10_2.8.aarch64.rpme6cce25cf49fcc8ae6eafbda50ab4da2f231bc9fb78a44f892f714f23ef57801-ol10_aarch64_appstream
dovecot-pgsql-2.3.21-19.el10_2.8.aarch64.rpma0ab7b0f12efd34ce653f479fee646b668b289082bcc8e91360dcc9caf2fde19-ol10_aarch64_appstream
dovecot-pigeonhole-2.3.21-19.el10_2.8.aarch64.rpm26b1c1b9b95260b3ab7dcf7b2c16b0784f187cede5f9425a915e3db6d6795245-ol10_aarch64_appstream
Oracle Linux 10 (x86_64) dovecot-2.3.21-19.el10_2.8.src.rpmc02ec47e66f06d96e3f5551842bdda0545fd8171b38740ca068251a74911fd17-ol10_x86_64_appstream
dovecot-2.3.21-19.el10_2.8.src.rpmc02ec47e66f06d96e3f5551842bdda0545fd8171b38740ca068251a74911fd17-ol10_x86_64_codeready_builder
dovecot-2.3.21-19.el10_2.8.x86_64.rpm622bbd0459b3e5eebf842f94f6388bcbaf4fc10c40460c2ccf45356e16e3e45d-ol10_x86_64_appstream
dovecot-devel-2.3.21-19.el10_2.8.x86_64.rpm60df7b3ff0c8932616b553194bb0f67dea2a209d1d0076fd966d002cd784afe7-ol10_x86_64_codeready_builder
dovecot-mysql-2.3.21-19.el10_2.8.x86_64.rpm2a648a9866ae7e74767e0f1b3bef16d0f18241e40a29aabee701b611f24cb9bd-ol10_x86_64_appstream
dovecot-pgsql-2.3.21-19.el10_2.8.x86_64.rpm9fd74e87a748bc6d46351f8a87c1d6a60e0851285fd5228dbc511988c1623cda-ol10_x86_64_appstream
dovecot-pigeonhole-2.3.21-19.el10_2.8.x86_64.rpm2ba72741f45abad0e1b8089bd67bfb1a22034a8aaf210b44a66ddad6285612fb-ol10_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete