Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: Dovecot 2.4.2 Moderate Auth Issue Advisory 2025:21159-1

suse
Calendar Grey December 10, 2025
Dist Suse Esm H88
SUSE security advisory for dovecot24 addresses a moderate authentication issue, providing update guidance and details.
* bsc#1252839 Cross-References: * CVE-2025-30189

Summary

## This update for dovecot24 fixes the following issues: * Update dovecot to 2.4.2: * CVE-2025-30189: Fixed users cached with same cache key when auth cache was enabled (bsc#1252839) * Changes * auth: Remove proxy_always field. * config: Change settings history parsing to use python3. * doveadm: Print table formatter - Print empty values as "-". * imapc: Propagate remote error codes properly. * lda: Default mail_home=$HOME environment if not using userdb lookup * lib-dcrypt: Salt for new version 2 keys has been increased to 16 bytes. * lib-dregex: Add libpcre2 based regular expression support to Dovecot, if the library is missing, disable all regular expressions. This adds libpcre2-32 as build dependency. * lib-oauth2: jwt - Allow nbf and iat to point 1 second into future.

References

* bsc#1252839

Cross-

* CVE-2025-30189

CVSS scores:

* CVE-2025-30189 ( SUSE ): 5.3

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

* CVE-2025-30189 ( SUSE ): 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

* CVE-2025-30189 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products:

* SUSE Linux Enterprise Server 16.0

* SUSE Linux Enterprise Server for SAP Applications 16.0

An update that solves one vulnerability can now be installed.

##

* https://www.suse.com/security/cve/CVE-2025-30189.html

* https://bugzilla.suse.com/show_bug.cgi?id=1252839

Announcement ID: SUSE-SU-2025:21159-1
Release Date: 2025-11-27T20:17:17Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here