## This update for dovecot24 fixes the following issues * CVE-2026-27851: lib-var-expand: safe filter leaks to all following pipelines (bsc#1265146). * CVE-2026-33603: login: base64 input can contain tabs that bypass IPC protection (bsc#1265147). * CVE-2026-40016: Sieve: contains/: matches O(NxM) substring match bypasses sieve_max_cpu_time limit (bsc#1265148). * CVE-2026-40020: IMAP folders can be shared-spammed to everyone (bsc#1265149). * CVE-2026-42006: imap-login: uncontrolled memory usage with excessive bracing over IMAP (bsc#1265150). Changes for dovecot24: * Update to 2.4.4 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:
* bsc#1265146
* bsc#1265147
* bsc#1265148
* bsc#1265149
* bsc#1265150
Cross-
* CVE-2026-27851
* CVE-2026-33603
* CVE-2026-40016
* CVE-2026-40020
* CVE-2026-42006
CVSS scores:
* CVE-2026-27851 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-27851 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-27851 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-27851 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-33603 ( SUSE ): 7.6
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-33603 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-33603 ( NVD ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Get the latest Linux and open source security news straight to your inbox.