Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Ubuntu 22 24 Dovecot Critical Regression Fix USN-8136-2

ubuntu
Calendar Grey April 28, 2026
Dist Ubuntu Esm H88
A regression for Dovecot affecting Ubuntu 22.04 and 24.04 addresses critical issues to enhance server security.
USN-8136-1 introduced a regression in Dovecot

Summary

USN-8136-1 introduced a regression in Dovecot

Software Description:

- dovecot: IMAP and POP3 email server

Details:

USN-8136-1 fixed vulnerabilities in Dovecot. The update caused a regression

on Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that Dovecot incorrectly handled invalid base64 SASL data.

An attacker could possibly use this issue to cause a denial of service. This

issue only affected Ubuntu 25.10. (CVE-2025-59028)

It was discovered that Dovecot script decode2text.sh incorrectly handled zip

files. An attacker could possibly use this issue to obtain sensitive

information. (CVE-2025-59031)

It was discovered that Dovecot incorrectly handled certain AUTHENTICATE

requests. An attacker could possibly use this issue to cause a denial of

service. (CVE-2025-59032)

It was discovered that Dovecot incorrectly handled certain SQL based

authentication. An attacker ...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
  dovecot-core                    1:2.3.21+dfsg1-2ubuntu6.4

Ubuntu 22.04 LTS
  dovecot-core                    1:2.3.16+dfsg1-3ubuntu2.8

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8136-2

https://ubuntu.com/security/notices/USN-8136-1

CVE-2026-0394, https://launchpad.net/bugs/2150116

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8136-2

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here