An update that solves 5 vulnerabilities can now be installed.. # dovecot24-2.4.4-1.1 on GA media Announcement ID: openSUSE-SU-2026:10766-1 Rating: moderate Cross-References: * CVE-2026-27851 * CVE-2026-33603 * CVE-2026-40016 * CVE-2026-40020 * CVE-2026-42006 CVSS scores: * CVE-2026-27851 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-27851 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33603 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33603 ( SUSE ): 7.6 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-40016 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40016 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40020 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40020 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42006 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42006 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 5 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the dovecot24-2.4.4-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * dovecot24 2.4.4-1.1 * dovecot24-backend-mysql 2.4.4-1.1 * dovecot24-backend-pgsql 2.4.4-1.1 * dovecot24-backend-sqlite 2.4.4-1.1 * dovecot24-devel 2.4.4-1.1 * dovecot24-fts 2.4.4-1.1 * dovecot24-fts-flatcurve 2.4.4-1.1 * dovecot24-fts-solr 2.4.4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27851.html * https://www.suse.com/security/cve/CVE-2026-33603.html * https://www.suse.com/security/cve/CVE-2026-40016.html * https://www.suse.com/security/cve/CVE-2026-40020.html * https://www.suse.com/security/cve/CVE-2026-42006.html . Animportant update for openSUSE Tumbleweed to address multiple moderate issues in the dovecot24 email server package.. openSUSE Update, dovecot24, moderate issues, email server, security advisory. . LinuxSecurity.com Team
An update that solves 10 vulnerabilities and has 10 bug fixes can now be installed.. openSUSE security update: security update for dovecot24 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20554-1 Rating: important References: * bsc#1260893 * bsc#1260894 * bsc#1260895 * bsc#1260896 * bsc#1260897 * bsc#1260898 * bsc#1260899 * bsc#1260900 * bsc#1260901 * bsc#1260902 Cross-References: * CVE-2025-59028 * CVE-2025-59031 * CVE-2025-59032 * CVE-2026-24031 * CVE-2026-27855 * CVE-2026-27856 * CVE-2026-27857 * CVE-2026-27858 * CVE-2026-27859 * CVE-2026-27860 CVSS scores: * CVE-2025-59028 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-59031 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2025-59031 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-59032 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59032 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-24031 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L * CVE-2026-24031 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-27855 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-27855 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-27856 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-27856 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-27857 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-27857 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27858 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27858 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27859 ( SUSE ): 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-27859 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27860 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27860 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 10 vulnerabilities and has 10 bug fixes can now be installed. Description: This update for dovecot24 fixes the following issues: - Update to v2.4.3 - CVE-2025-59028: Invalid base64 authentication can cause DoS for other logins (bsc#1260894). - CVE-2025-59031: decode2text.sh OOXML extraction may follow symlinks and read unintended files during indexing (bsc#1260895). - CVE-2025-59032: pigeonhole: ManageSieve panic occurs with sieve-connect as a client (bsc#1260902). - CVE-2026-24031: SQL injection possible if auth_username_chars is configured empty. Fixed escaping to always happen. v2.4 regression (bsc#1260896). - CVE-2026-27855: OTP driver vulnerable to replay attack (bsc#1260900). - CVE-2026-27856: Doveadm credentials were not checked using timing-safe checking function (bsc#1260899). - CVE-2026-27857: sending excessive parenthesis causes imap-login to use excessive memory (bsc#1260898). - CVE-2026-27858: pigeonhole: managesieve-login can allocate large amount of memory during authentication (bsc#1260901). - CVE-2026-27859: excessive RFC 2231 MIME parameters in email would can excessive CPU usage (bsc#1260897). - CVE-2026-27860: LDAP query injection possible if auth_username_chars is configured empty. Fixed escaping to always happen. v2.4 regression (bsc#1260893). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patchopenSUSE-Leap-16.0-577=1 Package List: - openSUSE Leap 16.0: dovecot24-2.4.3-160000.1.1 dovecot24-backend-mysql-2.4.3-160000.1.1 dovecot24-backend-pgsql-2.4.3-160000.1.1 dovecot24-backend-sqlite-2.4.3-160000.1.1 dovecot24-devel-2.4.3-160000.1.1 dovecot24-fts-2.4.3-160000.1.1 dovecot24-fts-flatcurve-2.4.3-160000.1.1 dovecot24-fts-solr-2.4.3-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2025-59028.html * https://www.suse.com/security/cve/CVE-2025-59031.html * https://www.suse.com/security/cve/CVE-2025-59032.html * https://www.suse.com/security/cve/CVE-2026-24031.html * https://www.suse.com/security/cve/CVE-2026-27855.html * https://www.suse.com/security/cve/CVE-2026-27856.html * https://www.suse.com/security/cve/CVE-2026-27857.html * https://www.suse.com/security/cve/CVE-2026-27858.html * https://www.suse.com/security/cve/CVE-2026-27859.html * https://www.suse.com/security/cve/CVE-2026-27860.html . This article highlights the important security updates for Dovecot 24 on openSUSE addressing major vulnerabilities.. Dovecot24 Security Update, openSUSE Vulnerability Fix, Important Dovecot Fixes. . Severity: Important. LinuxSecurity.com Team
An update that solves 10 vulnerabilities can now be installed.. # Security update for dovecot24 Announcement ID: SUSE-SU-2026:21208-1 Release Date: 2026-04-16T13:10:27Z Rating: important References: * bsc#1260893 * bsc#1260894 * bsc#1260895 * bsc#1260896 * bsc#1260897 * bsc#1260898 * bsc#1260899 * bsc#1260900 * bsc#1260901 * bsc#1260902 Cross-References: * CVE-2025-59028 * CVE-2025-59031 * CVE-2025-59032 * CVE-2026-24031 * CVE-2026-27855 * CVE-2026-27856 * CVE-2026-27857 * CVE-2026-27858 * CVE-2026-27859 * CVE-2026-27860 CVSS scores: * CVE-2025-59028 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-59028 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-59031 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-59031 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2025-59031 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2025-59032 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-59032 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59032 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-24031 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-24031 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L * CVE-2026-24031 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L * CVE-2026-27855 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-27855 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-27855 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-27856 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-27856 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-27856 ( NVD ): 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-27857 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27857 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-27857 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-27858 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27858 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27858 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27859 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27859 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-27859 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-27860 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-27860 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27860 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for dovecot24 fixes the following issues: * Update to v2.4.3 * CVE-2025-59028: Invalid base64 authentication can cause DoS for other logins (bsc#1260894). * CVE-2025-59031: decode2text.sh OOXML extraction may follow symlinks and read unintended files during indexing (bsc#1260895). * CVE-2025-59032: pigeonhole: ManageSieve panic occurs with sieve-connect as a client (bsc#1260902). * CVE-2026-24031: SQL injection possible if auth_username_chars is configured empty. Fixed escaping to always happen. v2.4 regression (bsc#1260896). * CVE-2026-27855: OTP driver vulnerable to replay attack (bsc#1260900). * CVE-2026-27856: Doveadm credentials were not checked using timing-safe checking function (bsc#1260899). * CVE-2026-27857: sending excessive parenthesis causes imap-login to use excessive memory (bsc#1260898). * CVE-2026-27858: pigeonhole: managesieve-login can allocate large amount of memory during authentication (bsc#1260901). * CVE-2026-27859: excessive RFC 2231 MIME parameters in email would can excessive CPU usage (bsc#1260897). * CVE-2026-27860: LDAP query injection possible if auth_username_chars is configured empty. Fixed escaping to always happen. v2.4 regression (bsc#1260893). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-577=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-577=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * dovecot24-fts-solr-2.4.3-160000.1.1 * dovecot24-fts-solr-debuginfo-2.4.3-160000.1.1 * dovecot24-debugsource-2.4.3-160000.1.1 * dovecot24-backend-mysql-debuginfo-2.4.3-160000.1.1 * dovecot24-backend-pgsql-debuginfo-2.4.3-160000.1.1 * dovecot24-backend-sqlite-debuginfo-2.4.3-160000.1.1 * dovecot24-devel-2.4.3-160000.1.1 * dovecot24-fts-debuginfo-2.4.3-160000.1.1 * dovecot24-backend-pgsql-2.4.3-160000.1.1 * dovecot24-debuginfo-2.4.3-160000.1.1 * dovecot24-fts-2.4.3-160000.1.1 * dovecot24-2.4.3-160000.1.1 * dovecot24-backend-mysql-2.4.3-160000.1.1 * dovecot24-backend-sqlite-2.4.3-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dovecot24-fts-solr-2.4.3-160000.1.1 * dovecot24-fts-solr-debuginfo-2.4.3-160000.1.1 * dovecot24-debugsource-2.4.3-160000.1.1 * dovecot24-backend-mysql-debuginfo-2.4.3-160000.1.1 * dovecot24-backend-pgsql-debuginfo-2.4.3-160000.1.1 * dovecot24-backend-sqlite-debuginfo-2.4.3-160000.1.1 *dovecot24-devel-2.4.3-160000.1.1 * dovecot24-fts-debuginfo-2.4.3-160000.1.1 * dovecot24-backend-pgsql-2.4.3-160000.1.1 * dovecot24-debuginfo-2.4.3-160000.1.1 * dovecot24-fts-2.4.3-160000.1.1 * dovecot24-2.4.3-160000.1.1 * dovecot24-backend-mysql-2.4.3-160000.1.1 * dovecot24-backend-sqlite-2.4.3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-59028.html * https://www.suse.com/security/cve/CVE-2025-59031.html * https://www.suse.com/security/cve/CVE-2025-59032.html * https://www.suse.com/security/cve/CVE-2026-24031.html * https://www.suse.com/security/cve/CVE-2026-27855.html * https://www.suse.com/security/cve/CVE-2026-27856.html * https://www.suse.com/security/cve/CVE-2026-27857.html * https://www.suse.com/security/cve/CVE-2026-27858.html * https://www.suse.com/security/cve/CVE-2026-27859.html * https://www.suse.com/security/cve/CVE-2026-27860.html * https://bugzilla.suse.com/show_bug.cgi?id=1260893 * https://bugzilla.suse.com/show_bug.cgi?id=1260894 * https://bugzilla.suse.com/show_bug.cgi?id=1260895 * https://bugzilla.suse.com/show_bug.cgi?id=1260896 * https://bugzilla.suse.com/show_bug.cgi?id=1260897 * https://bugzilla.suse.com/show_bug.cgi?id=1260898 * https://bugzilla.suse.com/show_bug.cgi?id=1260899 * https://bugzilla.suse.com/show_bug.cgi?id=1260900 * https://bugzilla.suse.com/show_bug.cgi?id=1260901 * https://bugzilla.suse.com/show_bug.cgi?id=1260902 . SUSE Dovecot24 security update addresses 10 issues, includes important fixes for authentication and SQL attacks.. Dovecot24 Security, SUSE Important Update, Authentication Issues, SQL Injection Fixes. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for dovecot24 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2025-20113-1 Rating: moderate References: * bsc#1252839 Cross-References: * CVE-2025-30189 CVSS scores: * CVE-2025-30189 ( SUSE ): 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N * CVE-2025-30189 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for dovecot24 fixes the following issues: - Update dovecot to 2.4.2: - CVE-2025-30189: Fixed users cached with same cache key when auth cache was enabled (bsc#1252839) - Changes - auth: Remove proxy_always field. - config: Change settings history parsing to use python3. - doveadm: Print table formatter - Print empty values as "-". - imapc: Propagate remote error codes properly. - lda: Default mail_home=$HOME environment if not using userdb lookup - lib-dcrypt: Salt for new version 2 keys has been increased to 16 bytes. - lib-dregex: Add libpcre2 based regular expression support to Dovecot, if the library is missing, disable all regular expressions. This adds libpcre2-32 as build dependency. - lib-oauth2: jwt - Allow nbf and iat to point 1 second into future. - lib: Replace libicu with our own unicode library. Removes libicu as build dependency. - login-common: If proxying fails due to remote having invalid SSL cert, don't reconnect. - New features - auth: Add ssl_client_cert_fp and ssl_client_cert_pubkey_fp fields - config: Add support for $SET:filter/path/setting. - config: Improve @group includes to work with overwriting their settings. - doveadm kick: Addsupport for kicking multiple usernames - doveadm mailbox status: Add support for deleted status item. - imap, imap-client: Add experimental partial IMAP4rev2 support. - imap: Implement support for UTF8=ACCEPT for APPEND - lib-oauth2, oauth2: Add oauth2_token_expire_grace setting. - lmtp: lmtp-client - Support command pipelining. - login-common: Support local/remote blocks better. - master: accept() unix/inet connections before creating child process to handle it. This reduces timeouts when child processes are slow to spawn themselves. - Bug fixes - SMTPUTF8 was accepted even when it wasn't enabled. - auth, *-login: Direct logging with -L parameter was not working. - auth: Crash occured when OAUTH token validation failed with oauth2_use_worker_with_mech=yes. - auth: Invalid field handling crashes were fixed. - auth: ldap - Potential crash could happen at deinit. - auth: mech-gssapi - Server sending empty initial response would cause errors. - auth: mech-winbind - GSS-SPNEGO mechanism was erroneously marked as - not accepting NUL. - config: Multiple issues with $SET handling has been fixed. - configure: Building without LDAP didn't work. - doveadm: If source user didn't exist, a crash would occur. - imap, pop3, submission, imap-urlauth: USER environment usage was broken when running standalone. - imap-hibernate: Statistics would get truncated on unhibernation. - imap: "SEARCH MIMEPART FILENAME ENDS" command could have accessed memory outside allocated buffer, resulting in a crash. - imapc: Fetching partial headers would cause other cached headers to be cached empty, breaking e.g. imap envelope responses when caching to disk. - imapc: Shared namespace's INBOX mailbox was not always uppercased. - imapc: imapc_features=guid-forced GUID generation was not working correctly. - lda: USER environment was not accepted if -d hasn'tbeen specified. - lib-http: http-url - Significant path percent encoding through parse and create was not preserved. This is mainly important for Dovecot's Lua bindings for lib-http. - lib-settings: Crash would occur when using %variables in SET_FILE type settings. - lib-storage: Attachment flags were attempted to be added for readonly mailboxes with mail_attachment_flags=add-flags. - lib-storage: Root directory for unusable shared namespaces was unnecessarily attempted to be created. - lib: Crash would occur when config was reloaded and logging to syslog. - login-common: Crash might have occured when login proxy was destroyed. - sqlite: The sqlite_journal_mode=wal setting didn't actually do anything. - Many other bugs have been fixed. - Update pigeonhole to 2.4.2 - Changes - lib-sieve: Use new regular expression library in core. - managesieve: Add default service_extra_groups=$SET:default_internal_group. - New features - lib-sieve: Add support for "extlists" extension. - lib-sieve: regex - Allow unicode comparator. - Bug fixes - lib-sieve-tool: sieve-tool - All sieve_script settings were overriden. - lib-sieve: storage: dict: sieve_script_dict filter was missing from settings. - sieve-ldap-storage: Fix compile without LDAP. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-79=1 Package List: - openSUSE Leap 16.0: dovecot24-2.4.2-160000.1.1 dovecot24-backend-mysql-2.4.2-160000.1.1 dovecot24-backend-pgsql-2.4.2-160000.1.1 dovecot24-backend-sqlite-2.4.2-160000.1.1 dovecot24-devel-2.4.2-160000.1.1 dovecot24-fts-2.4.2-160000.1.1 dovecot24-fts-flatcurve-2.4.2-160000.1.1 dovecot24-fts-solr-2.4.2-160000.1.1 References: *https://www.suse.com/security/cve/CVE-2025-30189.html . An important security update for openSUSE to fix a cache issue in dovecot24 with moderate severity rating.. openSUSE dovecot24 update security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.