==========================================================================
Ubuntu Security Notice USN-8136-2
April 28, 2026

dovecot regression
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

USN-8136-1 introduced a regression in Dovecot

Software Description:
- dovecot: IMAP and POP3 email server

Details:

USN-8136-1 fixed vulnerabilities in Dovecot. The update caused a regression
on Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

 It was discovered that Dovecot incorrectly handled invalid base64 SASL data.
 An attacker could possibly use this issue to cause a denial of service. This
 issue only affected Ubuntu 25.10. (CVE-2025-59028)

 It was discovered that Dovecot script decode2text.sh incorrectly handled zip
 files. An attacker could possibly use this issue to obtain sensitive
 information. (CVE-2025-59031)

 It was discovered that Dovecot incorrectly handled certain AUTHENTICATE
 requests. An attacker could possibly use this issue to cause a denial of
 service. (CVE-2025-59032)

 It was discovered that Dovecot incorrectly handled certain SQL based
 authentication. An attacker could possibly use this issue to bypass
 authentication. This issue only affected Ubuntu 25.10. (CVE-2026-24031)

 It was discovered that Dovecot incorrectly handled certain LDAP based
 authentication. An attacker could possibly use this issue to bypass
 restrictions and allow probing of LDAP structure. This issue only affected
 Ubuntu 25.10. (CVE-2026-27860)

 It was discovered that Dovecot is vulnerable to replay attack under
 certain conditions. An attacker could possibly use this issue to bypass
 authentication. (CVE-2026-27855)

 It was discovered that Dovecot is vulnerable to a timing attack under
 certain conditions. An attacker could possibly use this issue to bypass
 authentication. (CVE-2026-27856)

 It was discovered that Dovecot incorrectly handled certain IMAP login
 requests. An attacker could possibly use this issue to cause a denial of
 service. (CVE-2026-27857)

 It was discovered that Dovecot incorrectly handled certain specially
 crafted messages. An attacker could possibly use this issue to cause a
 denial of service. (CVE-2026-27858)

 It was discovered that Dovecot incorrectly handled certain specially
 crafted mail messages. An attacker could possibly use this issue to
 cause a denial of service. (CVE-2026-27859)

 It was discovered that Dovecot incorrectly handles file paths. A attacker
 could possibly use this issue to perform a path traversal and obtain or
 modify arbitrary files. This issue only affected Ubuntu 22.04 LTS and
 Ubuntu 24.04 LTS. (CVE-2026-0394)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
  dovecot-core                    1:2.3.21+dfsg1-2ubuntu6.4

Ubuntu 22.04 LTS
  dovecot-core                    1:2.3.16+dfsg1-3ubuntu2.8

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-8136-2
  https://ubuntu.com/security/notices/USN-8136-1
  CVE-2026-0394, https://launchpad.net/bugs/2150116

Package Information:
  https://launchpad.net/ubuntu/+source/dovecot/1:2.3.21+dfsg1-2ubuntu6.4
  https://launchpad.net/ubuntu/+source/dovecot/1:2.3.16+dfsg1-3ubuntu2.8

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to