[CLSA-2026:1787232907] dovecot: Fix of CVE-2026-27858
Type:
security
Severity:
Important
Release date:
2026-08-20 18:31:09 UTC
Description:
- CVE-2026-27858: fix pre-auth memory exhaustion in managesieve-login from an oversized AUTHENTICATE initial response
CVEs fixed:
Updated packages:
  • dovecot-2.2.36-8.el7.tuxcare.els3.i686.rpm
    sha:73621dcd97027bd474579b090aa8ca5e98a804729ede8954a90acfbc1226f8da
  • dovecot-2.2.36-8.el7.tuxcare.els3.x86_64.rpm
    sha:25d180392800a2e840f2936b1b29bc18930765aafdabe1fc6a938e4a585eb94f
  • dovecot-devel-2.2.36-8.el7.tuxcare.els3.i686.rpm
    sha:9bb42a64853cfe20486eca7bea51ede7115f433cf980fcd7dcd8357afa084606
  • dovecot-devel-2.2.36-8.el7.tuxcare.els3.x86_64.rpm
    sha:c3a3919357aa510d8caa404e055cabb69dcd3b3f4c42de640760c6d8e22ea77d
  • dovecot-mysql-2.2.36-8.el7.tuxcare.els3.x86_64.rpm
    sha:6fca6bd8ec1b282cd44d8db7608f3daa9bf42595638dc2207fae2907cec2d9ad
  • dovecot-pgsql-2.2.36-8.el7.tuxcare.els3.x86_64.rpm
    sha:528557a9456084f1edd19a5818605c6cd71679cf97fa5acb4c263906c3000173
  • dovecot-pigeonhole-2.2.36-8.el7.tuxcare.els3.x86_64.rpm
    sha:653f93f4d43830e135614abf4f3ef6712048caf0e70505359ec0faa5cd17fe73
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.