[CLSA-2026:1787231577] dovecot: Fix of CVE-2026-27858
Type:
security
Severity:
Important
Release date:
2026-08-20 13:13:08 UTC
Description:
- CVE-2026-27858: fix pre-auth memory exhaustion in managesieve-login from an oversized AUTHENTICATE initial response
CVEs fixed:
Updated packages:
  • dovecot-2.2.36-8.el7.tuxcare.els3.i686.rpm
    sha:661182aee9c47c7da6a56b37560baff3e38e57a2537c8cae861a597b7cfd499c
  • dovecot-2.2.36-8.el7.tuxcare.els3.x86_64.rpm
    sha:51a28ade6d4cb98caceb78b93636bf52672df1f8ee07052a439b769efc111bd9
  • dovecot-devel-2.2.36-8.el7.tuxcare.els3.i686.rpm
    sha:c7a2f0d8616489d051ac997e010d415654bc609d734abf36ec867561996e6a18
  • dovecot-devel-2.2.36-8.el7.tuxcare.els3.x86_64.rpm
    sha:1db1fa39e0ced517f0ffac42619d528aaab80e88ec5884207c7216755b234a57
  • dovecot-mysql-2.2.36-8.el7.tuxcare.els3.x86_64.rpm
    sha:a98349f6aa76dc542bd9a17fa691c6817ec232eed36ce528e64c3db7571addcb
  • dovecot-pgsql-2.2.36-8.el7.tuxcare.els3.x86_64.rpm
    sha:7ce1379f6b30854fa7511460d9aee440e036d6f178d347d5a7b7739771687e68
  • dovecot-pigeonhole-2.2.36-8.el7.tuxcare.els3.x86_64.rpm
    sha:2c8325216a26902a0492151b10a4b37d2cd06d4c1c3fde939cb41b17ab4ca7f7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.