[CLSA-2026:1787232011] dovecot: Fix of CVE-2026-27858
Type:
security
Severity:
Important
Release date:
2026-08-20 13:20:21 UTC
Description:
- CVE-2026-27858: fix pre-auth memory exhaustion in managesieve-login from an oversized AUTHENTICATE initial response
CVEs fixed:
Updated packages:
  • dovecot-2.2.36-8.el7.tuxcare.els3.i686.rpm
    sha:5b918cb98a7b1483d4c5b633609ad7224fb1aae3d7a1a10bdc9b6b591f0faf08
  • dovecot-2.2.36-8.el7.tuxcare.els3.x86_64.rpm
    sha:7a324d76dd692ed66d5f84b5907e590767bfbcd095cf9d6d502f3f67500d0c87
  • dovecot-devel-2.2.36-8.el7.tuxcare.els3.i686.rpm
    sha:fea0f7cccb4fbbca1e856aa6aa809a6aa5191119de9ca9d302d2d76bb6eb0143
  • dovecot-devel-2.2.36-8.el7.tuxcare.els3.x86_64.rpm
    sha:672fdc0c51c786c2bab06da5ddb418e3dcdfc5d17dc44981116a94f10c445ba3
  • dovecot-mysql-2.2.36-8.el7.tuxcare.els3.x86_64.rpm
    sha:65e2592ce53da9333cec156194d4f4460845e627e66bee6c6a37d15db30b2438
  • dovecot-pgsql-2.2.36-8.el7.tuxcare.els3.x86_64.rpm
    sha:eb5fe6e473c8900fe3ff4d1d8f97000edf84cb546f8ee1c6e3b6a11d03562afd
  • dovecot-pigeonhole-2.2.36-8.el7.tuxcare.els3.x86_64.rpm
    sha:6bad6da6401d9d1aa577e96b2330a024d5042f3ccba5b5830802cc033eb14c62
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.