Back Linuxsecurity Fedora 44 Dovecot Moderate Info Disclosure DoS Vuln 2026
CVE-2026-27851: lib-var-expand: Safe filter marks all following pipelines safe. CVE-2026-33603: auth: CRAM-SHA-*-PLUS channel binding could be faked. MITM attacker with a certificate trusted by the client could have bypassed the requirement for channel binding. CVE-2026-40020: IMAP folders can be shared-spammed to everyone. CVE-2026-42006: An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete. indexer-worker, quota-status, script-login, program-client-local: Root privileges are now dropped permanently before serving requests. indexer-worker: Default restart_request_count changed to 1 to work correctly after permanent root privilege drop. lmtp: Add back service_extra_groups=$SET:default_internal_group that was incorrectly removed in v2.4.3. master: inet_listener_reuse_port has been replaced by service_reuse_port. The new setting properly pre-creates all listener sockets at startup and ...
* Fri May 15 2026 Michal Hlavinka - 1:2.4.4-1 - updated to 2.4.4 (#2476459)
* Fri May 15 2026 Michal Hlavinka - 1:2.4.4-1 - updated to 2.4.4 (#2476459)
[ 1 ] Bug #2479583 - CVE-2026-33603 dovecot: Dovecot: Information disclosure via SCRAM TLS channel binding bypass [fedora-all] [ 2 ] Bug #2479588 - CVE-2026-40020 dovecot: dovecot: Denial of Service via IMAP SETACL command injection [fedora-all] [ 3 ] Bug #2481123 - CVE-2026-40016 dovecot: Dovecot: Denial of Service due to Sieve script CPU limit bypass [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-96eeb03b88' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
