Oracle Dovecot Security Fixes Address Multiple Vulnerabilities

Oracle Dovecot Security Fixes Address Multiple Vulnerabilities

First seen 13 Aug 2026, 00:33 UTC Linuxsecurity 81% similarity 57.9

Article Content

Browse articles
ThreatCluster

Oracle has released important security updates for Dovecot in Oracle Linux 7, addressing multiple vulnerabilities. The updates fix CVE-2020-12100, CVE-2020-12673, CVE-2020-12674, and several CVEs from 2026, including CVE-2025-59032, CVE-2026-27856, CVE-2026-27857, CVE-2026-27858, and CVE-2026-42006. These vulnerabilities could lead to resource exhaustion, out-of-bounds reads, and crashes, impacting systems using Dovecot for email services. The updates include backports of critical fixes, and users are advised to audit Linux privileges to mitigate potential risks. The vulnerabilities affect various Dovecot packages across both 32-bit and 64-bit architectures. Administrators are urged to apply the patches promptly to safeguard their systems.

Key Points: • Oracle released critical updates for Dovecot addressing multiple CVEs. • Vulnerabilities include resource exhaustion and out-of-bounds reads. • Affected systems include Oracle Linux 7 with Dovecot installed.

ThreatCluster AI How this analysis works

Timeline

2020-08-12
CVE-2020-12100 published
Resource exhaustion vulnerability in Dovecot due to deeply nested MIME parts disclosed.
Linuxsecurity
2020-08-12
CVE-2020-12673 published
Out-of-bounds read vulnerability in Dovecot's NTLM implementation disclosed.
Linuxsecurity
2020-08-12
CVE-2020-12674 published
Crash vulnerability in Dovecot due to an assert in RPA implementation disclosed.
Linuxsecurity
2026-03-27
CVE-2025-59032 published
Vulnerability affecting Dovecot disclosed, requiring urgent attention for patching.
Linuxsecurity
2026-03-27
CVE-2026-27856 published
Vulnerability affecting Dovecot disclosed, requiring urgent attention for patching.
Linuxsecurity
2026-03-27
CVE-2026-27857 published
Vulnerability affecting Dovecot disclosed, requiring urgent attention for patching.
Linuxsecurity
2026-03-27
CVE-2026-27858 published
Vulnerability affecting Dovecot disclosed, requiring urgent attention for patching.
Linuxsecurity
2026-05-12
CVE-2026-42006 published
New vulnerability affecting Dovecot disclosed, requiring urgent attention for patching.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story