Bug 2476476 (CVE-2026-42006)
| Summary: | CVE-2026-42006 dovecot: Dovecot: Denial of Service via excessive IMAP bracing | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Dovecot. A remote attacker can exploit this vulnerability by sending excessive open braces over the Internet Message Access Protocol (IMAP), leading to uncontrolled memory usage. This can cause the affected system to consume memory up to its configured limit, resulting in a Denial of Service (DoS).
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2492898, 2492900, 2492895, 2492906, 2492907, 2492908 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-05-12 14:02:24 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:41905 https://access.redhat.com/errata/RHSA-2026:41905 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:41988 https://access.redhat.com/errata/RHSA-2026:41988 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:42091 https://access.redhat.com/errata/RHSA-2026:42091 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:44357 https://access.redhat.com/errata/RHSA-2026:44357 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:44373 https://access.redhat.com/errata/RHSA-2026:44373 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:44355 https://access.redhat.com/errata/RHSA-2026:44355 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:46380 https://access.redhat.com/errata/RHSA-2026:46380 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:46379 https://access.redhat.com/errata/RHSA-2026:46379 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:46381 https://access.redhat.com/errata/RHSA-2026:46381 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:46532 https://access.redhat.com/errata/RHSA-2026:46532 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:49513 https://access.redhat.com/errata/RHSA-2026:49513 |