Bug 2402122 - CVE-2025-30189 dovecot 2.4: access to other users' emails
Summary: CVE-2025-30189 dovecot 2.4: access to other users' emails
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: dovecot
Version: 43
Hardware: All
OS: Linux
unspecified
urgent
Target Milestone: ---
Assignee: Michal Hlavinka
QA Contact: Fedora Extras Quality Assurance
URL: https://security-tracker.debian.org/t...
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-10-07 09:48 UTC by Stephan Verbücheln
Modified: 2025-10-09 15:18 UTC (History)
3 users (show)

Fixed In Version: dovecot-2.4.1-6.fc44
Clone Of:
Environment:
Last Closed: 2025-10-09 15:18:48 UTC
Type: ---
Embargoed:
mhlavink: mirror+


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker FC-2480 0 None None None 2025-10-09 09:01:57 UTC

Description Stephan Verbücheln 2025-10-07 09:48:31 UTC
A flaw in the authentication cache implementation allows users to access other users' emails in dovecot 2.4.

Note that authentication cache is not enabled by default.

The bug was introduced with dovecot 2.4, specifically the renaming of configuration variables (%u to %{user}), 2.3 is not affected.

Reproducible: Always

Steps to Reproduce:
1. Configure authentication cache.
2. Access email.
Actual Results:
Access to other users' emails.

Expected Results:
Access only to your own emails.

Additional Information:
CVE-2025-30189 has been assigned but not yet published. Debian has documented this in bugs and security advisories:

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1115474
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1115964
https://security-tracker.debian.org/tracker/CVE-2025-30189

The bug was fixed on August 1, 2025, but somehow has not made it into upstream release:
https://github.com/dovecot/core/commit/a70ce7d3e2f983979e971414c5892c4e30197231

Comment 1 Stephan Verbücheln 2025-10-08 11:29:22 UTC
The same bug in Ubuntu has been fixed.

https://bugs.launchpad.net/ubuntu/+source/dovecot/+bug/2126984

Comment 2 Fedora Update System 2025-10-09 14:19:02 UTC
FEDORA-2025-d5eb72768a (dovecot-2.4.1-6.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-d5eb72768a

Comment 3 Fedora Update System 2025-10-09 15:18:48 UTC
FEDORA-2025-d5eb72768a (dovecot-2.4.1-6.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.