Bug 2525583 (CVE-2026-42007) - CVE-2026-42007 dovecot: Dovecot: Arbitrary Code Execution via Sieve editheader use-after-free
Summary: CVE-2026-42007 dovecot: Dovecot: Arbitrary Code Execution via Sieve editheade...
Keywords:
Status: NEW
Alias: CVE-2026-42007
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2526683
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-28 11:24 UTC by OSIDB Bzimport
Modified: 2026-09-01 07:26 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-28 11:24:15 UTC
An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.


Note You need to log in before you can comment on or make changes to this bug.