PT-2026-28366 · Dovecot+4 · Dovecot+4

·

CVE-2026-27858

·

Publicado

2026-01-01

·

Atualizado

2026-07-07

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Dovecot versions prior to 2.4.3
Description An attacker can send a crafted message before authentication, leading to excessive memory allocation within the managesieve component. This can cause the managesieve-login process to crash, potentially resulting in a denial-of-service condition. No publicly available exploits are currently known.
Recommendations Update to version 2.4.3 or later. Protect access to the managesieve protocol.

Exploit

Correção

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2026:13498
ALSA-2026:13830
ALSA-2026:13857
ALSA-2026:19149
ALSA-2026:19364
AZL-81710
BDU:2026-10384
CVE-2026-27858
OESA-2026-1849
OPENSUSE-SU-2026:10442-1
OPENSUSE-SU-2026:20554-1
RHSA-2026:13498
RHSA-2026:13830
RHSA-2026:13857
SUSE-SU-2026:1641-1
SUSE-SU-2026:21208-1
USN-8136-1

Produtos afetados

Dovecot
Linuxmint
Red Os
Rocky Linux
Ubuntu