PT-2026-83058 · Dovecot · Dovecot

·

CVE-2026-40015

·

Published

2026-08-28

·

Updated

2026-09-02

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions dovecot versions prior to 2.4.5-1.1
Description An attacker with valid credentials can establish multiple connections to the imap-hibernate service and send invalid commands. This action can trigger an intermittent out-of-bounds read, leading to a process crash. Such crashes interrupt hibernated IMAP sessions, resulting in a degradation of IMAP service. An out-of-bounds read occurs when the software reads data past the end of the intended buffer, potentially accessing restricted memory.
Recommendations Update to version 2.4.5-1.1. Disable IMAP hibernation.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98328
CVE-2026-40015
OPENSUSE-SU-2026:11629-1
OPENSUSE-SU-2026:21720-1
SUSE-SU-2026:3919-1

Affected Products

Dovecot