Home / mailings [USN-8136-1] Dovecot vulnerabilities
Posted on 31 March 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8136-1
March 31, 2026
dovecot vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 25.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in Dovecot.
Software Description:
- dovecot: IMAP and POP3 email server
Details:
It was discovered that Dovecot incorrectly handled invalid base64 SASL data.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 25.10. (CVE-2025-59028)
It was discovered that Dovecot script decode2text.sh incorrectly handled zip
files. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-59031)
It was discovered that Dovecot incorrectly handled certain AUTHENTICATE
requests. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-59032)
It was discovered that Dovecot incorrectly handled certain SQL based
authentication. An attacker could possibly use this issue to bypass
authentication. This issue only affected Ubuntu 25.10. (CVE-2026-24031)
It was discovered that Dovecot incorrectly handled certain LDAP based
authentication. An attacker could possibly use this issue to bypass
restrictions and allow probing of LDAP structure. This issue only affected
Ubuntu 25.10. (CVE-2026-27860)
It was discovered that Dovecot is vulnerable to replay attack under
certain conditions. An attacker could possibly use this issue to bypass
authentication. (CVE-2026-27855)
It was discovered that Dovecot is vulnerable to a timing attack under
certain conditions. An attacker could possibly use this issue to bypass
authentication. (CVE-2026-27856)
It was discovered that Dovecot incorrectly handled certain IMAP login
requests. An attacker could possibly use this issue to cause a denial of
service. (CVE-2026-27857)
It was discovered that Dovecot incorrectly handled certain specially
crafted messages. An attacker could possibly use this issue to cause a
denial of service. (CVE-2026-27858)
It was discovered that Dovecot incorrectly handled certain specially
crafted mail messages. An attacker could possibly use this issue to
cause a denial of service. (CVE-2026-27859)
It was discovered that Dovecot incorrectly handles file paths. A attacker
could possibly use this issue to perform a path traversal and obtain or
modify arbitrary files. This issue only affected Ubuntu 22.04 LTS and
Ubuntu 24.04 LTS. (CVE-2026-0394)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 25.10
dovecot-core 1:2.4.1+dfsg1-5ubuntu4.1
Ubuntu 24.04 LTS
dovecot-core 1:2.3.21+dfsg1-2ubuntu6.3
Ubuntu 22.04 LTS
dovecot-core 1:2.3.16+dfsg1-3ubuntu2.7
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8136-1
CVE-2025-59028, CVE-2025-59031, CVE-2025-59032, CVE-2026-0394,
CVE-2026-24031, CVE-2026-27855, CVE-2026-27856, CVE-2026-27857,
CVE-2026-27858, CVE-2026-27859, CVE-2026-27860
Package Information:
https://launchpad.net/ubuntu/+source/dovecot/1:2.4.1+dfsg1-5ubuntu4.1
https://launchpad.net/ubuntu/+source/dovecot/1:2.3.21+dfsg1-2ubuntu6.3
https://launchpad.net/ubuntu/+source/dovecot/1:2.3.16+dfsg1-3ubuntu2.7
--===============3567501099420304914==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
