CVE-2026-40015: Medium severity vulnerability
An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process. The crash interrupts hibernated IMAP sessions handled by the affected process, which can cause degradation of service for IMAP. Disable IMAP hibernation. Update to non-vulnerable version. No publicly available exploits are known.
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs valid credentials and network access to the imap-hibernate service. No user interaction is required.
What is the operational impact of a successful attack?
The attacker can cause the affected imap-hibernate process to crash. Hibernated IMAP sessions handled by that process are interrupted, potentially degrading IMAP service.
Is there a mitigation if updating cannot happen immediately?
Disable IMAP hibernation to mitigate the issue. Updating to a non-vulnerable version is the recommended remediation.
Are public exploits available?
No publicly available exploits are known.