RHSA-2026:46381: Important: dovecot security update
Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages. Security Fix(es): dovecot: Dovecot: Denial of Service via excessive IMAP bracing (CVE-2026-42006) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/dovecotto a version that resolves this vulnerability.Fixed in 2.3.16-3.el8_8.2 - Upgrade
Upgrade
redhat/dovecot-debuginfoto a version that resolves this vulnerability.Fixed in 2.3.16-3.el8_8.2 - Upgrade
Upgrade
redhat/dovecot-debugsourceto a version that resolves this vulnerability.Fixed in 2.3.16-3.el8_8.2 - Upgrade
Upgrade
redhat/dovecot-mysqlto a version that resolves this vulnerability.Fixed in 2.3.16-3.el8_8.2 - Upgrade
Upgrade
redhat/dovecot-mysql-debuginfoto a version that resolves this vulnerability.Fixed in 2.3.16-3.el8_8.2 - Upgrade
Upgrade
redhat/dovecot-pgsqlto a version that resolves this vulnerability.Fixed in 2.3.16-3.el8_8.2 - Upgrade
Upgrade
redhat/dovecot-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 2.3.16-3.el8_8.2 - Upgrade
Upgrade
redhat/dovecot-pigeonholeto a version that resolves this vulnerability.Fixed in 2.3.16-3.el8_8.2 - Upgrade
Upgrade
redhat/dovecot-pigeonhole-debuginfoto a version that resolves this vulnerability.Fixed in 2.3.16-3.el8_8.2 - Upgrade
Upgrade
dovecotto a version that resolves this vulnerability.Patch CVE-2026-42006
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:46381?
The severity of RHSA-2026:46381 is rated as high, with a score of 7.
What vulnerabilities does RHSA-2026:46381 address?
RHSA-2026:46381 addresses security vulnerabilities found in the Dovecot IMAP server.
How do I fix RHSA-2026:46381?
To fix RHSA-2026:46381, users should apply the latest security update for Dovecot as provided by Red Hat.
Is RHSA-2026:46381 applicable to all Dovecot installations?
RHSA-2026:46381 applies to all installations of Dovecot on supported Red Hat systems.
What should I do if I cannot apply the update for RHSA-2026:46381 immediately?
If unable to apply the update for RHSA-2026:46381 immediately, it is recommended to review your system's security posture and minimize exposure until the update can be applied.