馃摑 Preliminary Checks
馃憖 What Happened?
Because there is a full distro inside the docker container, I tried to open a shell and run apt-get upgrade to update my system until a new docker container image is published, however, doing that this time got me some sort of version mismatch:
Error: imap settings: Failed to parse configuration: settings struct imap #11 key mismatch imap_compress_on_proxy != mail_utf8_extensions
Just making sure everyone is aware of this.
Package : dovecot
CVE ID : CVE-2026-27852 CVE-2026-33263 CVE-2026-33604 CVE-2026-33605
CVE-2026-33606 CVE-2026-33607 CVE-2026-40013 CVE-2026-40014
CVE-2026-40015 CVE-2026-40017 CVE-2026-40018 CVE-2026-40203
CVE-2026-40204 CVE-2026-40205 CVE-2026-42007 CVE-2026-42008
CVE-2026-42391 CVE-2026-42392 CVE-2026-42393 CVE-2026-42394
CVE-2026-42395 CVE-2026-52681 CVE-2026-52687 CVE-2026-73208
CVE-2026-73209
Debian Bug : 1144639
Multiple vulnerabilities have been discovered in the Dovecot IMAP server
which could result in denial of service, SMTP smuggling, information
disclosure, code injection via malformed Sieve scripts or bypass of ACL
restrictions.
For the stable distribution (trixie), these problems have been fixed in
version 1:2.4.1+dfsg1-6+deb13u7.
馃憻 Reproduction Steps
No response
馃悑 DMS Version
v16.0.1
馃捇 Operating System and Architecture
Ubuntu 24.04.5 LTS x86_64
鈿欙笍 Container configuration files
This is not relevant to this bug report
馃摐 Relevant log output
# dpkg -l | egrep dovecot
ii dovecot-auth-lua 1:2.4.1+dfsg1-6+deb13u6 amd64 secure POP3/IMAP server - Lua authentication plugin
ii dovecot-core 1:2.4.1+dfsg1-6+deb13u6 amd64 secure POP3/IMAP server - core files
ii dovecot-flatcurve 1:2.4.1+dfsg1-6+deb13u6 amd64 secure POP3/IMAP server - Flatcurve support
ii dovecot-fts-xapian 1.9.1-1~bpo12+1 amd64 full-text search for dovecot using xapian
ii dovecot-imapd 1:2.4.1+dfsg1-6+deb13u6 amd64 secure POP3/IMAP server - IMAP daemon
ii dovecot-ldap 1:2.4.1+dfsg1-6+deb13u6 amd64 secure POP3/IMAP server - LDAP support
ii dovecot-lmtpd 1:2.4.1+dfsg1-6+deb13u6 amd64 secure POP3/IMAP server - LMTP server
ii dovecot-managesieved 1:2.4.1+dfsg1-6+deb13u6 amd64 secure POP3/IMAP server - ManageSieve server
ii dovecot-pop3d 1:2.4.1+dfsg1-6+deb13u6 amd64 secure POP3/IMAP server - POP3 daemon
ii dovecot-sieve 1:2.4.1+dfsg1-6+deb13u6 amd64 secure POP3/IMAP server - Sieve filters support
ii dovecot-solr 1:2.4.1+dfsg1-6+deb13u6 amd64 secure POP3/IMAP server - Solr support
馃摑 Preliminary Checks
馃憖 What Happened?
Because there is a full distro inside the docker container, I tried to open a shell and run apt-get upgrade to update my system until a new docker container image is published, however, doing that this time got me some sort of version mismatch:
Just making sure everyone is aware of this.
Package : dovecot
CVE ID : CVE-2026-27852 CVE-2026-33263 CVE-2026-33604 CVE-2026-33605
CVE-2026-33606 CVE-2026-33607 CVE-2026-40013 CVE-2026-40014
CVE-2026-40015 CVE-2026-40017 CVE-2026-40018 CVE-2026-40203
CVE-2026-40204 CVE-2026-40205 CVE-2026-42007 CVE-2026-42008
CVE-2026-42391 CVE-2026-42392 CVE-2026-42393 CVE-2026-42394
CVE-2026-42395 CVE-2026-52681 CVE-2026-52687 CVE-2026-73208
CVE-2026-73209
Debian Bug : 1144639
Multiple vulnerabilities have been discovered in the Dovecot IMAP server
which could result in denial of service, SMTP smuggling, information
disclosure, code injection via malformed Sieve scripts or bypass of ACL
restrictions.
For the stable distribution (trixie), these problems have been fixed in
version 1:2.4.1+dfsg1-6+deb13u7.
馃憻 Reproduction Steps
No response
馃悑 DMS Version
v16.0.1
馃捇 Operating System and Architecture
Ubuntu 24.04.5 LTS x86_64
鈿欙笍 Container configuration files
This is not relevant to this bug report馃摐 Relevant log output