[CLSA-2026:1787334245] dovecot: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-21 17:44:15 UTC
Description:
- CVE-2026-0394: normalize expanded passwd-file paths and enforce their base directory to prevent path traversal - CVE-2025-59031: remove the unsafe decode2text.sh attachment conversion script
Updated packages:
  • dovecot-2.3.16-8.el9_2.tuxcare.els7.i686.rpm
    sha:7d1af3f83f908d099c3a9b77bff3b6d3382011f57e93e3e3d513be0bfab1b2eb
  • dovecot-2.3.16-8.el9_2.tuxcare.els7.x86_64.rpm
    sha:0e4325b6417ba491860ea02f34a769daa2cfa56c5e50d3078ae5f417f61bb572
  • dovecot-devel-2.3.16-8.el9_2.tuxcare.els7.i686.rpm
    sha:1f246d52b3885f3c47a33dc07197284f75963f7e7c7399296ce20f15807091bd
  • dovecot-devel-2.3.16-8.el9_2.tuxcare.els7.x86_64.rpm
    sha:df30ab2ee46102aebe03ce1a15f90f768436effcd0aeee66407ddbfe629046ba
  • dovecot-mysql-2.3.16-8.el9_2.tuxcare.els7.x86_64.rpm
    sha:462dd29b3250f11154f8ab42fcd35abfc2d370d0524ba502fc96ef02bae576aa
  • dovecot-pgsql-2.3.16-8.el9_2.tuxcare.els7.x86_64.rpm
    sha:17554c45675a435f6bec5a53fe980415b9e343ee39c99caa045f201d8b8ad050
  • dovecot-pigeonhole-2.3.16-8.el9_2.tuxcare.els7.x86_64.rpm
    sha:f145de7d1f8be570105869f9e2295ec6b2a88dc7208e205f0d4a8dd5cbb81aea
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.