CVE-2026-40015

NameCVE-2026-40015
DescriptionAn attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process. The crash interrupts hibernated IMAP sessions handled by the affected process, which can cause degradation of service for IMAP. Disable IMAP hibernation. Update to non-vulnerable version. No publicly available exploits are known.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6526-1
Debian Bugs1146018

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dovecot (PTS)bookworm, bookworm (security)1:2.3.19.1+dfsg1-2.1+deb12u6vulnerable
trixie1:2.4.1+dfsg1-6+deb13u6vulnerable
trixie (security)1:2.4.1+dfsg1-6+deb13u7fixed
forky1:2.4.5+dfsg1-2fixed
sid1:2.4.5+dfsg1-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dovecotsourcetrixie1:2.4.1+dfsg1-6+deb13u7DSA-6526-1
dovecotsource(unstable)1:2.4.5+dfsg1-11146018

Notes

https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40015-imap-hibernate-can-be-crashed
Fixed by: https://github.com/dovecot/core/commit/caeee3d1d2b725963555fe63ea8200292cad1058
Fixed by: https://github.com/dovecot/core/commit/09f7a34a6a9888d1325524ff8095d0a7793c075f

Search for package or bug name: Reporting problems