| Name | CVE-2026-52681 |
| Description | Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Compiled script files are also not removed when a script is deleted or renamed. The configured Sieve CPU limit can be bypassed, allowing sustained CPU consumption, and the leftover files increase disk consumption. Both can cause degradation of service for mail delivery. Monitor system for abnormal CPU usage and disk consumption. Update to non-vulnerable version. No publicly available exploits are known. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DSA-6526-1 |
| Debian Bugs | 1146018 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| dovecot (PTS) | bookworm, bookworm (security) | 1:2.3.19.1+dfsg1-2.1+deb12u6 | vulnerable |
| trixie | 1:2.4.1+dfsg1-6+deb13u6 | vulnerable | |
| trixie (security) | 1:2.4.1+dfsg1-6+deb13u7 | fixed | |
| forky | 1:2.4.5+dfsg1-2 | fixed | |
| sid | 1:2.4.5+dfsg1-3 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| dovecot | source | trixie | 1:2.4.1+dfsg1-6+deb13u7 | DSA-6526-1 | ||
| dovecot | source | (unstable) | 1:2.4.5+dfsg1-1 | 1146018 |
https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-52681-sieve-resource-usage-tracking-lost-when-active-script-changes
Fixed by: https://github.com/dovecot/core/commit/8d52bc7d037cda5f27fe996511a5367752095812
Fixed by: https://github.com/dovecot/core/commit/0ea42d6620746132c10f7a6ce4262dbbccf12751
Fixed by: https://github.com/dovecot/pigeonhole/commit/d82c2e624e4a9c364a6fa58fad0938ae5578660c
Fixed by: https://github.com/dovecot/pigeonhole/commit/4d0cbfe6260d567ebc34a747c29bb4e140124d93
Fixed by: https://github.com/dovecot/pigeonhole/commit/d6ba245e6ea6b062cd29f90cd4400e1865c711bc
Fixed by: https://github.com/dovecot/pigeonhole/commit/a6e8a540d5dfbd74c8397861a4df0224c857c83f
Fixed by: https://github.com/dovecot/pigeonhole/commit/62c759f78aa305c7aac7ea4733ea3c21a4059865
Fixed by: https://github.com/dovecot/pigeonhole/commit/d40ae7f5f55262bf8d210400da8a48523eb87ceb
Fixed by: https://github.com/dovecot/pigeonhole/commit/9b53f677825589c0334365aa0d165abf90175648
Fixed by: https://github.com/dovecot/pigeonhole/commit/3f62d49c50f182e467972ccecdd340ec178f8dba
Fixed by: https://github.com/dovecot/pigeonhole/commit/64b37c84373690d65e28fb5f45453612c260e4c8
Fixed by: https://github.com/dovecot/pigeonhole/commit/f65a341b027442d4448da039b8c623dcb69c37aa