Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package dovecot24 for openSUSE:Factory checked in at 2026-08-28 19:56:15 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/dovecot24 (Old) and /work/SRC/openSUSE:Factory/.dovecot24.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "dovecot24" Fri Aug 28 19:56:15 2026 rev:19 rq:1374366 version:2.4.5 Changes: -------- --- /work/SRC/openSUSE:Factory/dovecot24/dovecot24.changes 2026-05-13 17:22:00.337928368 +0200 +++ /work/SRC/openSUSE:Factory/.dovecot24.new.1265/dovecot24.changes 2026-08-28 19:58:48.232931867 +0200 @@ -1,0 +2,340 @@ +Fri Aug 28 12:04:17 UTC 2026 - Marcus Rueckert <[email protected]> + +- The following man pages are currently not available as they are + missing in the tarball. They will be added back to the package + when the upstream issue is solved: + + doveadm-sieve.1 sieve-dump.1 sieve-filter.1 sieve-test.1 sievec.1 + pigeonhole.7 + +------------------------------------------------------------------- +Fri Aug 28 11:33:18 UTC 2026 - Marcus Rueckert <[email protected]> + +- Update to 2.4.5 (boo#1276794 boo#1276795 boo#1276799 boo#1276800 + boo#1276802 boo#1276804 boo#1276807 boo#1276809 boo#1276810 + boo#1276811 boo#1276812 boo#1276813 boo#1276815 boo#1276817 + boo#1276819 boo#1276820 boo#1276824 boo#1276826 boo#1276827 + boo#1276828 boo#1276829 boo#1276830 boo#1276833 boo#1276835 + boo#1276837) + - Critical bug fixes + - CVE-2026-27852: Messages with a huge number of From/To/Cc/etc + email addresses could result in excessive memory usage. + - CVE-2026-33263: Submission: Login service crashes with panic + once mail_max_userip_connections limit is reached. + - CVE-2026-33604: The SMTP outbound dot-stuffing mechanism does + not properly escape dots following a bare \r in message + bodies, potentially allowing spoofed emails via malicious + end-of-DATA injection. + - CVE-2026-33606: Mail content stored by a user can be crafted + so that it is interpreted as dsync protocol commands when an + administrator later runs dsync with the stream protocol, for + example during a migration. + - CVE-2026-33607: IMAP LIST command could be used to cause + excessive CPU usage. + - CVE-2026-40014: IMAP THREAD command could have used excessive + amount of CPU processing a single email with a massive number + of Message-IDs in References header. + - CVE-2026-40015: Invalid IMAP command sent to imap-hibernate + process might crash it. + - CVE-2026-40017: IMAP THREAD command could have used excessive + amount of CPU processing emails with a large number of + specially crafted Message-IDs in References header. The fix + requires a new dovecot.index.thread file format, which is + enabled only after setting dovecot_storage_version or newer. + This rebuilds the index, so it will cause some extra CPU + usage and extra metacache disk IO usage. It shouldn't cause + (much) extra object storage IO, because all the fields should + be coming from dovecot.index.cache. + - CVE-2026-40203: When IMAP COMPRESS=DEFLATE was enabled, an + attacker could send mails into a victim's mailbox and observe + network traffic to determine whether a secret message matched + a known string by comparing compressed response sizes (a + CRIME-style attack). The fix resets the compression + dictionary after each IMAP command, preventing information + from leaking between commands. + - CVE-2026-40205: If multiple OAUTH scopes were required, then + this could have been only partially enforced with certain + configurations. + - CVE-2026-4200: XCLIENT FORWARD allows to forward key only + passdb fields without the "forward_" prefix which allows + connections from trusted networks to set nopasswd field which + allows to skip the authentication. + - CVE-2026-42391: Pre-login IMAP ID command could have used + excessive amount of memory, causing the process to become + killed and disconnecting all the other IMAP connections being + proxied by the process. Or alternatively it could have caused + excessive CPU usage, slowing down all the other IMAP + connections being proxied by the process. + - CVE-2026-42392: If URLAUTH is enabled, sending an invalid + IMAP URLFETCH can result in an untagged NO response + containing uninitialized memory, potentially leaking + sensitive data. + - CVE-2026-42393: Doveadm password length or API key length + could still be determined via timing based attacks. + - CVE-2026-42395: XCLIENT FORWARD command from + login_trusted_networks could have been used to cause login + processes to crash. + - CVE-2026-52681: Sieve resource usage (sieve_max_cpu_time) was + tracked in the active Sieve binary. Switching to a different + active binary could have been used to reset (bypass) the + resource usage. + - CVE-2026-52687: Using IMAP COMPRESS ZSTD command can cause + excessive memory usage in imap-login process, possibly making + it reach vsz_limit and kill all the connections being served + by the process. Fixed by disabling COMPRESS command with all + other compression algorithms than the standard DEFLATE. + - CVE-2026-73208: In oauth2, scope/aud checking was done with + JWT tokens. Now it requires all scopes. + - CVE-2026-73209: Sending IMAP COMPRESS package containing + zero-length frames crashes imap or imap-login process. +- Changes + - auth: SIGHUP no longer flushes the passdb cache and SIGUSR2 + no longer logs cache statistics. Use "doveadm auth cache + flush" and the new "doveadm auth cache status" instead. + - auth: The OTP authentication mechanism, the {OTP} password + scheme and the passdb set-credentials support have been + removed. They were unmaintained and unused. This also drops + the passdb_sql_update_query setting. + - config: doveconf no longer prints a flat global setting when + a top-level named filter overrides the same setting. + - doveadm: The doveadm protocol has been bumped to v1.4. The + server uses the newer multiplex stream format with clients + supporting it. Older clients keep working unchanged. + - map: Change imap_compress_on_proxy default to yes. + - lib-dict-extra: Increase dict client request timeout from 30s + to 65s, so it stays above the SQL/Cassandra query timeout. + - lib-http: HTTP requests are now parsed strictly: obsolete + line folding (obs-fold) and a bare LF line terminator are + rejected. Both are request desynchronization/smuggling risks. + HTTP responses are still parsed leniently. + - lib-storage: A '~' in a mailbox name is now escaped only when + it is at the beginning of the mailbox name, not at the + beginning of every hierarchy part. Directories written by + older versions are migrated automatically while listing + mailboxes. + - lib-var-expand: Add %{time:unix} provider and the epoch, + from_epoch, date, iso8601 and escape filters. Deprecates the + old time providers. + - lib-var-expand: The safe filter must now be the last filter + in the chain. + - master: Increase the timeout after config reload before + killing still running old processes from 6s to 35s, so that + lib-master can stop them gracefully first. + - New features + - config: Support heredoc syntax for multi-line setting values: + key = <<EOD ... EOD. doveconf now outputs inline SET_FILE + contents (e.g. ssl_ca) using heredoc instead of the "inline:" + prefix. The + - "inline:" form is still accepted. + - configure: Build imap-hibernate also when only kqueue notify + is available. + - doveadm: Add "doveadm auth cache status" command, with + --reset for clearing the counters. + - doveadm: dump - List all supported dump types, and print the + key type also for KEM and unsupported keys. + - fts-flatcurve: Add support for phrase searching. This fixes + false positives where the searched words existed, but not as + a phrase. + - fts-flatcurve: Delete the FTS index directory also when a + Maildir mailbox is deleted. + - imap: Add [THROTTLED] response code to tagged replies when a + plugin has throttled the command. + - last-login: Add last_login_dict_fields setting for updating + multiple dictionary fields at login. + - lib-dcrypt: Add ML-KEM-512/768/1024 support with OpenSSL 3. + - lib-dcrypt: Support AEAD with Dovecot key encryption. + - lib-settings: Expand %{variables} also in strlist and + boollist keys. + - lib-sql: sqlite - Add sqlite_busy_timeout setting, default + 1s. + - login-common: Log the destination also when a proxy + connection fails. + - quota: Update quota-clone also when "doveadm quota recalc" is + run. + - Bug fixes + - Fix building on systems with a signed 32-bit time_t. + - Fix building with Lua when LUA_LIBS contains linker flags + such as -L. + - anvil: Fix busy loop eating CPU after an admin socket + connection was disconnected. + - auth: Fix authentication failing after a password change when + the + - passdb cache entry was verified by an auth worker. + - auth: Fix the credentials scheme of one passdb leaking into + the next one during a multi-passdb lookup. + - auth: oauth2 - Fix losing userdb_* fields during OAUTHBEARER + authentication. + - auth: passwd-file - Fix %{passdb:...} and %{userdb:...} + expansion returning garbage or crashing. + - config: Fix crash in "doveconf -f" for a filter that includes + a @group. + - config: Fix crash when including a default @group into a + filter. + - config: Fix hiding secrets in doveconf output. + - config: Fix startup failures with some settings containing + %{variables}. + - configure: Fix BUILD_IMAP_HIBERNATE detection. + - doc: solr-schema-9.xml - Add the mandatory tokenizer class + attribute. + - doveadm: compress-connect - Fix writing server input to a + non-blocking stdout. + - doveadm: fs delete - Fix crash with concurrent async deletes. + - doveconf: Fix bogus "Multiple settings matched" error when + stdout is redirected to a file that already has content. + - dsync: Fix truncating a mailbox attribute value when it is + compared to the local one, e.g. truncating a Sieve script. + - dsync: backup - Mailbox attributes changed or created only in + the destination are now reverted or deleted. + - fts-flatcurve: Ignore index directory entries that vanish + during iteration. + - fts: Don't run FTS optimize on forced resync. + - fts: build-mail - Fix accessing Content-Type header buffer + out of bounds. + - imap-login, pop3-login: Tolerate SASL continuations "+" + without a trailing space when proxying authentication. + - imap: Don't report FETCH output stream errors as + - "BUG: Unknown internal error". + - imap: Fix hibernation always failing on FreeBSD. + - imap: Fix panic on GETMETADATA with an invalid UTF-8 mailbox + pattern. + - imapc: Don't send SEEEN/UNSEEN to the remote server when + private indexes are used. + - imapc: Fix SEARCH results pointing at wrong messages after an + untagged EXPUNGE. + - imapc: Fix SORT returning an empty result when search + criteria were used. + - imapc: Fix crash when copying a mail that was already + expunged in the source mailbox. + - imapc: Fix stale SEARCH/SORT results after a STORE in the + same session. + - imapc: Honor imapc_features=no-search also for SORT. + - imapc: Properly handle search criteria that can be sent to + remote server. + - lib-dcrypt: Don't panic on key algorithms the backend doesn't + support. + - lib-dcrypt: Fix x9.62 ECDSA signatures randomly failing + verification. + - lib-dict-backend: cdb - Fix use-after-free of the returned + key. + - lib-dns-client: Fix handling of a disconnect initiated by the + dns-client service. + - lib-fs: Fix panic in fs_write_stream_abort(), e.g. when the + disk is full during FTS indexing. + - lib-index: Fix "File is already open" error when appending to + the transaction log while another process is rotating it. + This showed up as "NO [SERVERBUG] Internal error occurred." + without any logging. + - lib-ldap: Fall back to system default CA paths, needed for + OpenLDAP built against GnuTLS. + - lib-mail: istream-binary-converter - Fix heap use-after-free + with a bodyless MIME part. + - lib-mail: message-parser - Fix out of bounds read with an + empty preamble, fix skipping the epilogue boundary line, and + degrade to a re-parse instead of panicking with an + inconsistent cached MIME tree. + - lib-master: Fix kick reason when the KICK-USER-SIGNAL command + arrives late, which logged "Killed with signal 15" instead of + "User kicked". + - lib-oauth2: jwt - Fix use-after-realloc, guard against an + empty body segment and percent-encode bare "." and ".." + identifiers. + - lib-program-client: Fix panic upon irregular termination. + - lib-settings: Fix sorting of the settings history, which + caused changed defaults and renames to be ignored once a + plugin registered its own history, if dovecot_config_version + has been set to greater than 2.4.0. + - lib-smtp: Fix assert with an empty broken localpart. + - lib-smtp: xclient - Reject an invalid HELO parameter with + 501. + - lib-sql: pgsql - Fix binary field values for rows after the + first. This mainly affected dict-sql maps with hexblob + fields. + - lib-ssl-iostream: Fix crash at process exit with OpenSSL 4.0. + - lib-storage: Don't log an error when the client resets the + connection while saving a mail. + - lib-storage: Fix crash when reverting a failed mailbox + deletion. + - lib-storage: Fix decoded size calculation for base64 + attachments, which could delete the cache record of a mail + with a detached attachment. + - lib-storage: Fix handling escaped mailbox names in the + mailbox list index. + - lib-storage: Fix rewriting non-NFC subscriptions with mUTF-7 + storage names, which caused repeated rename errors. + - lib-storage: Fix searching flags when the view is not up to + date. This broke e.g. a pipelined UID STORE +FLAGS \Deleted + followed by UID EXPUNGE. + - lib-storage: Fix the mailbox vsize header not being repaired + when it is corrupted, causing wrong mailbox sizes to be + reported. + - lib-storage: thread - Fix panic when running IMAP THREAD in + multiple connections in parallel. lib-var-expand: Reject an + empty separator in the index filter, which caused an infinite + loop. + - lib: Fix crash and out of bounds reads when decoding IDN + addresses. Reachable only with the experimental mail UTF-8 + support enabled. + - lib: ioloop - Fix panic and delayed timeouts when time moves + forwards. + - lib: ostream-multiplex - Fix stalls, busy loops and a panic + when streaming data through a multiplexed connection, e.g. + IMAP FETCH through a login proxy or TLS connections. + login-common: Fix connection hanging if an ostream write + failed. This happened at least with HAProxy health check + connections. login-common: Fix real_remote_ip being looked up + incorrectly. login-common: Reject proxy credentials with + ASCII control characters. login-proxy: Fix "doveadm kick" for + proxied connections in high-security mode, and log "Kicked by + admin" as the reason. + - maildir: Fix random SEARCH failures when another session + concurrently expunges mails. + - quota: Fix maildir quota dropping to zero after IMAP MOVE or + REPLACE. submission-login: proxy - Fix crash and unbounded + memory usage with a multi-line or malformed AUTH reply from + the backend. +- Update dovecot-pigeonhole to 2.4.5 + - Critical vulnerabilities + - CVE-2026-33605: managesieve-login: Pre-auth crash. An ++++ 43 more lines (skipped) ++++ between /work/SRC/openSUSE:Factory/dovecot24/dovecot24.changes ++++ and /work/SRC/openSUSE:Factory/.dovecot24.new.1265/dovecot24.changes Old: ---- dovecot-2.4.4.tar.gz dovecot-2.4.4.tar.gz.sig dovecot-pigeonhole-2.4.4.tar.gz dovecot-pigeonhole-2.4.4.tar.gz.sig New: ---- dovecot-2.4.5.tar.gz dovecot-2.4.5.tar.gz.sig dovecot-pigeonhole-2.4.5.tar.gz dovecot-pigeonhole-2.4.5.tar.gz.sig ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ dovecot24.spec ++++++ --- /var/tmp/diff_new_pack.bovS3E/_old 2026-08-28 19:58:49.556978158 +0200 +++ /var/tmp/diff_new_pack.bovS3E/_new 2026-08-28 19:58:49.559978263 +0200 @@ -17,8 +17,8 @@ %define pkg_name dovecot -%define dovecot_version 2.4.4 -%define dovecot_pigeonhole_version 2.4.4 +%define dovecot_version 2.4.5 +%define dovecot_pigeonhole_version 2.4.5 %define dovecot_branch 2.4 %define dovecot_pigeonhole_source_dir %{pkg_name}-pigeonhole-%{dovecot_pigeonhole_version} %define dovecot_pigeonhole_docdir %{_docdir}/%{pkg_name}/dovecot-pigeonhole @@ -48,7 +48,7 @@ %endif Name: dovecot24 -Version: 2.4.4 +Version: 2.4.5 Release: 0 Summary: IMAP and POP3 Server Written Primarily with Security in Mind License: BSD-3-Clause AND LGPL-2.1-or-later AND MIT @@ -632,14 +632,14 @@ %{_mandir}/man1/dovecot-lda.1%{?ext_man} %{_mandir}/man1/dovecot-sysreport.1%{?ext_man} %{_mandir}/man1/dovecot.1%{?ext_man} -%{_mandir}/man1/doveadm-sieve.1%{?ext_man} -%{_mandir}/man1/sieve-dump.1%{?ext_man} -%{_mandir}/man1/sieve-filter.1%{?ext_man} -%{_mandir}/man1/sieve-test.1%{?ext_man} -%{_mandir}/man1/sievec.1%{?ext_man} +#sieve# %{_mandir}/man1/doveadm-sieve.1%{?ext_man} +#sieve# %{_mandir}/man1/sieve-dump.1%{?ext_man} +#sieve# %{_mandir}/man1/sieve-filter.1%{?ext_man} +#sieve# %{_mandir}/man1/sieve-test.1%{?ext_man} +#sieve# %{_mandir}/man1/sievec.1%{?ext_man} %{_mandir}/man1/sieved.1%{?ext_man} %{_mandir}/man7/doveadm-search-query.7%{?ext_man} -%{_mandir}/man7/pigeonhole.7%{?ext_man} +#sieve# %{_mandir}/man7/pigeonhole.7%{?ext_man} # doc %doc %{_docdir}/%{pkg_name} %if %{with solr} ++++++ dovecot-2.4.4.tar.gz -> dovecot-2.4.5.tar.gz ++++++ /work/SRC/openSUSE:Factory/dovecot24/dovecot-2.4.4.tar.gz /work/SRC/openSUSE:Factory/.dovecot24.new.1265/dovecot-2.4.5.tar.gz differ: char 12, line 1 ++++++ dovecot-pigeonhole-2.4.4.tar.gz -> dovecot-pigeonhole-2.4.5.tar.gz ++++++ ++++ 17441 lines of diff (skipped)
