Hi Edmund, On Thu, Sep 10, 2026 at 01:45:31PM +0200, Edmund Lodewijks wrote: > Package: release.debian.org > Severity: normal > Tags: trixie > User: [email protected] > Usertags: pu > > Please consider cyrus-imapd 3.10.2-1+deb13u3 for trixie. > > This stacks on top of the already-accepted 3.10.2-1+deb13u2 (ack'ed > by Adam D. Barratt on bug #1142925, accepted into proposed-updates > on 2026-09-05, still awaiting the next point release). This does not > replace or conflict with it. > > It backports six new CVEs fixed upstream in 3.10.4, none of which > overlap with the CVE-2026-47081..47089 batch already in deb13u2: > > * CVE-2026-61907: JMAP snooze bypassed the destination mailbox's > ACL, letting a sharee insert mail into mailboxes they had no > insert rights on. > * CVE-2026-61908: heap out-of-bounds read via a crafted JMAP > email-header blob ID index. > * CVE-2026-61909: CalDAV/CardDAV multiget did not check per-href > ACLs, letting a partially-shared user read unshared events or > contacts. > * CVE-2026-61910: Mailbox/set let a sharee with maySetKeywords > change a shared mailbox's special-use role. > * CVE-2026-61911: Sieve mailboxexists/metadata let a script probe > another user's mailbox existence or read shared annotations. > * CVE-2026-61915: double-free in VPATCH BYPARAM handling could > crash a CalDAV worker. > > The debdiff also includes one small, non-CVE fix: a pre-existing > double-free in ical_support.c's parameter cleanup (present since at > least 3.10.2), needed for the CVE-2026-61915 upstream regression test > to actually pass. No code path previously exercised it. Fixed > upstream in commit 4f9fd773047cb8d2f73b00cee4bc2adc1893fb65. > > Built and tested clean via sbuild against a local stable chroot; > lintian warnings are pre-existing and unrelated to this diff. debdiff > attached below.
FWIW, before this can be accepted for trixie the issues need to be fixed as well in unstable, I see it is pending in the packaging repository by Xavier, so I guess an upload is imminent as well? Regards, Salvatore

