Hi Edmund,

On Thu, Sep 10, 2026 at 01:45:31PM +0200, Edmund Lodewijks wrote:
> Package: release.debian.org
> Severity: normal
> Tags: trixie
> User: [email protected]
> Usertags: pu
> 
> Please consider cyrus-imapd 3.10.2-1+deb13u3 for trixie.
> 
> This stacks on top of the already-accepted 3.10.2-1+deb13u2 (ack'ed
> by Adam D. Barratt on bug #1142925, accepted into proposed-updates
> on 2026-09-05, still awaiting the next point release). This does not
> replace or conflict with it.
> 
> It backports six new CVEs fixed upstream in 3.10.4, none of which
> overlap with the CVE-2026-47081..47089 batch already in deb13u2:
> 
>   * CVE-2026-61907: JMAP snooze bypassed the destination mailbox's
>     ACL, letting a sharee insert mail into mailboxes they had no
>     insert rights on.
>   * CVE-2026-61908: heap out-of-bounds read via a crafted JMAP
>     email-header blob ID index.
>   * CVE-2026-61909: CalDAV/CardDAV multiget did not check per-href
>     ACLs, letting a partially-shared user read unshared events or
>     contacts.
>   * CVE-2026-61910: Mailbox/set let a sharee with maySetKeywords
>     change a shared mailbox's special-use role.
>   * CVE-2026-61911: Sieve mailboxexists/metadata let a script probe
>     another user's mailbox existence or read shared annotations.
>   * CVE-2026-61915: double-free in VPATCH BYPARAM handling could
>     crash a CalDAV worker.
> 
> The debdiff also includes one small, non-CVE fix: a pre-existing
> double-free in ical_support.c's parameter cleanup (present since at
> least 3.10.2), needed for the CVE-2026-61915 upstream regression test
> to actually pass. No code path previously exercised it. Fixed
> upstream in commit 4f9fd773047cb8d2f73b00cee4bc2adc1893fb65.
> 
> Built and tested clean via sbuild against a local stable chroot;
> lintian warnings are pre-existing and unrelated to this diff. debdiff
> attached below.

FWIW, before this can be accepted for trixie the issues need to be
fixed as well in unstable, I see it is pending in the packaging
repository by Xavier, so I guess an upload is imminent as well?

Regards,
Salvatore

Reply via email to