Re: Safe upgrade path from 2.4.1 to 2.4.4 (CVE-2026-40020) on Debian 13
Tóth Attila via dovecot <[email protected]>
| Newsgroups | gmane.mail.imap.dovecot |
|---|---|
| Message-ID | <[email protected]> |
Hi Artem Ignatov, On 2026.08.21 12:06, Artem Ignatov via dovecot wrote: > Hello, > > (Redirected here from [email protected] - I understand that address > is > for commercial/Pro support, and this is a Community Edition question.) > > We run a production mail server on Debian GNU/Linux 13 (trixie), using > the > Dovecot package currently shipped in the Debian 13 stable repository: > > dovecot-core 1:2.4.1+dfsg1-6+deb13u6 > > We are affected by CVE-2026-40020 ("IMAP folders can be shared-spammed > to > everyone"), which as far as we understand is fixed upstream in Dovecot > 2.4.4. Debian 13 stable does not yet ship a backported fix, so we are > currently working around the issue by not using shared/ACL mailbox > access > at all, and waiting for an official Debian security update. https://security-tracker.debian.org/tracker/CVE-2026-40020 According to Debian's Security database, it says trixie (security) 1:2.4.1+dfsg1-6+deb13u6 has this fixed I appreciate Debian Security pages directly linking the exact commits. Browse to https://packages.debian.org/trixie/dovecot-core (right side pane it has a link for the original source and the Debian additions) and download: http://deb.debian.org/debian/pool/main/d/dovecot/dovecot_2.4.1+dfsg1-6+deb13u6.debian.tar.xz You can inspect the Debian specific package contents, especially the directory: debian/patches, where there are exact patches for the CVE and included in debian/patches/series. So applied during package creation. Actually it is a three piece patch set as it is listed among the referenced commits on the bottom of their CVE page. So if you are using dovecot-core (1:2.4.1+dfsg1-6+deb13u6), consider this CVE fixed for your version. If you are still able to trigger the bug, despite of the above mentioned references, you should file a bug report. I'm currently not primarily a Debian user (it was the first distro I used for several years before 2002), but often rely on their information and sometimes use patches to fix security issues outside of the Debian ecosystem. Although rarely there are some mishaps, but it is reliable. BR: Dw. > > We would appreciate the community's guidance on a few points: > > 1. Is a safe, supported upgrade path from 2.4.1 to 2.4.4 recommended > for a > production instance currently installed from Debian's own package > (rather than compiling from source or using a third-party > repository)? > > 2. Are there any breaking changes between 2.4.1 and 2.4.4 we should be > aware of - configuration syntax, Maildir index file format > compatibility, > or anything that would require downtime or re-indexing on a live > mail > store? > > 3. Our setup uses SQL-based virtual users/passdb (via > PostfixAdmin/MySQL), > Sieve filtering, and per-user quotas. Are there any known > interactions > between these features and the 2.4.4 update that we should test for > before rolling it out? > > 4. Do you have a general recommendation on whether to wait for the > Debian > security team to backport the fix into 13 stable, versus updating > manually ahead of that? > > Any guidance, or a pointer to relevant release notes/changelog entries > between 2.4.1 and 2.4.4, would be very helpful. > > Thank you, > Artem Ignatov > IT Administrator, GK INVEST > > _______________________________________________ > dovecot mailing list -- [email protected] > To unsubscribe send an email to [email protected] -- dr Tóth Attila, Radiológus, 06-20-825-8057 Attila Toth MD, Radiologist, +36-20-825-8057 _______________________________________________ dovecot mailing list -- [email protected] To unsubscribe send an email to [email protected]