Back to Security Advisories
High 2026-07-22

Dovecot Security Update — AlmaLinux 9 (ALSA-2026:41905)

AlmaLinux 9

Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages. Security Fix(es): * dovecot: Dove…

Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages.

Security Fix(es):

* dovecot: Dove…

Type:
security

Severity:
important

Release date:
2026-07-22

Description:
Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages.

Security Fix(es):

* dovecot: Dovecot: Denial of Service via excessive IMAP bracing (CVE-2026-42006)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 dovecot-devel-2.3.16-18.el9_8.1.aarch64.rpm 4eac150ea9102cc32fe3a2c3a504475b483568324cd8769cd2d044f0a9eee6b7
aarch64 dovecot-2.3.16-18.el9_8.1.aarch64.rpm a1a07d7b23c17ee7d4b18f86cd2e97cca9f7d6fb3a3cfc63b4ffc8a376eea5b9
aarch64 dovecot-pgsql-2.3.16-18.el9_8.1.aarch64.rpm a88a465177e0038c973aa9e90638d31a81d6443ba9d642af267c58fde5bdeb4f
aarch64 dovecot-mysql-2.3.16-18.el9_8.1.aarch64.rpm aa02f39d17b4d2c7737c6cfd1e7326f9acd5adefa3a9db84ce0423e8bdfc8917
aarch64 dovecot-pigeonhole-2.3.16-18.el9_8.1.aarch64.rpm e83b0aa9c51d76c8266092caeda3e7be478c93644bc9ee9d101498629f29db7c
i686 dovecot-2.3.16-18.el9_8.1.i686.rpm c98bb9bc75283c66d378fe674e94c8e4a1487e7808c67f11ca425677c895334a
i686 dovecot-devel-2.3.16-18.el9_8.1.i686.rpm de03e0b66934163a55dd327d58ecb207444fbbd6b584cc5c876eac65570c741b
ppc64le dovecot-mysql-2.3.16-18.el9_8.1.ppc64le.rpm 34837671460743f3ac911c81bf09a49080534044a4c98a50a65003c6b9b955c8
ppc64le dovecot-2.3.16-18.el9_8.1.ppc64le.rpm 7026c7b4f07bb583d462c68123e301ccd7825ca600758afca7ea53af45fbc68f
ppc64le dovecot-devel-2.3.16-18.el9_8.1.ppc64le.rpm e57ad42e861938611d2cbb1f3cb04580d74a21087fe356f8e9d1e643d69be14d
ppc64le dovecot-pgsql-2.3.16-18.el9_8.1.ppc64le.rpm efef5a40e20dcd815486936bd89ee6790cfb876df6cb0110d7683d184aa4aefc
ppc64le dovecot-pigeonhole-2.3.16-18.el9_8.1.ppc64le.rpm f4d40e1c63117ae0bd60a782fe2d012d51f6232d28656849869ada7b068d600f
s390x dovecot-2.3.16-18.el9_8.1.s390x.rpm 5d1d5b692c2080b459e9a627fc70626a88f3f42e7e8a4ba990f286663cca62aa
s390x dovecot-mysql-2.3.16-18.el9_8.1.s390x.rpm 7ade807831d238e8e236bb0e5adcffb6fa4fcd4f63e612b3c737350db29ccbfd
s390x dovecot-devel-2.3.16-18.el9_8.1.s390x.rpm 7d93631184b1b7985b97b93f8a14ea05babb9d9c8f5d7fae0c5d135030c9fd94
s390x dovecot-pgsql-2.3.16-18.el9_8.1.s390x.rpm a9fdb653ac9e4101be32093c2455621f06f3841c56bc3de14b64492ff020d2ce
s390x dovecot-pigeonhole-2.3.16-18.el9_8.1.s390x.rpm c95b48379c9dadd0d00e7037898e5651e57574371800440c60f8c0cc610f6d97
x86_64 dovecot-devel-2.3.16-18.el9_8.1.x86_64.rpm 118f613025ffd2681ecec939b0c8b4e02661730c6d5f33fdf3234668c2ce7c4c
x86_64 dovecot-2.3.16-18.el9_8.1.x86_64.rpm 3857511d951ebfda475568c8de73d6d7e44d4092a077eebe8506613261c91887
x86_64 dovecot-pigeonhole-2.3.16-18.el9_8.1.x86_64.rpm 5c29f5231102d93c4c6169206ff9651e87eb5472adbcf09f6161be560c23b0ff
x86_64 dovecot-mysql-2.3.16-18.el9_8.1.x86_64.rpm 778ecbf7a39d65068dbfbd1f3801a3c0ecc2cb41fe5ba4a2d217102a91c0d6b2
x86_64 dovecot-pgsql-2.3.16-18.el9_8.1.x86_64.rpm ce06a0bcd372816d8e2a477b7fa11972aba4cd64b67cfa3a77a9993555caa58b

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System