Alpine: multiple dovecot packages: security update to 2.4.5-r0

critical Tenable Self-Hosted Container Security Plugin ID 446515

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a
use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the
delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery,
which can crash the delivery process and may allow execution of arbitrary code in the context of that
process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available
exploits are known. (CVE-2026-42007)

- An attacker that can send mail to a user can craft a message whose headers contain a very large number of
email addresses or MIME parameters, which causes excessive memory usage when the message is later parsed.
The message is still delivered, but reading it over IMAP can exhaust the memory limit of the process and
terminate it, causing denial of service for the affected user. Update to non-vulnerable version. No
publicly available exploits are known. (CVE-2026-27852)

- When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll()
panic caused by file descriptor handling issues. If running in high-security mode (default for community
releases), only the new submission connection gets terminated. If running in high-performance mode
(default for Pro releases), all connections handled by the submission-login process will be terminated.
The crashes can cause failure for user to send a message, or it can cause duplicate messages to be sent.
If TLS is not used (in the backend server processing the submission), duplicate deliveries cannot happen,
because the crash can only happen at AUTH stage. Limit the number of connections handled by single
submission-login process. This has a performance impact though. Update to non-vulnerable version. No
publicly available exploits are known. (CVE-2026-33263)

- An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission
relay, can use a crafted line ending in the message body to bypass the outbound protection that prevents
message content from being interpreted as SMTP commands. A downstream mail server that hasn't yet fixed
the SMTP smuggling vulnerability can be tricked into treating part of the message body as new SMTP
commands, allowing injection of spoofed email. This is the same vulnerability class as CVE-2023-51764 and
CVE-2023-51766. Where you control the receiving mail servers, ensure they reject bare carriage returns in
message data. Update to non-vulnerable version. No publicly available exploits are known. (CVE-2026-33604)

- An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command
before authenticating. If running in high-security mode (default for community releases), only the
attacker's own connection is terminated. If running in high-performance mode (default for Pro releases),
all connections handled by the same managesieve-login process are terminated. Repeating the attack can
cause denial of service for Sieve script management. Restrict network access to the ManageSieve service to
trusted clients. Update to non-vulnerable version. No publicly available exploits are known.
(CVE-2026-33605)

Solution

Update the dovecot library and its related packages to version 2.4.5-r0 or later.

See Also

https://security.alpinelinux.org/vuln/CVE-2026-27852

https://security.alpinelinux.org/vuln/CVE-2026-33263

https://security.alpinelinux.org/vuln/CVE-2026-33604

https://security.alpinelinux.org/vuln/CVE-2026-33605

https://security.alpinelinux.org/vuln/CVE-2026-33606

https://security.alpinelinux.org/vuln/CVE-2026-33607

https://security.alpinelinux.org/vuln/CVE-2026-40014

https://security.alpinelinux.org/vuln/CVE-2026-40015

https://security.alpinelinux.org/vuln/CVE-2026-40017

https://security.alpinelinux.org/vuln/CVE-2026-40019

https://security.alpinelinux.org/vuln/CVE-2026-40203

https://security.alpinelinux.org/vuln/CVE-2026-40205

https://security.alpinelinux.org/vuln/CVE-2026-42007

https://security.alpinelinux.org/vuln/CVE-2026-42391

https://security.alpinelinux.org/vuln/CVE-2026-42392

https://security.alpinelinux.org/vuln/CVE-2026-42393

https://security.alpinelinux.org/vuln/CVE-2026-42395

https://security.alpinelinux.org/vuln/CVE-2026-52681

https://security.alpinelinux.org/vuln/CVE-2026-52687

https://security.alpinelinux.org/vuln/CVE-2026-73208

https://security.alpinelinux.org/vuln/CVE-2026-73209

Plugin Details

Severity: Critical

ID: 446515

Version: Revision 1.1

Type: Local

Published: 8/29/2026

Updated: 8/29/2026

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.48

CVSS v2

Risk Factor: High

Base Score: 8

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:C

CVSS Score Source: CVE-2026-42007

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/28/2026

Reference Information

CVE: CVE-2026-27852, CVE-2026-33263, CVE-2026-33604, CVE-2026-33605, CVE-2026-33606, CVE-2026-33607, CVE-2026-40014, CVE-2026-40015, CVE-2026-40017, CVE-2026-40019, CVE-2026-40203, CVE-2026-40205, CVE-2026-42007, CVE-2026-42391, CVE-2026-42392, CVE-2026-42393, CVE-2026-42395, CVE-2026-52681, CVE-2026-52687, CVE-2026-73208, CVE-2026-73209