Debian dsa-6526 : dovecot-auth-lua - security update

critical Nessus Plugin ID 350920

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 13 host has packages installed that are affected by multiple vulnerabilities as referenced in the dsa-6526 advisory.

- ------------------------------------------------------------------------- Debian Security Advisory DSA-6526-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff September 28, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : dovecot CVE ID : CVE-2026-27852 CVE-2026-33263 CVE-2026-33604 CVE-2026-33605 CVE-2026-33606 CVE-2026-33607 CVE-2026-40013 CVE-2026-40014 CVE-2026-40015 CVE-2026-40017 CVE-2026-40018 CVE-2026-40203 CVE-2026-40204 CVE-2026-40205 CVE-2026-42007 CVE-2026-42008 CVE-2026-42391 CVE-2026-42392 CVE-2026-42393 CVE-2026-42394 CVE-2026-42395 CVE-2026-52681 CVE-2026-52687 CVE-2026-73208 CVE-2026-73209 Debian Bug : 1144639

Multiple vulnerabilities have been discovered in the Dovecot IMAP server which could result in denial of service, SMTP smuggling, information disclosure, code injection via malformed Sieve scripts or bypass of ACL restrictions.

For the stable distribution (trixie), these problems have been fixed in version 1:2.4.1+dfsg1-6+deb13u7.

We recommend that you upgrade your dovecot packages.

For the detailed security status of dovecot please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/dovecot

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/

Mailing list: [email protected]

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the dovecot-auth-lua packages.

See Also

https://packages.debian.org/source/trixie/dovecot

https://security-tracker.debian.org/tracker/CVE-2026-27852

https://security-tracker.debian.org/tracker/CVE-2026-33263

https://security-tracker.debian.org/tracker/CVE-2026-33604

https://security-tracker.debian.org/tracker/CVE-2026-33605

https://security-tracker.debian.org/tracker/CVE-2026-33606

https://security-tracker.debian.org/tracker/CVE-2026-33607

https://security-tracker.debian.org/tracker/CVE-2026-40013

https://security-tracker.debian.org/tracker/CVE-2026-40014

https://security-tracker.debian.org/tracker/CVE-2026-40015

https://security-tracker.debian.org/tracker/CVE-2026-40017

https://security-tracker.debian.org/tracker/CVE-2026-40018

https://security-tracker.debian.org/tracker/CVE-2026-40203

https://security-tracker.debian.org/tracker/CVE-2026-40204

https://security-tracker.debian.org/tracker/CVE-2026-40205

https://security-tracker.debian.org/tracker/CVE-2026-42007

https://security-tracker.debian.org/tracker/CVE-2026-42008

https://security-tracker.debian.org/tracker/CVE-2026-42391

https://security-tracker.debian.org/tracker/CVE-2026-42392

https://security-tracker.debian.org/tracker/CVE-2026-42393

https://security-tracker.debian.org/tracker/CVE-2026-42394

https://security-tracker.debian.org/tracker/CVE-2026-42395

https://security-tracker.debian.org/tracker/CVE-2026-52681

https://security-tracker.debian.org/tracker/CVE-2026-52687

https://security-tracker.debian.org/tracker/CVE-2026-73208

https://security-tracker.debian.org/tracker/CVE-2026-73209

https://security-tracker.debian.org/tracker/source-package/dovecot

Plugin Details

Severity: Critical

ID: 350920

File Name: debian_DSA-6526.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/29/2026

Updated: 9/29/2026

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.3

CVSS v2

Risk Factor: High

Base Score: 8

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:C

CVSS Score Source: CVE-2026-42007

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:13.0, p-cpe:/a:debian:debian_linux:dovecot-auth-lua, p-cpe:/a:debian:debian_linux:dovecot-core, p-cpe:/a:debian:debian_linux:dovecot-dev, p-cpe:/a:debian:debian_linux:dovecot-flatcurve, p-cpe:/a:debian:debian_linux:dovecot-gssapi, p-cpe:/a:debian:debian_linux:dovecot-imapd, p-cpe:/a:debian:debian_linux:dovecot-ldap, p-cpe:/a:debian:debian_linux:dovecot-lmtpd, p-cpe:/a:debian:debian_linux:dovecot-managesieved, p-cpe:/a:debian:debian_linux:dovecot-mysql, p-cpe:/a:debian:debian_linux:dovecot-pgsql, p-cpe:/a:debian:debian_linux:dovecot-pop3d, p-cpe:/a:debian:debian_linux:dovecot-sieve, p-cpe:/a:debian:debian_linux:dovecot-solr, p-cpe:/a:debian:debian_linux:dovecot-sqlite, p-cpe:/a:debian:debian_linux:dovecot-submissiond

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 8/28/2026

Reference Information

CVE: CVE-2026-27852, CVE-2026-33263, CVE-2026-33604, CVE-2026-33605, CVE-2026-33606, CVE-2026-33607, CVE-2026-40013, CVE-2026-40014, CVE-2026-40015, CVE-2026-40017, CVE-2026-40018, CVE-2026-40203, CVE-2026-40204, CVE-2026-40205, CVE-2026-42007, CVE-2026-42008, CVE-2026-42391, CVE-2026-42392, CVE-2026-42393, CVE-2026-42394, CVE-2026-42395, CVE-2026-52681, CVE-2026-52687, CVE-2026-73208, CVE-2026-73209