StackPatch is liveSee product

Back to CVE digest
CVE-2026-0394 · cross-distro fix matrix

CVE-2026-0394: USN-8136-1 fixed vulnerabilities in Dovecot. The update caused a regression

Affects 5 Linux releases across 36 (distro × package) combinations. First disclosed: 2026-04-28.

Fix per ecosystem

Each block below is a distro release where CVE-2026-0394 has a known fix. Run the listed command on that distro to remediate.

Ubuntu jammy

Source: Ubuntu USN

  • dovecot→ fixed in1:2.3.16+dfsg1-3ubuntu2.8USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot
  • dovecot-auth-lua→ fixed in1:2.3.16+dfsg1-3ubuntu2.8USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-auth-lua
  • dovecot-core→ fixed in1:2.3.16+dfsg1-3ubuntu2.8USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-core
  • dovecot-dev→ fixed in1:2.3.16+dfsg1-3ubuntu2.8USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-dev
  • dovecot-gssapi→ fixed in1:2.3.16+dfsg1-3ubuntu2.8USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-gssapi
  • dovecot-imapd→ fixed in1:2.3.16+dfsg1-3ubuntu2.8USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-imapd
  • dovecot-ldap→ fixed in1:2.3.16+dfsg1-3ubuntu2.8USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-ldap
  • dovecot-lmtpd→ fixed in1:2.3.16+dfsg1-3ubuntu2.8USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-lmtpd
  • dovecot-lucene→ fixed in1:2.3.16+dfsg1-3ubuntu2.8USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-lucene
  • dovecot-managesieved→ fixed in1:2.3.16+dfsg1-3ubuntu2.8USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-managesieved
  • dovecot-mysql→ fixed in1:2.3.16+dfsg1-3ubuntu2.8USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-mysql
  • dovecot-pgsql→ fixed in1:2.3.16+dfsg1-3ubuntu2.8USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-pgsql
  • dovecot-pop3d→ fixed in1:2.3.16+dfsg1-3ubuntu2.8USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-pop3d
  • dovecot-sieve→ fixed in1:2.3.16+dfsg1-3ubuntu2.8USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-sieve
  • dovecot-solr→ fixed in1:2.3.16+dfsg1-3ubuntu2.8USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-solr
  • dovecot-sqlite→ fixed in1:2.3.16+dfsg1-3ubuntu2.8USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-sqlite
  • dovecot-submissiond→ fixed in1:2.3.16+dfsg1-3ubuntu2.8USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-submissiond

Ubuntu noble

Source: Ubuntu USN

  • dovecot→ fixed in1:2.3.21+dfsg1-2ubuntu6.4USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot
  • dovecot-auth-lua→ fixed in1:2.3.21+dfsg1-2ubuntu6.4USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-auth-lua
  • dovecot-core→ fixed in1:2.3.21+dfsg1-2ubuntu6.4USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-core
  • dovecot-dev→ fixed in1:2.3.21+dfsg1-2ubuntu6.4USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-dev
  • dovecot-gssapi→ fixed in1:2.3.21+dfsg1-2ubuntu6.4USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-gssapi
  • dovecot-imapd→ fixed in1:2.3.21+dfsg1-2ubuntu6.4USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-imapd
  • dovecot-ldap→ fixed in1:2.3.21+dfsg1-2ubuntu6.4USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-ldap
  • dovecot-lmtpd→ fixed in1:2.3.21+dfsg1-2ubuntu6.4USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-lmtpd
  • dovecot-managesieved→ fixed in1:2.3.21+dfsg1-2ubuntu6.4USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-managesieved
  • dovecot-mysql→ fixed in1:2.3.21+dfsg1-2ubuntu6.4USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-mysql
  • dovecot-pgsql→ fixed in1:2.3.21+dfsg1-2ubuntu6.4USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-pgsql
  • dovecot-pop3d→ fixed in1:2.3.21+dfsg1-2ubuntu6.4USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-pop3d
  • dovecot-sieve→ fixed in1:2.3.21+dfsg1-2ubuntu6.4USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-sieve
  • dovecot-solr→ fixed in1:2.3.21+dfsg1-2ubuntu6.4USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-solr
  • dovecot-sqlite→ fixed in1:2.3.21+dfsg1-2ubuntu6.4USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-sqlite
  • dovecot-submissiond→ fixed in1:2.3.21+dfsg1-2ubuntu6.4USN-8136-2
    sudo apt-get install --only-upgrade -y dovecot-submissiond

Debian bullseye

Source: Debian Security Tracker

  • dovecot→ fixed in1:2.3.13+dfsg1-2+deb11u3urgency: not yet assigned
    sudo apt-get install --only-upgrade -y dovecot

Debian bookworm

Source: Debian Security Tracker

  • dovecot→ fixed in1:2.3.19.1+dfsg1-2.1+deb12u2urgency: not yet assigned
    sudo apt-get install --only-upgrade -y dovecot

Debian trixie

Source: Debian Security Tracker

  • dovecot→ fixed in1:2.4.1+dfsg1-1urgency: not yet assigned
    sudo apt-get install --only-upgrade -y dovecot
Are YOU affected by CVE-2026-0394?

5-second check on your actual server. Reads /etc/os-release, uname -r, and the distro's package manager; matches against this same cross-source index live.

curl https://mindsparkstack.com/scan.sh | bash
Continuous monitoring beats manual checking

CVE-2026-0394dropped silently in your distro's update channel. Every new CVE is the same story. StackPatch runs the matcher hourly against all 5 sources and emails the exact remediation when something new applies to one of your servers. $99 lifetime, 50 founder seats, 30-day refund.

See StackPatch ($99 lifetime)