StackPatch is liveSee product

Back to CVE digest
Ubuntu USN · USN-8136-2

Dovecot regression

Published: Tue, 28 Apr 2026 12:52

CVE-2026-0394

Summary

USN-8136-1 introduced a regression in Dovecot

Details

USN-8136-1 fixed vulnerabilities in Dovecot. The update caused a regression on Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that Dovecot incorrectly handled invalid base64 SASL data. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 25.10. (CVE-2025-59028) It was discovered that Dovecot script decode2text.sh incorrectly handled zip files. An attacker could possibly use this issue to obtain sensitive information. (CVE-2025-59031) It was discovered that Dovecot incorrectly handled certain AUTHENTICATE requests. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-59032) It was discovered that Dovecot incorrectly handled certain SQL based authentication. An attacker could possibly use this issue to bypass authentication. This issue only affected Ubuntu 25.10. (CVE-2026-24031) It was discovered that Dovecot incorrectly handled certain LDAP based authentication. An attacker could possibly use this issue to bypass restrictions and allow probing of LDAP structure. This issue only affected Ubuntu 25.10. (CVE-2026-27860) It was discovered that Dovecot is vulnerable to replay attack under certain conditions. An attacker could possibly use this issue to bypass authentication. (CVE-2026-27855) It was discovered that Dovecot is vulnerable to a timing attack under certain conditions. An attacker could possibly use this issue to bypass authentication. (CVE-2026-27856) It was discovered that Dovecot incorrectly handled certain IMAP login requests. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-27857) It was discovered that Dovecot incorrectly handled certain specially crafted messages. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-27858) It was discovered that Dovecot incorrectly handled certain specially crafted mail messages. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-27859) It was discovered that Dovecot incorrectly handles file paths. A attacker could possibly use this issue to perform a path traversal and obtain or modify arbitrary files. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-0394)

Recommended actions per Ubuntu release

StackPatch playbook auto-generated per release codename and per affected package.

Ubuntu jammy

  • dovecot1:2.3.16+dfsg1-3ubuntu2.8apt_upgrade

    Standard apt upgrade. Install 1:2.3.16+dfsg1-3ubuntu2.8 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-auth-lua1:2.3.16+dfsg1-3ubuntu2.8apt_upgrade

    Standard apt upgrade. Install 1:2.3.16+dfsg1-3ubuntu2.8 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-auth-lua

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-core1:2.3.16+dfsg1-3ubuntu2.8apt_upgrade

    Standard apt upgrade. Install 1:2.3.16+dfsg1-3ubuntu2.8 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-core

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-dev1:2.3.16+dfsg1-3ubuntu2.8apt_upgrade

    Standard apt upgrade. Install 1:2.3.16+dfsg1-3ubuntu2.8 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-dev

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-gssapi1:2.3.16+dfsg1-3ubuntu2.8apt_upgrade

    Standard apt upgrade. Install 1:2.3.16+dfsg1-3ubuntu2.8 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-gssapi

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-imapd1:2.3.16+dfsg1-3ubuntu2.8apt_upgrade

    Standard apt upgrade. Install 1:2.3.16+dfsg1-3ubuntu2.8 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-imapd

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-ldap1:2.3.16+dfsg1-3ubuntu2.8apt_upgrade

    Standard apt upgrade. Install 1:2.3.16+dfsg1-3ubuntu2.8 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-ldap

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-lmtpd1:2.3.16+dfsg1-3ubuntu2.8apt_upgrade

    Standard apt upgrade. Install 1:2.3.16+dfsg1-3ubuntu2.8 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-lmtpd

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-lucene1:2.3.16+dfsg1-3ubuntu2.8apt_upgrade

    Standard apt upgrade. Install 1:2.3.16+dfsg1-3ubuntu2.8 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-lucene

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-managesieved1:2.3.16+dfsg1-3ubuntu2.8apt_upgrade

    Standard apt upgrade. Install 1:2.3.16+dfsg1-3ubuntu2.8 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-managesieved

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-mysql1:2.3.16+dfsg1-3ubuntu2.8apt_upgrade

    Standard apt upgrade. Install 1:2.3.16+dfsg1-3ubuntu2.8 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-mysql

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-pgsql1:2.3.16+dfsg1-3ubuntu2.8apt_upgrade

    Standard apt upgrade. Install 1:2.3.16+dfsg1-3ubuntu2.8 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-pgsql

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-pop3d1:2.3.16+dfsg1-3ubuntu2.8apt_upgrade

    Standard apt upgrade. Install 1:2.3.16+dfsg1-3ubuntu2.8 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-pop3d

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-sieve1:2.3.16+dfsg1-3ubuntu2.8apt_upgrade

    Standard apt upgrade. Install 1:2.3.16+dfsg1-3ubuntu2.8 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-sieve

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-solr1:2.3.16+dfsg1-3ubuntu2.8apt_upgrade

    Standard apt upgrade. Install 1:2.3.16+dfsg1-3ubuntu2.8 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-solr

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-sqlite1:2.3.16+dfsg1-3ubuntu2.8apt_upgrade

    Standard apt upgrade. Install 1:2.3.16+dfsg1-3ubuntu2.8 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-sqlite

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-submissiond1:2.3.16+dfsg1-3ubuntu2.8apt_upgrade

    Standard apt upgrade. Install 1:2.3.16+dfsg1-3ubuntu2.8 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-submissiond

    Most apt upgrades restart their service automatically. needrestart lists anything else.

Ubuntu noble

  • dovecot1:2.3.21+dfsg1-2ubuntu6.4apt_upgrade

    Standard apt upgrade. Install 1:2.3.21+dfsg1-2ubuntu6.4 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-auth-lua1:2.3.21+dfsg1-2ubuntu6.4apt_upgrade

    Standard apt upgrade. Install 1:2.3.21+dfsg1-2ubuntu6.4 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-auth-lua

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-core1:2.3.21+dfsg1-2ubuntu6.4apt_upgrade

    Standard apt upgrade. Install 1:2.3.21+dfsg1-2ubuntu6.4 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-core

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-dev1:2.3.21+dfsg1-2ubuntu6.4apt_upgrade

    Standard apt upgrade. Install 1:2.3.21+dfsg1-2ubuntu6.4 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-dev

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-gssapi1:2.3.21+dfsg1-2ubuntu6.4apt_upgrade

    Standard apt upgrade. Install 1:2.3.21+dfsg1-2ubuntu6.4 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-gssapi

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-imapd1:2.3.21+dfsg1-2ubuntu6.4apt_upgrade

    Standard apt upgrade. Install 1:2.3.21+dfsg1-2ubuntu6.4 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-imapd

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-ldap1:2.3.21+dfsg1-2ubuntu6.4apt_upgrade

    Standard apt upgrade. Install 1:2.3.21+dfsg1-2ubuntu6.4 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-ldap

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-lmtpd1:2.3.21+dfsg1-2ubuntu6.4apt_upgrade

    Standard apt upgrade. Install 1:2.3.21+dfsg1-2ubuntu6.4 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-lmtpd

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-managesieved1:2.3.21+dfsg1-2ubuntu6.4apt_upgrade

    Standard apt upgrade. Install 1:2.3.21+dfsg1-2ubuntu6.4 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-managesieved

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-mysql1:2.3.21+dfsg1-2ubuntu6.4apt_upgrade

    Standard apt upgrade. Install 1:2.3.21+dfsg1-2ubuntu6.4 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-mysql

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-pgsql1:2.3.21+dfsg1-2ubuntu6.4apt_upgrade

    Standard apt upgrade. Install 1:2.3.21+dfsg1-2ubuntu6.4 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-pgsql

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-pop3d1:2.3.21+dfsg1-2ubuntu6.4apt_upgrade

    Standard apt upgrade. Install 1:2.3.21+dfsg1-2ubuntu6.4 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-pop3d

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-sieve1:2.3.21+dfsg1-2ubuntu6.4apt_upgrade

    Standard apt upgrade. Install 1:2.3.21+dfsg1-2ubuntu6.4 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-sieve

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-solr1:2.3.21+dfsg1-2ubuntu6.4apt_upgrade

    Standard apt upgrade. Install 1:2.3.21+dfsg1-2ubuntu6.4 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-solr

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-sqlite1:2.3.21+dfsg1-2ubuntu6.4apt_upgrade

    Standard apt upgrade. Install 1:2.3.21+dfsg1-2ubuntu6.4 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-sqlite

    Most apt upgrades restart their service automatically. needrestart lists anything else.

  • dovecot-submissiond1:2.3.21+dfsg1-2ubuntu6.4apt_upgrade

    Standard apt upgrade. Install 1:2.3.21+dfsg1-2ubuntu6.4 from the apt repo.

    sudo apt-get update
    sudo apt-get install --only-upgrade -y dovecot-submissiond

    Most apt upgrades restart their service automatically. needrestart lists anything else.

Are YOU affected by USN-8136-2?

5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether USN-8136-2 (and any other live CVE) applies. Anonymous, no signup.

curl https://mindsparkstack.com/scan.sh | bash

References

Want this automated for your servers?

StackPatch runs this match against YOUR installed packages every hour

Free 1-server / $99 lifetime founder seat (50 only) / $19+/mo monthly. Indie pricing.