[El-errata] ELSA-2026-76763 Important: Oracle Linux 8 dovecot security, bug fix, and enhancement update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Wed Oct 7 18:10:59 UTC 2026


Oracle Linux Security Advisory ELSA-2026-76763

http://linux.oracle.com/errata/ELSA-2026-76763.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
dovecot-2.3.16-16.el8_10.i686.rpm
dovecot-2.3.16-16.el8_10.x86_64.rpm
dovecot-devel-2.3.16-16.el8_10.i686.rpm
dovecot-devel-2.3.16-16.el8_10.x86_64.rpm
dovecot-mysql-2.3.16-16.el8_10.x86_64.rpm
dovecot-pgsql-2.3.16-16.el8_10.x86_64.rpm
dovecot-pigeonhole-2.3.16-16.el8_10.x86_64.rpm

aarch64:
dovecot-2.3.16-16.el8_10.aarch64.rpm
dovecot-devel-2.3.16-16.el8_10.aarch64.rpm
dovecot-mysql-2.3.16-16.el8_10.aarch64.rpm
dovecot-pgsql-2.3.16-16.el8_10.aarch64.rpm
dovecot-pigeonhole-2.3.16-16.el8_10.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/dovecot-2.3.16-16.el8_10.src.rpm

Related CVEs:

CVE-2026-27852
CVE-2026-33263
CVE-2026-33605
CVE-2026-40018
CVE-2026-40019
CVE-2026-42007
CVE-2026-42391
CVE-2026-73208




Description of changes:

[1:2.3.16-15]
- fix CVE-2026-33605: ManageSieve login deadlock caused by lone CR
  protocol violation (RHEL-251995)

[1:2.3.16-14]
- fix CVE-2026-42007: heap use-after-free in pigeonhole edit_mail_snapshot
  after deleteheader operation (RHEL-251946)

[1:2.3.16-13]
- fix CVE-2026-40018: incorrect escaping of multi-byte strings in SQL commands (RHEL-252064)

[1:2.3.16-13]
- fix CVE-2026-42391: pre-auth CPU/memory amplification via
  excessive ID command key/value pairs (RHEL-252056)

[1:2.3.16-12]
- fix CVE-2026-73208: OAuth2 scope check requires all configured scopes, add oauth2_audience setting (RHEL-251905)

[1:2.3.16-11]
- fix CVE-2026-27852: denial of service via memory exhaustion from
  crafted message headers (RHEL-251573)

[1:2.3.16-10]
- fix CVE-2026-33263: submission-login panic at
  mail_max_userip_connections limit (RHEL-251922)

[1:2.3.16-9]
- fix mailbox leak causing assert crash (RHEL-176273)




More information about the El-errata mailing list