SB20260921170 - SUSE update for dovecot22



SB20260921170 - SUSE update for dovecot22

Published: September 21, 2026

Security Bulletin ID SB20260921170
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Resource exhaustion (CVE-ID: CVE-2026-40016)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the Sieve substring matching implementation when processing a malicious Sieve script. A remote user can upload a malicious Sieve script to cause a denial of service.

The script can be uploaded over the ManageSieve service or through local access, and the issue can bypass configured CPU time limits for Sieve by up to 130 times.


Remediation

Install update from vendor's website.