From 8f69843e965e3456530aca63f0ca2cb2d7ad5bf5 Mon Sep 17 00:00:00 2001 From: AlmaLinux RelEng Bot Date: Mon, 20 Jul 2026 18:01:18 -0400 Subject: [PATCH] import Oracle_OSS dovecot-2.3.21-19.el10_2.1 --- dovecot-2.3-cve-2026-42006.patch | 101 +++++++++++++++++++++++++++++++ dovecot-2.3-ph_scriptcmp.patch | 0 dovecot.spec | 9 ++- prestartscript | 0 4 files changed, 109 insertions(+), 1 deletion(-) create mode 100644 dovecot-2.3-cve-2026-42006.patch mode change 100644 => 100755 dovecot-2.3-ph_scriptcmp.patch mode change 100644 => 100755 prestartscript diff --git a/dovecot-2.3-cve-2026-42006.patch b/dovecot-2.3-cve-2026-42006.patch new file mode 100644 index 0000000..51e6020 --- /dev/null +++ b/dovecot-2.3-cve-2026-42006.patch @@ -0,0 +1,101 @@ +From cb7b32c0b0f6b241efb2e3ff7ffcb92f41e0d1c1 Mon Sep 17 00:00:00 2001 +From: Timo Sirainen +Date: Mon, 27 Apr 2026 17:40:46 +0300 +Subject: [PATCH] lib-imap: Fix imap_parser_params.list_count_limit to actually + work + +The previous fix in d0f67b52914565a35f3817335ab9633cb291513c was +accidentally limiting the number of ')', not the number of '('. +--- + src/lib-imap/imap-parser.c | 19 +++++++++++-------- + src/lib-imap/test-imap-parser.c | 14 ++++++++++++-- + 2 files changed, 23 insertions(+), 10 deletions(-) + +diff --git a/src/lib-imap/imap-parser.c b/src/lib-imap/imap-parser.c +index 20fe7bf..3cd87ab 100644 +--- a/src/lib-imap/imap-parser.c ++++ b/src/lib-imap/imap-parser.c +@@ -191,8 +191,15 @@ static struct imap_arg *imap_arg_create(struct imap_parser *parser) + return arg; + } + +-static void imap_parser_open_list(struct imap_parser *parser) ++static bool imap_parser_open_list(struct imap_parser *parser) + { ++ if (parser->list_count >= parser->list_count_limit) { ++ parser->error_msg = "Too many '('"; ++ parser->error = IMAP_PARSE_ERROR_BAD_SYNTAX; ++ return FALSE; ++ } ++ parser->list_count++; ++ + parser->list_arg = imap_arg_create(parser); + parser->list_arg->type = IMAP_ARG_LIST; + p_array_init(&parser->list_arg->_data.list, parser->pool, +@@ -200,6 +207,7 @@ static void imap_parser_open_list(struct imap_parser *parser) + parser->cur_list = &parser->list_arg->_data.list; + + parser->cur_type = ARG_PARSE_NONE; ++ return TRUE; + } + + static bool imap_parser_close_list(struct imap_parser *parser) +@@ -217,12 +225,6 @@ static bool imap_parser_close_list(struct imap_parser *parser) + parser->error = IMAP_PARSE_ERROR_BAD_SYNTAX; + return FALSE; + } +- if (parser->list_count >= parser->list_count_limit) { +- parser->error_msg = "Too many '('"; +- parser->error = IMAP_PARSE_ERROR_BAD_SYNTAX; +- return FALSE; +- } +- parser->list_count++; + + arg = imap_arg_create(parser); + arg->type = IMAP_ARG_EOL; +@@ -673,7 +675,8 @@ static bool imap_parser_read_arg(struct imap_parser *parser) + parser->literal8 = FALSE; + break; + case '(': +- imap_parser_open_list(parser); ++ if (!imap_parser_open_list(parser)) ++ return FALSE; + if ((parser->flags & IMAP_PARSE_FLAG_STOP_AT_LIST) != 0) { + i_stream_skip(parser->input, 1); + return FALSE; +diff --git a/src/lib-imap/test-imap-parser.c b/src/lib-imap/test-imap-parser.c +index 714da4a..b1e2272 100644 +--- a/src/lib-imap/test-imap-parser.c ++++ b/src/lib-imap/test-imap-parser.c +@@ -85,9 +85,15 @@ static void test_imap_parser_list_limit(void) + struct { + const char *input; + int ret; ++ const char *error; + } tests[] = { +- { "(())\r\n", 1 }, +- { "((()))\r\n", -1 }, ++ { "(())\r\n", 1, NULL }, ++ { "((\r\n", -1, "Missing ')'" }, ++ { "(()\r\n", -1, "Missing ')'" }, ++ { "(()))\r\n", -1, "Unexpected ')'" }, ++ { "((()))\r\n", -1, "Too many '('" }, ++ { "(({10}\r\n", -2, NULL }, ++ { "((({10}\r\n", -1, "Too many '('" }, + }; + struct istream_chain *chain; + struct istream *chain_input; +@@ -112,6 +118,10 @@ static void test_imap_parser_list_limit(void) + (void)i_stream_read(chain_input); + + test_assert_cmp(imap_parser_read_args(parser, 0, 0, &args), ==, tests[i].ret); ++ if (tests[i].ret == -1) { ++ enum imap_parser_error err; ++ test_assert_strcmp_idx(imap_parser_get_error(parser, &err), tests[i].error, i); ++ } + /* skip over CRLF */ + i_stream_skip(chain_input, i_stream_get_data_size(chain_input)); + +-- +2.52.0 + diff --git a/dovecot-2.3-ph_scriptcmp.patch b/dovecot-2.3-ph_scriptcmp.patch old mode 100644 new mode 100755 diff --git a/dovecot.spec b/dovecot.spec index e53cb88..55cb9b6 100644 --- a/dovecot.spec +++ b/dovecot.spec @@ -6,7 +6,7 @@ Name: dovecot Epoch: 1 Version: 2.3.21 %global prever %{nil} -Release: 19%{?dist} +Release: 19%{?dist}.1 #dovecot itself is MIT, a few sources are PD, pigeonhole is LGPLv2 License: MIT AND LGPL-2.1-only @@ -88,6 +88,8 @@ Patch34: dovecot-2.3-cve-2026-27857p3of5.patch Patch35: dovecot-2.3-cve-2026-27857p4of5.patch # https://github.com/dovecot/pigeonhole/commit/5701db04455ee4d8e927d0b225634780a9b656b4 Patch36: dovecot-2.3-cve-2026-27857p5of5.patch +# https://github.com/dovecot/core/commit/9a0f8c1066956ea7450ca82b57f904332006a502 +Patch37: dovecot-2.3-cve-2026-42006.patch BuildRequires: gcc, gcc-c++, openssl-devel, pam-devel, zlib-devel, bzip2-devel, libcap-devel BuildRequires: libtool, autoconf, automake, pkgconfig @@ -202,6 +204,7 @@ mv dovecot-2.3-pigeonhole-%{pigeonholever} dovecot-pigeonhole %patch -P 34 -p1 -b .cve-2026-27857p3of5 %patch -P 35 -p1 -b .cve-2026-27857p4of5 %patch -P 36 -p1 -b .cve-2026-27857p5of5 +%patch -P 37 -p1 -b .cve-2026-42006 cp run-test-valgrind.supp dovecot-pigeonhole/ # valgrind would fail with shell wrapper echo "testsuite" >dovecot-pigeonhole/run-test-valgrind.exclude @@ -562,6 +565,10 @@ make check %{_libdir}/%{name}/dict/libdriver_pgsql.so %changelog +* Fri Jun 26 2026 RHEL Packaging Agent - 1:2.3.21-19.1 +- fix CVE-2026-42006: fix imap_parser list_count_limit to actually + work (RHEL-188477) + * Mon May 11 2026 Michal Hlavinka - 1:2.3.21-19 - update release for rebuild diff --git a/prestartscript b/prestartscript old mode 100644 new mode 100755