-
Fri Jun 26 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 1:2.3.21-19.1
- fix CVE-2026-42006: fix imap_parser list_count_limit to actually
work (RHEL-188477)
-
Mon May 11 2026 Michal Hlavinka <mhlavink@redhat.com> - 1:2.3.21-19
- update release for rebuild
-
Thu Apr 30 2026 Michal Hlavinka <mhlavink@redhat.com> - 1:2.3.21-18
- fix CVE-2026-27858: denial of service via crafted message before authentication (RHEL-161626)
- fix CVE-2025-59032: ManageSieve: Denial of Service via crafted SASL initial response in AUTHENTICATE command (RHEL-162274)
- fix CVE-2026-27857: denial of service via specially crafted NOOP command (RHEL-161665)
-
Mon Jan 12 2026 Michal Hlavinka <mhlavink@redhat.com> - 1:2.3.21-17
- fix building with latest openssl (RHEL-117460)
- add /var/lib/dovecot to tmpfiles for image mode (RHEL-130953)
-
Wed Feb 05 2025 Michal Hlavinka <mhlavink@redhat.com> - 1:2.3.21-16
- fix sysusers config file name (RHEL-77323)
-
Tue Oct 29 2024 Troy Dawson <tdawson@redhat.com> - 1:2.3.21-15
- Bump release for October 2024 mass rebuild:
Resolves: RHEL-64018
-
Tue Aug 20 2024 Michal Hlavinka <mhlavink@redhat.com> - 1:2.3.21-14
- fix CVE-2024-23185: very large headers can cause resource exhaustion
when parsing message (RHEL-55218)
- fix CVE-2024-23184: using a large number of address headers may trigger
a denial of service (RHEL-55205)
-
Mon Aug 05 2024 Michal Hlavinka <mhlavink@redhat.com> - 1:2.3.21-13
- fix crash when user has sieve script that includes two missing scripts (RHEL-52541)
-
Tue Jul 23 2024 Michal Hlavinka <mhlavink@redhat.com> - 1:2.3.21-12
- fix building with noengine openssl
-
Mon Jun 24 2024 Troy Dawson <tdawson@redhat.com> - 1:2.3.21-11
- Bump release for June 2024 mass rebuild