|
|
Log in / Subscribe / Register

SUSE alert openSUSE-SU-2026:20962-1 (cyrus-imapd)

From:  null@suse.de
To:  security-announce@lists.opensuse.org
Subject:  openSUSE-SU-2026:20962-1: important: Security update for cyrus-imapd
Date:  Mon, 15 Jun 2026 17:51:19 +0200
Message-ID:  <20260615155119.5AADBFCE1@maintenance.suse.de>
Archive-link:  Article

openSUSE security update: security update for cyrus-imapd ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20962-1 Rating: important References: * bsc#1241536 * bsc#1241543 * bsc#1246165 * bsc#1251788 Cross-References: * CVE-2025-23394 * CVE-2025-49812 CVSS scores: * CVE-2025-49812 ( SUSE ): 7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L * CVE-2025-49812 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 4 bug fixes can now be installed. Description: This update for cyrus-imapd fixes the following issues: Changes in cyrus-imapd: - cyrus-imapd don't start because of missing "Requires=var-run.mount" from systemd (bsc#1251788) Remove var-run.mount from Requires and After - update to version 3.8.6 (bugfix release) VUL-0: CVE-2025-49812: cyrus-imapd: Opossum Attack Application Layer Desynchronization using Opportunistic TLS (bsc#1246165) The industry is deprecating STARTTLS (aka opportunistic TLS) in favor of implicit TLS over a dedicated port. STARTTLS is now disabled by default. * Fixed issue #5477: master: tighten up pidfile/etc handling (bsc#1241543) VUL-0: cyrus-imapd: privilege drop happens too late, opening attack vectors from cyrus to root * Fixed issue #5450: fix zoneinfo_db code for GCC 15 (thanks Yadd) * Fixed issue #5309: deadlock on shutdown (thanks Mark Cammidge) * Fixed issue #5424: recognise service-specific SASL options in ``cyr_info conf-lint`` * Fixed issue #5420: fix double-free in http_admin (thanks Wolfgang Breyha) * Fixed issue #5460: pop3d: add basic prometheus support (thanks Wolfgang Breyha) * Fixed issue #5454: httpd fails to parse OpenSSL version for status string - update to version 3.8.5 (bugfix release) * Fixed Issue #5029: check for unexpected extra tiny-tests directories * Fixed Issue #5148: added --enable-release-checks configure option for use when building releases * Fixed Issue #4489: calendar-color "changes" namespace (thanks Дилян Палаузов) * Fixed Issue #5009: various portability warnings and nits * Fixed Issue #5050: iTIP line endings (thanks Дилян Палаузов) * Fixed Issue #5052: iMIP line endings (thanks Дилян Палаузов) * Fixed Issue #5072: http_cgi use after free (thanks Дилян Палаузов) * Fixed Issue #5094: httpd crash when PROPFIND url is /dav/calendars * Fixed Issue #5118: broken language checks for "zr-hant" and "sr-me" * Fixed Issue #5047: proxying UID SEARCH - CVE-2025-23394: cyrus-imapd: daily-backup.sh allows escalation from cyrus to root (bsc#1241536) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-318=1 Package List: - openSUSE Leap 16.0: cyradm-3.8.6-bp160.1.1 cyrus-imapd-3.8.6-bp160.1.1 cyrus-imapd-devel-3.8.6-bp160.1.1 cyrus-imapd-snmp-3.8.6-bp160.1.1 cyrus-imapd-snmp-mibs-3.8.6-bp160.1.1 cyrus-imapd-utils-3.8.6-bp160.1.1 libcyrus0-3.8.6-bp160.1.1 perl-Cyrus-Annotator-3.8.6-bp160.1.1 perl-Cyrus-IMAP-3.8.6-bp160.1.1 perl-Cyrus-SIEVE-managesieve-3.8.6-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2025-23394.html * https://www.suse.com/security/cve/CVE-2025-49812.html


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds