CVE-2026-27859

Publication date 27 March 2026

Last updated 31 March 2026


Ubuntu priority

Cvss 3 Severity Score

5.3 · Medium

Score breakdown

Description

v3.0.2+ regression: Message headers MIME parameter parsing can cause excessive CPU usage. A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail delivery process to consume large amounts of CPU time. No publicly available exploits are known.

Status

Package Ubuntu Release Status
dovecot 25.10 questing
Fixed 1:2.4.1+dfsg1-5ubuntu4.1
24.04 LTS noble
Fixed 1:2.3.21+dfsg1-2ubuntu6.3
22.04 LTS jammy
Fixed 1:2.3.16+dfsg1-3ubuntu2.7
20.04 LTS focal
Vulnerable
18.04 LTS bionic
Vulnerable
16.04 LTS xenial
Vulnerable
14.04 LTS trusty
Vulnerable

Severity score breakdown

Parameter Value
Base score 5.3 · Medium
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact Low
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

Related Ubuntu Security Notices (USN)

    • USN-8136-1
    • Dovecot vulnerabilities
    • 31 March 2026

Other references


Access our resources on patching vulnerabilities