CVE-2026-27856

Publication date 27 March 2026

Last updated 27 March 2026


Ubuntu priority

Description

doveadm: Credentials verified without timing safety. Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. No publicly available exploits are known.

Status

Package Ubuntu Release Status
dovecot 25.10 questing
Vulnerable
24.04 LTS noble
Vulnerable
22.04 LTS jammy
Vulnerable
20.04 LTS focal
Vulnerable
18.04 LTS bionic
Not affected
16.04 LTS xenial
Not affected
14.04 LTS trusty
Not affected


Access our resources on patching vulnerabilities