Dovecot 2.4.5 Fixes 18 CVEs
Dovecot 2.4.5 is out, fixing 18 CVEs and adding phrase search.
If you run a mail server, this is not optional. Dovecot is the most widely deployed IMAP server in the world, and it is by definition internet-facing and authenticating untrusted input.
Why this needs immediate attention
An IMAP server sits in the worst position in a threat model: reachable from anywhere, accepting credentials, and parsing complex structured data from unauthenticated clients. IMAP itself is an intricate protocol, and mail messages are a parsing nightmare of nested MIME, character encodings, and decades of malformed output from non-compliant clients.
Eighteen CVEs in one release is a large batch. Without the individual severities to hand, the conservative assumption for anything in the pre-authentication parsing path is that it is serious.
# Debian and Ubuntu
sudo apt update && sudo apt install dovecot-core
# RHEL and derivatives
sudo dnf update dovecot
# confirm and restart
dovecot --version
sudo systemctl restart dovecot
Restarting Dovecot drops active IMAP connections. Clients reconnect automatically, so the user-visible impact is negligible, and it is certainly less disruptive than the alternative.
Check your exposure while you are there
A mail server is one of the few services where it is worth periodically re-examining what is actually reachable:
# what is Dovecot listening on
sudo ss -tlnp | grep dovecot
# recent authentication failures
sudo journalctl -u dovecot --since "24 hours ago" | grep -i "auth failed"
Our journalctl guide and the journalctl query builder cover digging into that properly.
If plaintext IMAP on port 143 is open to the internet without STARTTLS enforced, fix that while you are in the configuration. Implicit TLS on 993 should be the only thing exposed.
fail2ban in front of Dovecot is worth having. It does nothing about a parsing vulnerability, but it substantially reduces credential stuffing, which is the attack actually running against your server continuously right now.
Self-hosted mail generally
This is a good moment to restate the honest position on running your own mail. Receiving mail is manageable. Sending mail that reaches recipients is genuinely hard, because deliverability depends on reputation systems you do not control, and a residential or small-provider IP address starts with none.
If you do run it, the security maintenance is the part that cannot be deferred. Mail servers are scanned continuously, and an unpatched IMAP server with known CVEs is found in hours rather than weeks.
Details are at dovecot.org.