Please consider cyrus-imapd 3.10.2-1+deb13u3 for trixie.
This stacks on top of the already-accepted 3.10.2-1+deb13u2 (ack'ed
by Adam D. Barratt on bug #1142925, accepted into proposed-updates
on 2026-09-05, still awaiting the next point release). This does not
replace or conflict with it.
It backports six new CVEs fixed upstream in 3.10.4, none of which
overlap with the CVE-2026-47081..47089 batch already in deb13u2:
* CVE-2026-61907: JMAP snooze bypassed the destination mailbox's
ACL, letting a sharee insert mail into mailboxes they had no
insert rights on.
* CVE-2026-61908: heap out-of-bounds read via a crafted JMAP
email-header blob ID index.
* CVE-2026-61909: CalDAV/CardDAV multiget did not check per-href
ACLs, letting a partially-shared user read unshared events or
contacts.
* CVE-2026-61910: Mailbox/set let a sharee with maySetKeywords
change a shared mailbox's special-use role.
* CVE-2026-61911: Sieve mailboxexists/metadata let a script probe
another user's mailbox existence or read shared annotations.
* CVE-2026-61915: double-free in VPATCH BYPARAM handling could
crash a CalDAV worker.
The debdiff also includes one small, non-CVE fix: a pre-existing
double-free in ical_support.c's parameter cleanup (present since at
least 3.10.2), needed for the CVE-2026-61915 upstream regression test
to actually pass. No code path previously exercised it. Fixed
upstream in commit 4f9fd773047cb8d2f73b00cee4bc2adc1893fb65.
Built and tested clean via sbuild against a local stable chroot;
lintian warnings are pre-existing and unrelated to this diff. debdiff
attached below.
Kind regards,
Edmund