7.1

CVE-2026-61915

An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cyrus ≫ Imap Version < 3.8.8
Cyrus ≫ Imap Version >= 3.9.0 < 3.10.4
Cyrus ≫ Imap Version >= 3.11.0 < 3.12.4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.121
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 2.8 4.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
MITRE 4.2 1.6 2.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
CWE-415 Double Free

The product calls free() twice on the same memory address.

https://cyrusimap.org
Product
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html
Release Notes
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html
Release Notes
https://www.cyrusimap.org/3.12/imap/download/release-notes/3.8/x/3.8.8.html
Release Notes