CVE-2020-24386: Debian Linux

Medium severity, CVSS 6.8. EPSS: 2.8% chance of exploitation in the next 30 days.

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

Affected products

  • Debian Debian Linux: version 10.0 only
  • Dovecot Dovecot: from 2.2.26, before 2.3.13 (fixed in 2.3.13)
  • Fedoraproject Fedora: version 32 only

Published 2021-01-04. Last modified 2026-06-17.