An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 20:18
Updated : 2026-09-10 15:17
NVD link : CVE-2026-61915
Mitre link : CVE-2026-61915
CVE.ORG link : CVE-2026-61915
JSON object : View
Products Affected
No product.
CWE
CWE-415
Double Free
