CVE-2026-61915

An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 20:18

Updated : 2026-09-10 15:17


NVD link : CVE-2026-61915

Mitre link : CVE-2026-61915

CVE.ORG link : CVE-2026-61915


JSON object : View

Products Affected

No product.

CWE
CWE-415

Double Free