Security update for clamav
This update for clamav fixes the following issues: Update to version 1.5.3. Security issues fixed: - CVE-2026-20213: out-of-bounds write due to improper boundary checks for content in PE files during scanning (bsc#1270107). - CVE-2026-20214: out-of-bounds write due to improper boundary checks for content in FSG files during scanning (bsc#1270085). - CVE-2026-20215: out-of-bounds write due to improper boundary checks for content in 7z files during scanning (bsc#1270088). - CVE-2026-20216: denial of service due to improper handling of temporary resources during InstallShield file scanning (bsc#1270089). - CVE-2026-20217: out-of-bounds write due to improper boundary checks for content in PESpin files during scanning (bsc#1270091). - CVE-2026-20243: out-of-bounds write due to improper boundary checks for content in ALZ files during scanning (bsc#1270092). - CVE-2026-20244: integer overflow and DoS due to improper boundary checks for content in DMG files during scanning (bsc#1270106). - CVE-2026-41676: buffer overflow due to missing checks via `Deriver:derive`, `PkeyCtxRef:derive` and OpenSSL 1.1.1 (bsc#1270138). Other updates and bugfixes: - Version 1.5.3: * Fixed a bug in the PESpin unpacker cleanup path that could free pointers into the scanned file buffer and crash the scanner. * Fixed an integer overflow in PE rebuild size calculations that could be reached through a malformed Aspack-packed PE file and lead to a heap buffer overflow write. * Fixed an InstallShield archive extraction limit bypass that could write far more temporary data than intended and exhaust temporary storage. * Fixed an FSG unpacker loop underflow that could write past the section array while scanning a malformed PE file. * Fixed ALZ parser size handling bugs that could cause malformed ALZ archives to panic, abort the scanner, or skip expected scan-limit handling. * Fixed a 7z parser substream count overflow that could under-allocate parser metadata arrays and write past them while reading a malformed archive. * Fixed 32-bit DMG parser size checks that could let a short mish stripe table pass validation and crash 32-bit scanner builds. * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time-of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Upgraded the Rust tar dependency to resolve the RUSTSEC-2026-0067 and RUSTSEC-2026-0068 advisories, and upgraded the Rust openssl dependency to resolve CVE-2026-41676. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for clamav fixes the following issues: Update to version 1.5.3. Security issues fixed: - CVE-2026-20213: out-of-bounds write due to improper boundary checks for content in PE files during scanning (bsc#1270107). - CVE-2026-20214: out-of-bounds write due to improper boundary checks for content in FSG files during scanning (bsc#1270085). - CVE-2026-20215: out-of-bounds write due to improper boundary checks for content in 7z files during scanning (bsc#1270088). - CVE-2026-20216: denial of service due to improper handling of temporary resources during InstallShield file scanning (bsc#1270089). - CVE-2026-20217: out-of-bounds write due to improper boundary checks for content in PESpin files during scanning (bsc#1270091). - CVE-2026-20243: out-of-bounds write due to improper boundary checks for content in ALZ files during scanning (bsc#1270092). - CVE-2026-20244: integer overflow and DoS due to improper boundary checks for content in DMG files during scanning (bsc#1270106). - CVE-2026-41676: buffer overflow due to missing checks via `Deriver:derive`, `PkeyCtxRef:derive` and OpenSSL 1.1.1 (bsc#1270138). Other updates and bugfixes: - Version 1.5.3: * Fixed a bug in the PESpin unpacker cleanup path that could free pointers into the scanned file buffer and crash the scanner. * Fixed an integer overflow in PE rebuild size calculations that could be reached through a malformed Aspack-packed PE file and lead to a heap buffer overflow write. * Fixed an InstallShield archive extraction limit bypass that could write far more temporary data than intended and exhaust temporary storage. * Fixed an FSG unpacker loop underflow that could write past the section array while scanning a malformed PE file. * Fixed ALZ parser size handling bugs that could cause malformed ALZ archives to panic, abort the scanner, or skip expected scan-limit handling. * Fixed a 7z parser substream count overflow that could under-allocate parser metadata arrays and write past them while reading a malformed archive. * Fixed 32-bit DMG parser size checks that could let a short mish stripe table pass validation and crash 32-bit scanner builds. * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time-of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Upgraded the Rust tar dependency to resolve the RUSTSEC-2026-0067 and RUSTSEC-2026-0068 advisories, and upgraded the Rust openssl dependency to resolve CVE-2026-41676. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket.
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1270085
- https://bugzilla.suse.com/1270088
- https://bugzilla.suse.com/1270089
- https://bugzilla.suse.com/1270091
- https://bugzilla.suse.com/1270092
- https://bugzilla.suse.com/1270106
- https://bugzilla.suse.com/1270107
- https://bugzilla.suse.com/1270138
- https://www.suse.com/security/cve/CVE-2026-20213
- https://www.suse.com/security/cve/CVE-2026-20214
- https://www.suse.com/security/cve/CVE-2026-20215
- https://www.suse.com/security/cve/CVE-2026-20216
- https://www.suse.com/security/cve/CVE-2026-20217
- https://www.suse.com/security/cve/CVE-2026-20243
- https://www.suse.com/security/cve/CVE-2026-20244
- https://www.suse.com/security/cve/CVE-2026-41676