MGASA-2026-0348

Source
https://advisories.mageia.org/MGASA-2026-0348.html
Import Source
https://advisories.mageia.org/MGASA-2026-0348.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0348
Upstream
  • CVE-2026-20339
  • CVE-2026-20345
  • CVE-2026-20346
  • CVE-2026-20347
  • CVE-2026-20348
Published
2026-08-31T19:40:26Z
Modified
2026-09-01T03:15:03.645755465Z
Summary
Updated clamav packages fix security vulnerabilities
Details

An indexing error while converting GPT partition names that could read or write beyond a stack-allocated partition entry. (CVE-2026-20345) An integer overflow in the PESpin unpacker that could allocate an undersized buffer and then write beyond it while rebuilding a PE file. (CVE-2026-20339) An integer underflow in the PDF parser that could cause a crash while reading a malformed hex string. (CVE-2026-20346) Undefined behavior and integer overflow in the Mach-O parser that could cause a crash while scanning a malformed Mach-O file. (CVE-2026-20347) XAR parser size handling that could request an excessive allocation or exceed scan limits while decompressing a malformed table of contents. (CVE-2026-20348)

References
Credits

Affected packages

Mageia:10 / clamav

Package

Name
clamav
Purl
pkg:rpm/mageia/clamav?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.6-1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0348.json"