SUSE-SU-2026:22574-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202622574-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22574-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:22574-1
Upstream
Related
Published
2026-07-07T16:57:40Z
Modified
2026-07-15T18:24:12.330896901Z
Summary
Security update for clamav
Details

This update for clamav fixes the following issues:

Update to version 1.5.3.

Security issues fixed:

  • CVE-2026-20213: out-of-bounds write due to improper boundary checks for content in PE files during scanning (bsc#1270107).
  • CVE-2026-20214: out-of-bounds write due to improper boundary checks for content in FSG files during scanning (bsc#1270085).
  • CVE-2026-20215: out-of-bounds write due to improper boundary checks for content in 7z files during scanning (bsc#1270088).
  • CVE-2026-20216: denial of service due to improper handling of temporary resources during InstallShield file scanning (bsc#1270089).
  • CVE-2026-20217: out-of-bounds write due to improper boundary checks for content in PESpin files during scanning (bsc#1270091).
  • CVE-2026-20243: out-of-bounds write due to improper boundary checks for content in ALZ files during scanning (bsc#1270092).
  • CVE-2026-20244: integer overflow and DoS due to improper boundary checks for content in DMG files during scanning (bsc#1270106).
  • CVE-2026-41676: buffer overflow due to missing checks via Deriver:derive, PkeyCtxRef:derive and OpenSSL 1.1.1 (bsc#1270138).

Other updates and bugfixes:

  • Version 1.5.3:
    • Fixed a bug in the PESpin unpacker cleanup path that could free pointers into the scanned file buffer and crash the scanner.
    • Fixed an integer overflow in PE rebuild size calculations that could be reached through a malformed Aspack-packed PE file and lead to a heap buffer overflow write.
    • Fixed an InstallShield archive extraction limit bypass that could write far more temporary data than intended and exhaust temporary storage.
    • Fixed an FSG unpacker loop underflow that could write past the section array while scanning a malformed PE file.
    • Fixed ALZ parser size handling bugs that could cause malformed ALZ archives to panic, abort the scanner, or skip expected scan-limit handling.
    • Fixed a 7z parser substream count overflow that could under-allocate parser metadata arrays and write past them while reading a malformed archive.
    • Fixed 32-bit DMG parser size checks that could let a short mish stripe table pass validation and crash 32-bit scanner builds.
    • Hardened clamscan, clamdscan, and clamonacc quarantine actions against time-of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations.
    • Upgraded the Rust tar dependency to resolve the RUSTSEC-2026-0067 and RUSTSEC-2026-0068 advisories, and upgraded the Rust openssl dependency to resolve CVE-2026-41676.
    • Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies.
    • Metadata preclass scans now run before the final scan verdict.
    • ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path.
    • ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket.
References

Affected packages

SUSE:Linux Enterprise Server 16.0 / clamav

Package

Name
clamav
Purl
pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Server%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.3-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "clamav-milter": "1.5.3-160000.1.1",
            "libclamav12": "1.5.3-160000.1.1",
            "clamav": "1.5.3-160000.1.1",
            "clamav-devel": "1.5.3-160000.1.1",
            "libfreshclam4": "1.5.3-160000.1.1",
            "libclammspack0": "1.5.3-160000.1.1",
            "clamav-docs-html": "1.5.3-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22574-1.json"

SUSE:Linux Enterprise Server for SAP applications 16.0 / clamav

Package

Name
clamav
Purl
pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.3-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "clamav-docs-html": "1.5.3-160000.1.1",
            "clamav-milter": "1.5.3-160000.1.1",
            "clamav": "1.5.3-160000.1.1",
            "clamav-devel": "1.5.3-160000.1.1",
            "libfreshclam4": "1.5.3-160000.1.1",
            "libclammspack0": "1.5.3-160000.1.1",
            "libclamav12": "1.5.3-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22574-1.json"