SUSE-SU-2026:2833-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262833-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2833-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:2833-1
Upstream
Related
Published
2026-07-09T19:10:57Z
Modified
2026-07-10T10:00:08.945516733Z
Summary
Security update for clamav
Details

This update for clamav fixes the following issues

  • CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107).
  • CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085).
  • CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088).
  • CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089).
  • CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091).
  • CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092).
  • CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106).
  • CVE-2026-41676: rust-openssl: Deriver:derive and PkeyCtxRef:derive can overflow short buffers on OpenSSL 1.1.1 (bsc#1270138).

Changes for clamav:

  • Update to 1.5.3:

    • Hardened clamscan, clamdscan, and clamonacc quarantine actions against time-of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations.
    • Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies.
    • Metadata preclass scans now run before the final scan verdict.
    • ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path.
    • ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket.
References

Affected packages

SUSE:Linux Enterprise Server 12 SP5-LTSS / clamav

Package

Name
clamav
Purl
pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.3-3.56.1

Ecosystem specific

{
    "binaries": [
        {
            "clamav-milter": "1.5.3-3.56.1",
            "libclamav12": "1.5.3-3.56.1",
            "clamav-devel": "1.5.3-3.56.1",
            "clamav": "1.5.3-3.56.1",
            "libfreshclam4": "1.5.3-3.56.1",
            "libclammspack0": "1.5.3-3.56.1",
            "clamav-docs-html": "1.5.3-3.56.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2833-1.json"

SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5 / clamav

Package

Name
clamav
Purl
pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.3-3.56.1

Ecosystem specific

{
    "binaries": [
        {
            "clamav-milter": "1.5.3-3.56.1",
            "libclamav12": "1.5.3-3.56.1",
            "clamav": "1.5.3-3.56.1",
            "clamav-devel": "1.5.3-3.56.1",
            "libfreshclam4": "1.5.3-3.56.1",
            "libclammspack0": "1.5.3-3.56.1",
            "clamav-docs-html": "1.5.3-3.56.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2833-1.json"