SUSE-SU-2026:4180-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264180-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4180-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4180-1
Upstream
CVE (9)
  • CVE-2025-8088
  • CVE-2026-20337
  • CVE-2026-20338
  • CVE-2026-20339
  • CVE-2026-20345
  • CVE-2026-20346
  • CVE-2026-20347
  • CVE-2026-20348
  • CVE-2026-46671
Related
Published
2026-09-14T14:49:34Z
Modified
2026-09-15T17:00:06Z
Summary
Security update for clamav
Details

This update for clamav fixes the following issues:

  • CVE-2026-20337: Improper boundary checks for content in zip archive parser (bsc#1274597).
  • CVE-2026-20338: invalid free due to bad ownership handling when merging ZIP catalogue records (bsc#1274598).
  • CVE-2026-20339: integer overflow in the PESpin unpacker leads to undersized allocation and heap out-of-bounds write (bsc#1274599).
  • CVE-2026-20345: out-of-bounds read/write via indexing error when converting GPT partition names (bsc#1274600).
  • CVE-2026-20346: integer underflow when parsing malformed PDF hex strings causes a crash (bsc#1274601).
  • CVE-2026-20347: integer overflow and undefined behavior when scanning malformed Mach-O files causes a crash (bsc#1274602).
  • CVE-2026-20348: improper size handling in the XAR parser allows excessive allocation and scan-limit bypass (bsc#1274603).
  • CVE-2026-46671: onenote_parser: Path traversal in Parser:parse_notebook allows reading files outside the notebook directory (bsc#1271922).
  • CVE-2025-8088: ejects path separators in NTFS alternate data stream names to prevent extraction outside ClamAV's temporary scan directory on Windows.

Changes for clamav:

Update to 1.5.4:

  • Fixed thread-safety issues in the clamd STATS command that could disclose process memory or crash the daemon while scans and STATS requests run concurrently. Also fixed partial socket-write handling used for large STATS responses.
  • FreeBSD: Restored support for safe quarantine move and remove actions while preserving protection against source-path replacement races.
  • Fixed an OpenSSL library-context leak in legacy hashing helpers when a requested message digest cannot be fetched, such as when the default provider is unavailable in a FIPS-enabled environment.
  • Upgraded the Rust crossbeam-epoch dependency to resolve the RUSTSEC-2026-0204 advisory.
References

Affected packages

SUSE:Linux Enterprise Module for Basesystem 15 SP7
clamav

Package

Name
clamav
Purl
pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.5.4-150600.18.31.1

Ecosystem specific

{
    "binaries":  [
        {
            "clamav":  "1.5.4-150600.18.31.1",
            "clamav-devel":  "1.5.4-150600.18.31.1",
            "clamav-docs-html":  "1.5.4-150600.18.31.1",
            "clamav-milter":  "1.5.4-150600.18.31.1",
            "libclamav12":  "1.5.4-150600.18.31.1",
            "libclammspack0":  "1.5.4-150600.18.31.1",
            "libclamunrar12":  "1.5.4-150600.18.31.1",
            "libfreshclam4":  "1.5.4-150600.18.31.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4180-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
clamav

Package

Name
clamav
Purl
pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.5.4-150600.18.31.1

Ecosystem specific

{
    "binaries":  [
        {
            "clamav":  "1.5.4-150600.18.31.1",
            "clamav-devel":  "1.5.4-150600.18.31.1",
            "clamav-docs-html":  "1.5.4-150600.18.31.1",
            "clamav-milter":  "1.5.4-150600.18.31.1",
            "libclamav12":  "1.5.4-150600.18.31.1",
            "libclammspack0":  "1.5.4-150600.18.31.1",
            "libclamunrar12":  "1.5.4-150600.18.31.1",
            "libfreshclam4":  "1.5.4-150600.18.31.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4180-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
clamav

Package

Name
clamav
Purl
pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.5.4-150600.18.31.1

Ecosystem specific

{
    "binaries":  [
        {
            "clamav":  "1.5.4-150600.18.31.1",
            "clamav-devel":  "1.5.4-150600.18.31.1",
            "clamav-docs-html":  "1.5.4-150600.18.31.1",
            "clamav-milter":  "1.5.4-150600.18.31.1",
            "libclamav12":  "1.5.4-150600.18.31.1",
            "libclammspack0":  "1.5.4-150600.18.31.1",
            "libclamunrar12":  "1.5.4-150600.18.31.1",
            "libfreshclam4":  "1.5.4-150600.18.31.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4180-1.json"