SUSE-SU-2026:4208-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264208-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4208-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4208-1
Upstream
  • CVE-2025-8088
  • CVE-2026-20337
  • CVE-2026-20338
  • CVE-2026-20339
  • CVE-2026-20345
  • CVE-2026-20346
  • CVE-2026-20347
  • CVE-2026-20348
Related
  • CVE-2025-8088
  • CVE-2026-20337
  • CVE-2026-20338
  • CVE-2026-20339
  • CVE-2026-20345
  • CVE-2026-20346
  • CVE-2026-20347
  • CVE-2026-20348
  • CVE-2026-46671
Published
2026-09-16T08:23:41Z
Modified
2026-09-16T21:45:03Z
Summary
Security update for clamav
Details

This update for clamav fixes the following issues:

  • CVE-2026-20337: Improper boundary checks for content in zip archive parser (bsc#1274597).
  • CVE-2026-20338: invalid free due to bad ownership handling when merging ZIP catalogue records (bsc#1274598).
  • CVE-2026-20339: integer overflow in the PESpin unpacker leads to undersized allocation and heap out-of-bounds write (bsc#1274599).
  • CVE-2026-20345: out-of-bounds read/write via indexing error when converting GPT partition names (bsc#1274600).
  • CVE-2026-20346: integer underflow when parsing malformed PDF hex strings causes a crash (bsc#1274601).
  • CVE-2026-20347: integer overflow and undefined behavior when scanning malformed Mach-O files causes a crash (bsc#1274602).
  • CVE-2026-20348: improper size handling in the XAR parser allows excessive allocation and scan-limit bypass (bsc#1274603).
  • CVE-2026-46671: onenote_parser: Path traversal in Parser:parse_notebook allows reading files outside the notebook directory (bsc#1271922).
  • CVE-2025-8088: rejects path separators in NTFS alternate data stream names to prevent extraction outside ClamAV's temporary scan directory on Windows.

Changes for clamav:

Update to 1.5.4:

  • Fixed thread-safety issues in the clamd STATS command that could disclose process memory or crash the daemon while scans and STATS requests run concurrently. Also fixed partial socket-write handling used for large STATS responses.
  • FreeBSD: Restored support for safe quarantine move and remove actions while preserving protection against source-path replacement races.
  • Fixed an OpenSSL library-context leak in legacy hashing helpers when a requested message digest cannot be fetched, such as when the default provider is unavailable in a FIPS-enabled environment.
  • Upgraded the Rust crossbeam-epoch dependency to resolve the RUSTSEC-2026-0204 advisory.
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
clamav

Package

Name
clamav
Purl
pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.5.4-150400.13.11.1

Ecosystem specific

{
    "binaries": [
        {
            "clamav": "1.5.4-150400.13.11.1",
            "clamav-devel": "1.5.4-150400.13.11.1",
            "clamav-docs-html": "1.5.4-150400.13.11.1",
            "clamav-milter": "1.5.4-150400.13.11.1",
            "libclamav12": "1.5.4-150400.13.11.1",
            "libclammspack0": "1.5.4-150400.13.11.1",
            "libclamunrar12": "1.5.4-150400.13.11.1",
            "libfreshclam4": "1.5.4-150400.13.11.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4208-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
clamav

Package

Name
clamav
Purl
pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.5.4-150400.13.11.1

Ecosystem specific

{
    "binaries": [
        {
            "clamav": "1.5.4-150400.13.11.1",
            "clamav-devel": "1.5.4-150400.13.11.1",
            "clamav-docs-html": "1.5.4-150400.13.11.1",
            "clamav-milter": "1.5.4-150400.13.11.1",
            "libclamav12": "1.5.4-150400.13.11.1",
            "libclammspack0": "1.5.4-150400.13.11.1",
            "libclamunrar12": "1.5.4-150400.13.11.1",
            "libfreshclam4": "1.5.4-150400.13.11.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4208-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
clamav

Package

Name
clamav
Purl
pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.5.4-150400.13.11.1

Ecosystem specific

{
    "binaries": [
        {
            "clamav": "1.5.4-150400.13.11.1",
            "clamav-devel": "1.5.4-150400.13.11.1",
            "clamav-docs-html": "1.5.4-150400.13.11.1",
            "clamav-milter": "1.5.4-150400.13.11.1",
            "libclamav12": "1.5.4-150400.13.11.1",
            "libclammspack0": "1.5.4-150400.13.11.1",
            "libclamunrar12": "1.5.4-150400.13.11.1",
            "libfreshclam4": "1.5.4-150400.13.11.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4208-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
clamav

Package

Name
clamav
Purl
pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.5.4-150400.13.11.1

Ecosystem specific

{
    "binaries": [
        {
            "clamav": "1.5.4-150400.13.11.1",
            "clamav-devel": "1.5.4-150400.13.11.1",
            "clamav-docs-html": "1.5.4-150400.13.11.1",
            "clamav-milter": "1.5.4-150400.13.11.1",
            "libclamav12": "1.5.4-150400.13.11.1",
            "libclammspack0": "1.5.4-150400.13.11.1",
            "libclamunrar12": "1.5.4-150400.13.11.1",
            "libfreshclam4": "1.5.4-150400.13.11.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4208-1.json"
SUSE:Linux Enterprise Micro 5.5
clamav

Package

Name
clamav
Purl
pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Micro%205.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.5.4-150400.13.11.1

Ecosystem specific

{
    "binaries": [
        {
            "clamav": "1.5.4-150400.13.11.1",
            "libclamav12": "1.5.4-150400.13.11.1",
            "libclammspack0": "1.5.4-150400.13.11.1",
            "libclamunrar12": "1.5.4-150400.13.11.1",
            "libfreshclam4": "1.5.4-150400.13.11.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4208-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
clamav

Package

Name
clamav
Purl
pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.5.4-150400.13.11.1

Ecosystem specific

{
    "binaries": [
        {
            "clamav": "1.5.4-150400.13.11.1",
            "clamav-devel": "1.5.4-150400.13.11.1",
            "clamav-docs-html": "1.5.4-150400.13.11.1",
            "clamav-milter": "1.5.4-150400.13.11.1",
            "libclamav12": "1.5.4-150400.13.11.1",
            "libclammspack0": "1.5.4-150400.13.11.1",
            "libclamunrar12": "1.5.4-150400.13.11.1",
            "libfreshclam4": "1.5.4-150400.13.11.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4208-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
clamav

Package

Name
clamav
Purl
pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.5.4-150400.13.11.1

Ecosystem specific

{
    "binaries": [
        {
            "clamav": "1.5.4-150400.13.11.1",
            "clamav-devel": "1.5.4-150400.13.11.1",
            "clamav-docs-html": "1.5.4-150400.13.11.1",
            "clamav-milter": "1.5.4-150400.13.11.1",
            "libclamav12": "1.5.4-150400.13.11.1",
            "libclammspack0": "1.5.4-150400.13.11.1",
            "libclamunrar12": "1.5.4-150400.13.11.1",
            "libfreshclam4": "1.5.4-150400.13.11.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4208-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
clamav

Package

Name
clamav
Purl
pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.5.4-150400.13.11.1

Ecosystem specific

{
    "binaries": [
        {
            "clamav": "1.5.4-150400.13.11.1",
            "clamav-devel": "1.5.4-150400.13.11.1",
            "clamav-docs-html": "1.5.4-150400.13.11.1",
            "clamav-milter": "1.5.4-150400.13.11.1",
            "libclamav12": "1.5.4-150400.13.11.1",
            "libclammspack0": "1.5.4-150400.13.11.1",
            "libclamunrar12": "1.5.4-150400.13.11.1",
            "libfreshclam4": "1.5.4-150400.13.11.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4208-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
clamav

Package

Name
clamav
Purl
pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.5.4-150400.13.11.1

Ecosystem specific

{
    "binaries": [
        {
            "clamav": "1.5.4-150400.13.11.1",
            "clamav-devel": "1.5.4-150400.13.11.1",
            "clamav-docs-html": "1.5.4-150400.13.11.1",
            "clamav-milter": "1.5.4-150400.13.11.1",
            "libclamav12": "1.5.4-150400.13.11.1",
            "libclammspack0": "1.5.4-150400.13.11.1",
            "libclamunrar12": "1.5.4-150400.13.11.1",
            "libfreshclam4": "1.5.4-150400.13.11.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4208-1.json"