ClamAV 1.5.0 release candidate

"Val Snyder \(micasnyd\) via clamav-announce" <[email protected]> Wed, 20 Aug 2025 18:21:53 +0000
Newsgroups gmane.comp.security.virus.clamav.announce
Message-ID <CH3PR11MB8750A6128542C2A00A343393C633A__22965.2085503162$1755714407$gmane$org@CH3PR11MB8750.namprd11.prod.outlook.com>
--===============5516589023394447032==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_CH3PR11MB8750A6128542C2A00A343393C633ACH3PR11MB8750namp_"

--_000_CH3PR11MB8750A6128542C2A00A343393C633ACH3PR11MB8750namp_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

Read this online at https://blog.clamav.net/2025/08/clamav-150-release-cand=
idate-now.html


The ClamAV 1.5.0 release candidate is now available. You may find the sourc=
e code and installers for this release at clamav.net/downloads<https://www.=
clamav.net/downloads> or on the ClamAV GitHub release page<https://github.c=
om/Cisco-Talos/clamav/releases/tag/clamav-1.5.0-rc>.
The release candidate phase is expected to last two to four weeks before we=
 publish the stable release. This will depend on whether any changes are re=
quired to stabilize this version. Please take this time to evaluate ClamAV =
1.5.0.
Please help us validate this release by providing feedback via GitHub issue=
s<https://github.com/Cisco-Talos/clamav/issues>, via the ClamAV mailing lis=
t<https://lists.clamav.net/mailman/listinfo/clamav-users> or on our Discord=
<https://discord.gg/sGaxA5Q>.
IMPORTANT: A major feature of the 1.5 release is a FIPS-compliant method fo=
r verifying the authenticity of CVD signature database archives and CDIFF s=
ignature database patch files. The feature is ready to test in this release=
 candidate, but we are not yet distributing the associated =93.cvd.sign=94 =
signature files for the daily, main, and bytecode databases. Because these =
files are not available, ClamAV will fall back to using the legacy MD5-base=
d RSA signature check. In other words, Freshclam will continue to fail on F=
IPS-enabled systems for now. However, the unit tests do include a test sign=
ing key and certificate pair along with tests to exercise signing and verif=
ication using the FIPS-compliant method.
Note: Windows builds on GitHub Actions, which use VCPkg to provide C librar=
y dependencies, are failing at this time.
Tip: If you are downloading the source from the GitHub release page, the pa=
ckage labeled "clamav-1.5.0-release candidate.tar.gz" does not require an i=
nternet connection to build. All dependencies are included in this package.=
 However, if you download the ZIP or TAR.GZ generated by GitHub, located at=
 the very bottom, then an internet connection will be required during the b=
uild to download additional Rust dependencies.
For Docker users, there is no specific Docker tag for the release candidate=
, but you can use the clamav:unstable or clamav:unstable_base tags.
ClamAV 1.5.0 includes the following improvements and changes:
Major changes

  *
Added checks to determine if an OLE2-based Microsoft Office document is enc=
rypted.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1295>
  *
Added the ability to record URIs found in HTML if the generate-JSON-metadat=
a feature is enabled. Also adds an option to disable this in case you want =
the JSON metadata feature but do not want to record HTML URIs. The ClamScan=
 command-line option is --json-store-html-uris=3Dno. The clamd.conf config =
option is JsonStoreHTMLURIs no. The libclamav general scan option is CL_SCA=
N_GENERAL_STORE_HTML_URIS
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1281>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1482>
GitHub pull request #3<https://github.com/Cisco-Talos/clamav/pull/1514>
  *
Added the ability to record URIs found in PDFs if the generate-JSON-metadat=
a feature is enabled. Also adds an option to disable this in case you want =
the JSON metadata feature but do not want to record PDF URIs. The ClamScan =
command-line option is --json-store-pdf-uris=3Dno. The clamd.conf config op=
tion is JsonStorePDFURIs no. The libclamav general scan option is CL_SCAN_G=
ENERAL_STORE_PDF_URIS
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1482>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1514>
  *
Added regex support for the clamd.conf OnAccessExcludePath config option. T=
his change courtesy of GitHub user b1tg.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1314>
  *
Added CVD signing/verification with external .sign files.
Freshclam will now attempt to download external signature files to accompan=
y existing .cvd databases and .cdiff patch files. Sigtool now has commands =
to sign and verify using the external signatures.
ClamAV now installs a 'certs' directory in the app config directory (e.g., =
<prefix>/etc/certs). The install path is configurable. The CMake option to =
configure the CVD certs directory is -D CVD_CERTS_DIRECTORY=3DPATH
New options to set an alternative CVD certs directory:
Added two new APIs to the public clamav.h header:

cl_error_t cl_cvdverify_ex(
    const char *file,
    const char *certs_directory,
    uint32_t dboptions);

cl_error_t cl_cvdunpack_ex(
    const char *file,
    const char *dir,
    const char *certs_directory,
    uint32_t dboptions);


The original cl_cvdverify and cl_cvdunpack are deprecated.
Added a cl_engine_field enum option CL_ENGINE_CVDCERTSDIR. You may set this=
 option with cl_engine_set_str and get it with cl_engine_get_str, to overri=
de the compiled in default CVD certs directory.
Thank you to Mark Carey at SAP for inspiring work on this feature with an i=
nitial proof of concept for external-signature FIPS compliant CVD signing.
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1417>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1478>
GitHub pull request #3<https://github.com/Cisco-Talos/clamav/pull/1489>
GitHub pull request #4<https://github.com/Cisco-Talos/clamav/pull/1491>
     *   The command-line option for Freshclam, ClamD, ClamScan, and Sigtoo=
l is --cvdcertsdir PATH
     *   The environment variable for Freshclam, ClamD, ClamScan, and Sigto=
ol is CVD_CERTS_DIR
     *   The config option for Freshclam and ClamD is CVDCertsDirectory PAT=
H
  *
Freshclam, ClamD, ClamScan, and Sigtool: Added an option to enable FIPS-lik=
e limits disabling MD5 and SHA1 from being used for verifying digital signa=
tures or for being used to trust a file when checking for false positives (=
FPs).
For freshclam.conf and clamd.conf set this config option:

FIPSCryptoHashLimits yes


For clamscan and sigtool use this command-line option:

--fips-limits


For libclamav: Enable FIPS-limits for a ClamAV engine like this:

cl_engine_set_num(engine, CL_ENGINE_FIPS_LIMITS, 1);


ClamAV will also attempt to detect if FIPS-mode is enabled. If so, it will =
automatically enable the FIPS-limits feature.
This change mitigates safety concerns over the use of MD5 and SHA1 algorith=
ms to trust files and is required to enable ClamAV to operate legitimately =
in FIPS-mode enabled environments.
Note: ClamAV may still calculate MD5 or SHA1 hashes as needed for detection=
 purposes or for informational purposes in FIPS-enabled environments and wh=
en the FIPS-limits option is enabled.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
  *
Upgraded the clean-file scan cache to use SHA2-256 (prior versions use MD5)=
. The clean-file cache algorithm is not configurable.
This change resolves safety concerns over the use of MD5 to trust files and=
 is required to enable ClamAV to operate legitimately in FIPS-mode enabled =
environments.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
  *
ClamD: Added an option to disable select administrative commands including =
SHUTDOWN, RELOAD, STATS and VERSION.
The new clamd.conf options are:

EnableShutdownCommand yes
EnableReloadCommand yes
EnableStatsCommand yes
EnableVersionCommand yes


This change courtesy of GitHub user ChaoticByte.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1502>
  *
libclamav: Added extended hashing functions with a "flags" parameter that a=
llows the caller to choose if they want to bypass FIPS hash algorithm limit=
s:

cl_error_t cl_hash_data_ex(
    const char *alg,
    const uint8_t *data,
    size_t data_len,
    uint8_t **hash,
    size_t *hash_len,
    uint32_t flags);

cl_error_t cl_hash_init_ex(
    const char *alg,
    uint32_t flags,
    cl_hash_ctx_t **ctx_out);

cl_error_t cl_update_hash_ex(
    cl_hash_ctx_t *ctx,
    const uint8_t *data,
    size_t length);

cl_error_t cl_finish_hash_ex(
    cl_hash_ctx_t *ctx,
    uint8_t **hash,
    size_t *hash_len,
    uint32_t flags);

void cl_hash_destroy(void *ctx);

cl_error_t cl_hash_file_fd_ex(
    const char *alg,
    int fd,
    size_t offset,
    size_t length,
    uint8_t **hash,
    size_t *hash_len,
    uint32_t flags);


GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
  *
ClamScan: Improved the precision of the bytes-scanned and bytes-read counte=
rs. The ClamScan scan summary will now report exact counts in "GiB", "MiB",=
 "KiB", or "B" as appropriate. Previously, it always reported "MB".
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
  *
ClamScan: Add hash & file-type in/out CLI options:
We will not be adding this for ClamDScan, as we do not have a mechanism in =
the ClamD socket API to receive scan options or a way for ClamD to include =
scan metadata in the response.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
     *   --hash-hint: The file hash so that libclamav does not need to calc=
ulate it. The type of hash must match the --hash-alg.
     *   --log-hash: Print the file hash after each file scanned. The type =
of hash printed will match the --hash-alg.
     *   --hash-alg: The hashing algorithm used for either --hash-hint or -=
-log-hash. Supported algorithms are "md5", "sha1", "sha2-256". If not speci=
fied, the default is "sha2-256".
     *   --file-type-hint: The file type hint so that libclamav can optimiz=
e scanning (e.g., "pe", "elf", "zip", etc.). You may also use ClamAV type n=
ames such as "CL_TYPE_PE". ClamAV will ignore the hint if it is not familia=
r with the specified type. See also: https://docs.clamav.net/appendix/FileT=
ypes.html#file-types
     *   --log-file-type: Print the file type after each file scanned.
  *
libclamav: Added new scan functions that provide additional functionality:

cl_error_t cl_scanfile_ex(
    const char *filename,
    cl_verdict_t *verdict_out,
    const char **last_alert_out,
    uint64_t *scanned_out,
    const struct cl_engine *engine,
    struct cl_scan_options *scanoptions,
    void *context,
    const char *hash_hint,
    char **hash_out,
    const char *hash_alg,
    const char *file_type_hint,
    char **file_type_out);

cl_error_t cl_scandesc_ex(
    int desc,
    const char *filename,
    cl_verdict_t *verdict_out,
    const char **last_alert_out,
    uint64_t *scanned_out,
    const struct cl_engine *engine,
    struct cl_scan_options *scanoptions,
    void *context,
    const char *hash_hint,
    char **hash_out,
    const char *hash_alg,
    const char *file_type_hint,
    char **file_type_out);

cl_error_t cl_scanmap_ex(
    cl_fmap_t *map,
    const char *filename,
    cl_verdict_t *verdict_out,
    const char **last_alert_out,
    uint64_t *scanned_out,
    const struct cl_engine *engine,
    struct cl_scan_options *scanoptions,
    void *context,
    const char *hash_hint,
    char **hash_out,
    const char *hash_alg,
    const char *file_type_hint,
    char **file_type_out);


The older cl_scan*() functions are now deprecated and may be removed in a f=
uture release. See clamav.h for more details.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
  *
libclamav: Added a new engine option to toggle temp directory recursion.
Temp directory recursion is the idea that each object scanned in ClamAV's r=
ecursive extract/scan process will get a new temp subdirectory, mimicking t=
he nesting structure of the file.
Temp directory recursion was introduced in ClamAV 0.103 and is enabled when=
ever --leave-temps / LeaveTemporaryFiles is enabled.
In ClamAV 1.5, an application linking to libclamav can separately enable te=
mp directory recursion if they wish. For ClamScan and ClamD, it will remain=
 tied to --leave-temps / LeaveTemporaryFiles options.
The new temp directory recursion option can be enabled with:

cl_engine_set_num(engine, CL_ENGINE_TMPDIR_RECURSION, 1);


GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
  *
libclamav: Added a class of scan callback functions that can be added with =
the following API function:

void cl_engine_set_scan_callback(struct cl_engine *engine, clcb_scan callba=
ck, cl_scan_callback_t location);


The scan callback location may be configured using the following five value=
s:
Each callback may alter scan behavior using the following return codes:
Each callback is given a pointer to the current scan layer from which they =
can get previous layers, can get the layer's fmap, and then various attribu=
tes of the layer and of the fmap. To make this possible, there are new APIs=
 to query scan-layer details and fmap details:

  cl_error_t cl_fmap_set_name(cl_fmap_t *map, const char *name);
  cl_error_t cl_fmap_get_name(cl_fmap_t *map, const char **name_out);
  cl_error_t cl_fmap_set_path(cl_fmap_t *map, const char *path);
  cl_error_t cl_fmap_get_path(cl_fmap_t *map, const char **path_out, size_t=
 *offset_out, size_t *len_out);
  cl_error_t cl_fmap_get_fd(const cl_fmap_t *map, int *fd_out, size_t *offs=
et_out, size_t *len_out);
  cl_error_t cl_fmap_get_size(const cl_fmap_t *map, size_t *size_out);
  cl_error_t cl_fmap_set_hash(const cl_fmap_t *map, const char *hash_alg, c=
har hash);
  cl_error_t cl_fmap_have_hash(const cl_fmap_t *map, const char *hash_alg, =
bool *have_hash_out);
  cl_error_t cl_fmap_will_need_hash_later(const cl_fmap_t *map, const char =
*hash_alg);
  cl_error_t cl_fmap_get_hash(const cl_fmap_t *map, const char *hash_alg, c=
har **hash_out);
  cl_error_t cl_fmap_get_data(const cl_fmap_t *map, size_t offset, size_t l=
en, const uint8_t **data_out, size_t *data_len_out);
  cl_error_t cl_scan_layer_get_fmap(cl_scan_layer_t *layer, cl_fmap_t **fma=
p_out);
  cl_error_t cl_scan_layer_get_parent_layer(cl_scan_layer_t *layer, cl_scan=
_layer_t **parent_layer_out);
  cl_error_t cl_scan_layer_get_type(cl_scan_layer_t *layer, const char **ty=
pe_out);
  cl_error_t cl_scan_layer_get_recursion_level(cl_scan_layer_t *layer, uint=
32_t *recursion_level_out);
  cl_error_t cl_scan_layer_get_object_id(cl_scan_layer_t *layer, uint64_t *=
object_id_out);
  cl_error_t cl_scan_layer_get_last_alert(cl_scan_layer_t *layer, const cha=
r **alert_name_out);
  cl_error_t cl_scan_layer_get_attributes(cl_scan_layer_t *layer, uint32_t =
*attributes_out);


This deprecates, but does not immediately remove, the existing scan callbac=
ks:

  void cl_engine_set_clcb_pre_cache(struct cl_engine *engine, clcb_pre_cach=
e callback);
  void cl_engine_set_clcb_file_inspection(struct cl_engine *engine, clcb_fi=
le_inspection callback);
  void cl_engine_set_clcb_pre_scan(struct cl_engine *engine, clcb_pre_scan =
callback);
  void cl_engine_set_clcb_post_scan(struct cl_engine *engine, clcb_post_sca=
n callback);
  void cl_engine_set_clcb_virus_found(struct cl_engine *engine, clcb_virus_=
found callback);
  void cl_engine_set_clcb_hash(struct cl_engine *engine, clcb_hash callback=
);


There is an interactive test program to demonstrate the new callbacks. See:=
 examples/ex_scan_callbacks.c
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
     *   CL_SCAN_CALLBACK_PRE_HASH: Occurs just after basic file-type detec=
tion and before any hashes have been calculated either for the cache or the=
 gen-json metadata.
     *   CL_SCAN_CALLBACK_PRE_SCAN: Occurs before parser modules run and be=
fore pattern matching.
     *   CL_SCAN_CALLBACK_POST_SCAN: Occurs after pattern matching and afte=
r running parser modules. A.k.a. the scan is complete for this layer.
     *   CL_SCAN_CALLBACK_ALERT: Occurs each time an alert (detection) woul=
d be triggered during a scan.
     *   CL_SCAN_CALLBACK_FILE_TYPE: Occurs each time the file type determi=
nation is refined. This may happen more than once per layer.
     *
CL_BREAK: Scan aborted by callback. The rest of the scan is skipped. This d=
oes not mark the file as clean or infected, it just skips the rest of the s=
can.
     *
CL_SUCCESS / CL_CLEAN: File scan will continue.
For CL_SCAN_CALLBACK_ALERT: This means you want to ignore this specific ale=
rt and keep scanning.
This is different than CL_VERIFIED because it does not affect prior or futu=
re alerts. Return CL_VERIFIED instead if you want to remove prior alerts fo=
r this layer and skip the rest of the scan for this layer.
     *
CL_VIRUS: This means you do not trust the file. A new alert will be added.
For CL_SCAN_CALLBACK_ALERT: This means you agree with the alert and no extr=
a alert is needed.
     *
CL_VERIFIED: Layer explicitly trusted by the callback and previous alerts r=
emoved for THIS layer. You might want to do this if you trust the hash or v=
erified a digital signature. The rest of the scan will be skipped for THIS =
layer. For contained files, this does NOT mean that the parent or adjacent =
layers are trusted.
  *
Signature names that start with "Weak." will no longer alert. Instead, they=
 will be tracked internally and can be found in scan metadata JSON. This is=
 a step towards enabling alerting signatures to depend on prior Weak indica=
tor matches in the current layer or in child layers.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
  *
For the "Generate Metadata JSON" feature:
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
     *
The "Viruses" array of alert names has been replaced by two new arrays that=
 include additional details beyond just signature name:
        *   "Indicators" records three types of indicators:
           *   Strong indicators are for traditional alerting signature mat=
ches and will halt the scan, except in all-match mode.
           *   Potentially Unwanted indicators will only cause an alert at =
the end of the scan unless a Strong indicator is found. They are treated th=
e same as Strong indicators in all-match mode.
           *   Weak indicators do not alert and will be leveraged in a futu=
re version as a condition for logical signature matches.
        *   "Alerts" records only alerting indicators. Events that trust a =
file, such as false positive signatures, will remove affected indicators, a=
nd mark them as "Ignored" in the "Indicators" array.
     *
Add new option to calculate and record additional hash types when the "gene=
rate metadata JSON" feature is enabled:
        *   libclamav option: CL_SCAN_GENERAL_STORE_EXTRA_HASHES
        *   ClamScan option: --json-store-extra-hashes (default off)
        *   clamd.conf option: JsonStoreExtraHashes (default 'no')
     *
The file hash is now stored as "sha2-256" instead of "FileMD5". If you enab=
le the "extra hashes" option, then it will also record "md5" and "sha1".
     *
Each object scanned now has a unique "Object ID".
  *
Sigtool: Renamed the sigtool option --sha256 to --sha2-256. The original op=
tion is still functional but is deprecated.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>

Other improvements

  *
Set a limit on the max-recursion config option. Users will no longer be abl=
e to set max-recursion higher than 100. This change prevents errors on star=
t up or crashes if encountering a file with that many layers of recursion.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1264>
  *
Build system: CMake improvements to support compiling for the AIX platform.=
 This change is courtesy of GitHub user KamathForAIX.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1387>
  *
Improve support for extracting malformed zip archives. This change is court=
esy of Frederick Sell.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1460>
  *
Windows: Code quality improvement for the ClamScan and ClamDScan --move and=
 --remove options. This change is courtesy of Maxim Suhanov.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1470>
  *
Added file type recognition for an initial set of AI model file types.
The file type is accessible to applications using libclamav via the scan ca=
llback functions and as an optional output parameter to the scan functions:=
 cl_scanfile_ex(), cl_scanmap_ex(), and cl_scandesc_ex().
When scanning these files, type will now show "CL_TYPE_AI_MODEL" instead of=
 "CL_TYPE_BINARY_DATA".
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1476>
  *
Added support for inline comments in ClamAV configuration files. This chang=
e is courtesy of GitHub user userwiths.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1308>
  *
Disabled the MyDoom hardcoded/heuristic detection because of false positive=
s.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1495>
  *
Sigtool: Added support for creating .cdiff and .script patch files for CVDs=
 that have underscores in the CVD name. Also improved support for relative =
paths with the --diff command.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1541>
  *
Windows: Improved support for file names with UTF-8 characters not found in=
 the ANSI or OEM code pages when printing scan results or showing activity =
in the ClamDTOP monitoring utility. Fixed a bug with opening files with suc=
h names with the Sigtool utility.
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1461>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1537>
  *
Improved the code quality of the ZIP module. Added inline documentation.
GitHub pull request #1<https://github.com/Cisco-Talos/clamav/pull/1548>
GitHub pull request #2<https://github.com/Cisco-Talos/clamav/pull/1552>
  *
Always run scan callbacks for embedded files. Embedded files are found with=
in other files through signature matches instead of by parsing. They will n=
ow be processed the same way and then they can trigger application callback=
s (e.g., "pre-scan", "post-scan", etc.).
This change will impact scans with both the "leave-temps" feature and the "=
force-to-disk" feature enabled, resulting in additional temporary files.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
  *
Added DevContainer templates to the ClamAV Git repository in order to make =
it easier to set up AlmaLinux or Debian development environments.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1462>

Bug fixes

  *
Reduced email multipart message parser complexity.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1347>
  *
Fixed possible undefined behavior in inflate64 module. The inflate64 module=
 is a modified version of the zlib library, taken from version 1.2.3 with s=
ome customization and with some cherry-picked fixes. This adds one addition=
al fix from zlib 1.2.9. Thank you to TITAN Team for reporting this issue.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1469>
  *
Fixed a bug in ClamD that broke reporting of memory usage on Linux. The STA=
TS command can be used to monitor ClamD directly or through ClamDTOP. The m=
emory stats feature does not work on all platforms (e.g., Windows).
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1465>
  *
Windows: Fixed a build issue when the same library dependency is found in t=
wo different locations.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1453>
  *
Fixed an infinite loop when scanning some email files in debug-mode. This f=
ix is courtesy of Yoann Lecuyer.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1445>
  *
Fixed a stack buffer overflow bug in the phishing signature load process. T=
his fix is courtesy of GitHub user Shivam7-1.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1486>
  *
Fixed a race condition in the Freshclam feature tests. This fix is courtesy=
 of GitHub user rma-x.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1513>
  *
Windows: Fixed a 5-byte heap buffer overread in the Windows unit tests. Thi=
s fix is courtesy of GitHub user Sophie0x2E.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1542>
  *
Fix double-extraction of OOXML-based office documents.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>
  *
ClamBC: Fixed crashes on startup.
GitHub pull request<https://github.com/Cisco-Talos/clamav/pull/1532>

Acknowledgments
Special thanks to the following people for code contributions and bug repor=
ts:

  *   b1tg
  *   ChaoticByte
  *   Frederick Sell
  *   KamathForAIX
  *   Mark Carey at SAP
  *   Maxim Suhanov
  *   rma-x
  *   Shivam7-1
  *   Sophie0x2E
  *   TITAN Team
  *   userwiths
  *   Yoann Lecuyer



Respectfully,
Val

Valerie Snyder (she/they)
ClamAV Development
Talos
Cisco Systems, Inc.

--_000_CH3PR11MB8750A6128542C2A00A343393C633ACH3PR11MB8750namp_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 10pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
Read this online at <a id=3D"LPlnk571614" href=3D"https://blog.clamav.net/2=
025/08/clamav-150-release-candidate-now.html">
https://blog.clamav.net/2025/08/clamav-150-release-candidate-now.html</a></=
div>
<span style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService,=
 Calibri, Helvetica, sans-serif; font-size: 10pt; color: rgb(0, 0, 0);"><br=
>
</span>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 1=
6px 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calib=
ri, Helvetica, sans-serif; font-size: 12pt;" class=3D"elementToProof">
<span style=3D"color: rgb(0, 0, 0);">The ClamAV&nbsp;1.5.0 release candidat=
e&nbsp;is now available. You&nbsp;may find the source code and installers f=
or this release at
</span><span style=3D"color: rgb(70, 120, 134);"><a style=3D"color: rgb(70,=
 120, 134); margin: 0px;" rel=3D"noreferrer noopener" class=3D"Hyperlink SC=
XW232052544 BCX0 OWAAutoLink" id=3D"OWAb71fa3e4-adfb-c3e3-3409-182b28fc8a35=
" target=3D"_blank" href=3D"https://www.clamav.net/downloads">clamav.net/do=
wnloads</a></span><span style=3D"color: rgb(0, 0, 0);">&nbsp;or&nbsp;on&nbs=
p;the
</span><span style=3D"color: rgb(70, 120, 134);"><a style=3D"color: rgb(70,=
 120, 134); margin: 0px;" rel=3D"noreferrer noopener" class=3D"Hyperlink SC=
XW232052544 BCX0 OWAAutoLink" id=3D"OWAd8fbc5b3-29c9-8682-cc8d-8dbc8fc72bbb=
" target=3D"_blank" href=3D"https://github.com/Cisco-Talos/clamav/releases/=
tag/clamav-1.5.0-rc">ClamAV
 GitHub release page</a></span><span style=3D"color: rgb(0, 0, 0);">.&nbsp;=
</span></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 0=
px 0px 11.2px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService,=
 Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" cla=
ss=3D"elementToProof">
The release candidate phase is expected to last two to four weeks before we=
 publish the stable release. This will depend on whether any changes are re=
quired&nbsp;to stabilize this version. Please take this time to evaluate Cl=
amAV 1.5.0.&nbsp;</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 1=
6px 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calib=
ri, Helvetica, sans-serif; font-size: 12pt;" class=3D"elementToProof">
<span style=3D"color: rgb(0, 0, 0);">Please help us validate&nbsp;this rele=
ase by providing feedback&nbsp;via
</span><span style=3D"color: rgb(70, 120, 134);"><a style=3D"color: rgb(70,=
 120, 134); margin: 0px;" rel=3D"noreferrer noopener" class=3D"Hyperlink SC=
XW232052544 BCX0 OWAAutoLink" id=3D"OWA523dc3a5-1611-cf0b-05cc-6681f976ba75=
" target=3D"_blank" href=3D"https://github.com/Cisco-Talos/clamav/issues">G=
itHub
 issues</a></span><span style=3D"color: rgb(0, 0, 0);">, via the </span><sp=
an style=3D"color: rgb(70, 120, 134);"><a style=3D"color: rgb(70, 120, 134)=
; margin: 0px;" rel=3D"noreferrer noopener" class=3D"Hyperlink SCXW23205254=
4 BCX0 OWAAutoLink" id=3D"OWA9a2770b5-abfc-af69-1dd6-a8c5120fe0bb" target=
=3D"_blank" href=3D"https://lists.clamav.net/mailman/listinfo/clamav-users"=
>ClamAV
 mailing list</a></span><span style=3D"color: rgb(0, 0, 0);">&nbsp;or on </=
span><span style=3D"color: rgb(70, 120, 134);"><a style=3D"color: rgb(70, 1=
20, 134); margin: 0px;" rel=3D"noreferrer noopener" class=3D"Hyperlink SCXW=
232052544 BCX0 OWAAutoLink" id=3D"OWAeb43d119-2e71-25ac-3e44-e469ed634541" =
target=3D"_blank" href=3D"https://discord.gg/sGaxA5Q">our
 Discord</a></span><span style=3D"color: rgb(0, 0, 0);">.&nbsp;</span></div=
>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 1=
6px 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calib=
ri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=3D"=
elementToProof">
<i>IMPORTANT: A major&nbsp;feature&nbsp;of the 1.5 release is a FIPS-compli=
ant method for verifying the authenticity of CVD signature database archive=
s and CDIFF signature database patch files. The feature is ready to test in=
 this&nbsp;release candidate, but we are not yet
 distributing the associated =93.cvd.sign=94 signature files for the daily,=
 main, and bytecode databases. Because these files are not&nbsp;available, =
ClamAV&nbsp;will fall back to using the legacy MD5-based RSA signature chec=
k. In other words, Freshclam&nbsp;will continue to
 fail on FIPS-enabled systems&nbsp;for now. However, the unit tests do incl=
ude a test signing key and certificate pair along with tests to exercise si=
gning and verification using the FIPS-compliant method.</i>&nbsp;</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 1=
6px 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calib=
ri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=3D"=
elementToProof">
<i>Note: Windows builds&nbsp;on GitHub Actions, which use VCPkg&nbsp;to pro=
vide C library dependencies, are failing at this time.</i>&nbsp;</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 1=
6px 0px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calib=
ri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=3D"=
elementToProof">
<i>Tip: If you are downloading the source from the GitHub release page, the=
 package labeled &quot;clamav-1.5.0-release candidate.tar.gz&quot; does not=
 require an internet connection to build. All dependencies are included in =
this package. However, if you download the
 ZIP or TAR.GZ generated by GitHub, located&nbsp;at the very bottom, then a=
n internet connection will be required&nbsp;during the build to download ad=
ditional&nbsp;Rust dependencies.</i>&nbsp;</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 0=
px 0px 11.2px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService,=
 Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" cla=
ss=3D"elementToProof">
For Docker users, there is no specific Docker tag for the release candidate=
, but you can use the clamav:unstable&nbsp;or clamav:unstable_base&nbsp;tag=
s.&nbsp;</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 0=
px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=
=3D"elementToProof">
ClamAV 1.5.0 includes the following improvements and changes:&nbsp;</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin: 24px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Ap=
tos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: =
rgb(0, 0, 0);" class=3D"elementToProof" id=3D"major-changes">
<b>Major changes</b></div>
<ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; paddi=
ng-right: 2.5em; padding-left: 2.5em; list-style-position: initial; list-st=
yle-type: disc;" data-line=3D"11">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added checks to determine if an OLE2-based Microsoft Office document is enc=
rypted.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1295" class=3D"OWAAutoLink" id=3D"OWA05a2a9cd-c9b0-9b00-c=
e23-eda240c71387" href=3D"https://github.com/Cisco-Talos/clamav/pull/1295">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added the ability to record URIs found in HTML if the generate-JSON-metadat=
a feature is enabled. Also adds an option to disable this in case you want =
the JSON metadata feature but do not want to record HTML URIs. The ClamScan=
 command-line option is
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
--json-store-html-uris=3Dno</code></span>. The
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
clamd.conf</code></span>&nbsp;config option is
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
JsonStoreHTMLURIs no</code></span>. The libclamav general scan option is
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
CL_SCAN_GENERAL_STORE_HTML_URIS</code></span></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1281" class=3D"OWAAutoLink" id=3D"OWA78c1ee0d-0a95-c703-6=
3b5-dd0eb08b4253" href=3D"https://github.com/Cisco-Talos/clamav/pull/1281">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1482" class=3D"OWAAutoLink" id=3D"OWA69d994c6-b06f-a0f5-6=
fda-f5113bba38c0" href=3D"https://github.com/Cisco-Talos/clamav/pull/1482">=
GitHub pull request #2</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1514" class=3D"OWAAutoLink" id=3D"OWAf43b3b6c-3c47-1396-a=
f13-b3104ee1ae8f" href=3D"https://github.com/Cisco-Talos/clamav/pull/1514">=
GitHub pull request #3</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added the ability to record URIs found in PDFs if the generate-JSON-metadat=
a feature is enabled. Also adds an option to disable this in case you want =
the JSON metadata feature but do not want to record PDF URIs. The ClamScan =
command-line option is
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
--json-store-pdf-uris=3Dno</code></span>. The
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
clamd.conf</code></span>&nbsp;config option is
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
JsonStorePDFURIs no</code></span>. The libclamav general scan option is
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
CL_SCAN_GENERAL_STORE_PDF_URIS</code></span></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1482" class=3D"OWAAutoLink" id=3D"OWA852d7d5a-f07b-3c88-b=
571-9d6752a8c195" href=3D"https://github.com/Cisco-Talos/clamav/pull/1482">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1514" class=3D"OWAAutoLink" id=3D"OWA4fead452-3c7f-8773-3=
5cc-9160137c87be" href=3D"https://github.com/Cisco-Talos/clamav/pull/1514">=
GitHub pull request #2</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added regex support for the <span style=3D"font-family: Consolas, &quot;Cou=
rier New&quot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
clamd.conf</code></span>&nbsp;<span style=3D"font-family: Consolas, &quot;C=
ourier New&quot;, monospace;"><code style=3D"font-family: Consolas, &quot;C=
ourier New&quot;, monospace;">OnAccessExcludePath</code></span>&nbsp;config=
 option.
 This change courtesy of GitHub user b1tg.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1314" class=3D"OWAAutoLink" id=3D"OWAbf99d4d2-4dfa-164d-d=
931-c3238e9f92ed" href=3D"https://github.com/Cisco-Talos/clamav/pull/1314">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added CVD signing/verification with external <span style=3D"font-family: Co=
nsolas, &quot;Courier New&quot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
.sign</code></span>&nbsp;files.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Freshclam will now attempt to download external signature files to accompan=
y existing
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
.cvd</code></span>&nbsp;databases and
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
.cdiff</code></span>&nbsp;patch files. Sigtool now has commands to sign and=
 verify using the external signatures.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
ClamAV now installs a 'certs' directory in the app config directory (e.g., =
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
&lt;prefix&gt;/etc/certs</code></span>). The install path is configurable. =
The CMake option to configure the CVD certs directory is
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
-D CVD_CERTS_DIRECTORY=3DPATH</code></span></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
New options to set an alternative CVD certs directory:</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added two new APIs to the public clamav.h header:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, &quot;Courier New&quot;, monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, &quot;Cour=
ier New&quot;, monospace; display: inline-block;">cl_error_t cl_cvdverify_e=
x(=0A=
 &nbsp; &nbsp;const char *file,=0A=
 &nbsp; &nbsp;const char *certs_directory,=0A=
 &nbsp; &nbsp;uint32_t dboptions);=0A=
=0A=
cl_error_t cl_cvdunpack_ex(=0A=
 &nbsp; &nbsp;const char *file,=0A=
 &nbsp; &nbsp;const char *dir,=0A=
 &nbsp; &nbsp;const char *certs_directory,=0A=
 &nbsp; &nbsp;uint32_t dboptions);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
The original <span style=3D"font-family: Consolas, &quot;Courier New&quot;,=
 monospace;"><code style=3D"font-family: Consolas, &quot;Courier New&quot;,=
 monospace;">cl_cvdverify</code></span>&nbsp;and
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
cl_cvdunpack</code></span>&nbsp;are deprecated.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added a <span style=3D"font-family: Consolas, &quot;Courier New&quot;, mono=
space;"><code style=3D"font-family: Consolas, &quot;Courier New&quot;, mono=
space;">cl_engine_field</code></span>&nbsp;enum option
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
CL_ENGINE_CVDCERTSDIR</code></span>. You may set this option with
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
cl_engine_set_str</code></span>&nbsp;and get it with
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
cl_engine_get_str</code></span>, to override the compiled in default CVD ce=
rts directory.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Thank you to Mark Carey at SAP for inspiring work on this feature with an i=
nitial proof of concept for external-signature FIPS compliant CVD signing.<=
/div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1417" class=3D"OWAAutoLink" id=3D"OWAb5184d4e-2ca5-6bb9-a=
905-c5882333e245" href=3D"https://github.com/Cisco-Talos/clamav/pull/1417">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1478" class=3D"OWAAutoLink" id=3D"OWAdc848458-6848-14d8-5=
365-666eac927bef" href=3D"https://github.com/Cisco-Talos/clamav/pull/1478">=
GitHub pull request #2</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1489" class=3D"OWAAutoLink" id=3D"OWA4529ee9b-7a60-dbc1-2=
263-da9794b4b35b" href=3D"https://github.com/Cisco-Talos/clamav/pull/1489">=
GitHub pull request #3</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1491" class=3D"OWAAutoLink" id=3D"OWAe6d8ec8b-15a7-db44-b=
42c-1590acd95882" href=3D"https://github.com/Cisco-Talos/clamav/pull/1491">=
GitHub pull request #4</a></div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc; flex-direction: column; display: flex;" data-line=3D"5=
9">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
The command-line option for Freshclam, ClamD, ClamScan, and Sigtool is <spa=
n role=3D"presentation" style=3D"font-family: Consolas, &quot;Courier New&q=
uot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
--cvdcertsdir PATH</code></span></li><li style=3D"font-family: Aptos, Aptos=
_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-si=
ze: 12pt; color: rgb(0, 0, 0); direction: ltr; align-self: start; text-inde=
nt: 0px; margin: 0px 0px 0.25em;">
The environment variable for Freshclam, ClamD, ClamScan, and Sigtool is <sp=
an role=3D"presentation" style=3D"font-family: Consolas, &quot;Courier New&=
quot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
CVD_CERTS_DIR</code></span></li><li style=3D"font-family: Aptos, Aptos_Embe=
ddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 1=
2pt; color: rgb(0, 0, 0); direction: ltr; align-self: start; text-indent: 0=
px; margin: 0px 0px 0.25em;">
The config option for Freshclam and ClamD is <span role=3D"presentation" st=
yle=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
CVDCertsDirectory PATH</code></span></li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Freshclam, ClamD, ClamScan, and Sigtool: Added an option to enable FIPS-lik=
e limits disabling MD5 and SHA1 from being used for verifying digital signa=
tures or for being used to trust a file when checking for false positives (=
FPs).</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
For <span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospac=
e;"><code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospac=
e;">freshclam.conf</code></span>&nbsp;and
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
clamd.conf</code></span>&nbsp;set this config option:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, &quot;Courier New&quot;, monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, &quot;Cour=
ier New&quot;, monospace; display: inline-block;">FIPSCryptoHashLimits yes=
=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
For <span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospac=
e;"><code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospac=
e;">clamscan</code></span>&nbsp;and
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
sigtool</code></span>&nbsp;use this command-line option:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, &quot;Courier New&quot;, monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, &quot;Cour=
ier New&quot;, monospace; display: inline-block;">--fips-limits=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
For libclamav: Enable FIPS-limits for a ClamAV engine like this:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, &quot;Courier New&quot;, monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, &quot;Cour=
ier New&quot;, monospace; display: inline-block;">cl_engine_set_num(engine,=
 CL_ENGINE_FIPS_LIMITS, 1);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
ClamAV will also attempt to detect if FIPS-mode is enabled. If so, it will =
automatically enable the FIPS-limits feature.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
This change mitigates safety concerns over the use of MD5 and SHA1 algorith=
ms to trust files and is required to enable ClamAV to operate legitimately =
in FIPS-mode enabled environments.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Note: ClamAV may still calculate MD5 or SHA1 hashes as needed for detection=
 purposes or for informational purposes in FIPS-enabled environments and wh=
en the FIPS-limits option is enabled.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA3bc6c935-6fa4-22ae-8=
456-022cacd80bca" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Upgraded the clean-file scan cache to use SHA2-256 (prior versions use MD5)=
. The clean-file cache algorithm is not configurable.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
This change resolves safety concerns over the use of MD5 to trust files and=
 is required to enable ClamAV to operate legitimately in FIPS-mode enabled =
environments.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA9d847376-e446-36d0-5=
909-d1f8176d7ad7" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
ClamD: Added an option to disable select administrative commands including =
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
SHUTDOWN</code></span>,
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
RELOAD</code></span>,
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
STATS</code></span>&nbsp;and
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
VERSION</code></span>.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
The new <span style=3D"font-family: Consolas, &quot;Courier New&quot;, mono=
space;"><code style=3D"font-family: Consolas, &quot;Courier New&quot;, mono=
space;">clamd.conf</code></span>&nbsp;options are:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, &quot;Courier New&quot;, monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, &quot;Cour=
ier New&quot;, monospace; display: inline-block;">EnableShutdownCommand yes=
=0A=
EnableReloadCommand yes=0A=
EnableStatsCommand yes=0A=
EnableVersionCommand yes=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
This change courtesy of GitHub user ChaoticByte.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1502" class=3D"OWAAutoLink" id=3D"OWA05231360-4ef1-b33b-0=
51e-8dba35d99d3e" href=3D"https://github.com/Cisco-Talos/clamav/pull/1502">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
libclamav: Added extended hashing functions with a &quot;flags&quot; parame=
ter that allows the caller to choose if they want to bypass FIPS hash algor=
ithm limits:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, &quot;Courier New&quot;, monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, &quot;Cour=
ier New&quot;, monospace; display: inline-block;">cl_error_t cl_hash_data_e=
x(=0A=
 &nbsp; &nbsp;const char *alg,=0A=
 &nbsp; &nbsp;const uint8_t *data,=0A=
 &nbsp; &nbsp;size_t data_len,=0A=
 &nbsp; &nbsp;uint8_t **hash,=0A=
 &nbsp; &nbsp;size_t *hash_len,=0A=
 &nbsp; &nbsp;uint32_t flags);=0A=
=0A=
cl_error_t cl_hash_init_ex(=0A=
 &nbsp; &nbsp;const char *alg,=0A=
 &nbsp; &nbsp;uint32_t flags,=0A=
 &nbsp; &nbsp;cl_hash_ctx_t **ctx_out);=0A=
=0A=
cl_error_t cl_update_hash_ex(=0A=
 &nbsp; &nbsp;cl_hash_ctx_t *ctx,=0A=
 &nbsp; &nbsp;const uint8_t *data,=0A=
 &nbsp; &nbsp;size_t length);=0A=
=0A=
cl_error_t cl_finish_hash_ex(=0A=
 &nbsp; &nbsp;cl_hash_ctx_t *ctx,=0A=
 &nbsp; &nbsp;uint8_t **hash,=0A=
 &nbsp; &nbsp;size_t *hash_len,=0A=
 &nbsp; &nbsp;uint32_t flags);=0A=
=0A=
void cl_hash_destroy(void *ctx);=0A=
=0A=
cl_error_t cl_hash_file_fd_ex(=0A=
 &nbsp; &nbsp;const char *alg,=0A=
 &nbsp; &nbsp;int fd,=0A=
 &nbsp; &nbsp;size_t offset,=0A=
 &nbsp; &nbsp;size_t length,=0A=
 &nbsp; &nbsp;uint8_t **hash,=0A=
 &nbsp; &nbsp;size_t *hash_len,=0A=
 &nbsp; &nbsp;uint32_t flags);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA73d13217-d993-7e10-6=
4e9-8a24739754d7" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
ClamScan: Improved the precision of the bytes-scanned and bytes-read counte=
rs. The ClamScan scan summary will now report exact counts in &quot;GiB&quo=
t;, &quot;MiB&quot;, &quot;KiB&quot;, or &quot;B&quot; as appropriate. Prev=
iously, it always reported &quot;MB&quot;.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA331054d8-2133-dac4-2=
005-fcbf0d2b7110" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
ClamScan: Add hash &amp; file-type in/out CLI options:</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
We will not be adding this for ClamDScan, as we do not have a mechanism in =
the ClamD socket API to receive scan options or a way for ClamD to include =
scan metadata in the response.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA6a2e29da-f569-be47-3=
b75-4f096fcbff0a" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc; flex-direction: column; display: flex;" data-line=3D"1=
99">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;"><code style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;">--hash-hint</code></span>: The file hash so that libc=
lamav does not need to calculate it. The type of hash must
 match the <span role=3D"presentation" style=3D"font-family: Consolas, &quo=
t;Courier New&quot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
--hash-alg</code></span>.</li><li style=3D"font-family: Aptos, Aptos_Embedd=
edFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12p=
t; color: rgb(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px=
; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;"><code style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;">--log-hash</code></span>: Print the file hash after e=
ach file scanned. The type of hash printed will match the
<span role=3D"presentation" style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
--hash-alg</code></span>.</li><li style=3D"font-family: Aptos, Aptos_Embedd=
edFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12p=
t; color: rgb(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px=
; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;"><code style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;">--hash-alg</code></span>: The hashing algorithm used =
for either
<span role=3D"presentation" style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
--hash-hint</code></span>&nbsp;or
<span role=3D"presentation" style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
--log-hash</code></span>. Supported algorithms are &quot;md5&quot;, &quot;s=
ha1&quot;, &quot;sha2-256&quot;. If not specified, the default is &quot;sha=
2-256&quot;.</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos=
_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb=
(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0px=
 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;"><code style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;">--file-type-hint</code></span>: The file type hint so=
 that libclamav can optimize scanning (e.g., &quot;pe&quot;, &quot;elf&quot=
;,
 &quot;zip&quot;, etc.). You may also use ClamAV type names such as &quot;C=
L_TYPE_PE&quot;. ClamAV will ignore the hint if it is not familiar with the=
 specified type. See also:
<span role=3D"presentation" style=3D"color: rgb(0, 95, 184);"><a style=3D"c=
olor: rgb(0, 95, 184);" data-href=3D"https://docs.clamav.net/appendix/FileT=
ypes.html#file-types" class=3D"OWAAutoLink" id=3D"OWA285a709b-a28e-9de4-5ca=
b-f1e4a636f9a9" href=3D"https://docs.clamav.net/appendix/FileTypes.html#fil=
e-types">https://docs.clamav.net/appendix/FileTypes.html#file-types</a></sp=
an></li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontSe=
rvice, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0)=
; direction: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25=
em;">
<span role=3D"presentation" style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;"><code style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;">--log-file-type</code></span>: Print the file type af=
ter each file scanned.</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
libclamav: Added new scan functions that provide additional functionality:<=
/div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, &quot;Courier New&quot;, monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, &quot;Cour=
ier New&quot;, monospace; display: inline-block;">cl_error_t cl_scanfile_ex=
(=0A=
 &nbsp; &nbsp;const char *filename,=0A=
 &nbsp; &nbsp;cl_verdict_t *verdict_out,=0A=
 &nbsp; &nbsp;const char **last_alert_out,=0A=
 &nbsp; &nbsp;uint64_t *scanned_out,=0A=
 &nbsp; &nbsp;const struct cl_engine *engine,=0A=
 &nbsp; &nbsp;struct cl_scan_options *scanoptions,=0A=
 &nbsp; &nbsp;void *context,=0A=
 &nbsp; &nbsp;const char *hash_hint,=0A=
 &nbsp; &nbsp;char **hash_out,=0A=
 &nbsp; &nbsp;const char *hash_alg,=0A=
 &nbsp; &nbsp;const char *file_type_hint,=0A=
 &nbsp; &nbsp;char **file_type_out);=0A=
=0A=
cl_error_t cl_scandesc_ex(=0A=
 &nbsp; &nbsp;int desc,=0A=
 &nbsp; &nbsp;const char *filename,=0A=
 &nbsp; &nbsp;cl_verdict_t *verdict_out,=0A=
 &nbsp; &nbsp;const char **last_alert_out,=0A=
 &nbsp; &nbsp;uint64_t *scanned_out,=0A=
 &nbsp; &nbsp;const struct cl_engine *engine,=0A=
 &nbsp; &nbsp;struct cl_scan_options *scanoptions,=0A=
 &nbsp; &nbsp;void *context,=0A=
 &nbsp; &nbsp;const char *hash_hint,=0A=
 &nbsp; &nbsp;char **hash_out,=0A=
 &nbsp; &nbsp;const char *hash_alg,=0A=
 &nbsp; &nbsp;const char *file_type_hint,=0A=
 &nbsp; &nbsp;char **file_type_out);=0A=
=0A=
cl_error_t cl_scanmap_ex(=0A=
 &nbsp; &nbsp;cl_fmap_t *map,=0A=
 &nbsp; &nbsp;const char *filename,=0A=
 &nbsp; &nbsp;cl_verdict_t *verdict_out,=0A=
 &nbsp; &nbsp;const char **last_alert_out,=0A=
 &nbsp; &nbsp;uint64_t *scanned_out,=0A=
 &nbsp; &nbsp;const struct cl_engine *engine,=0A=
 &nbsp; &nbsp;struct cl_scan_options *scanoptions,=0A=
 &nbsp; &nbsp;void *context,=0A=
 &nbsp; &nbsp;const char *hash_hint,=0A=
 &nbsp; &nbsp;char **hash_out,=0A=
 &nbsp; &nbsp;const char *hash_alg,=0A=
 &nbsp; &nbsp;const char *file_type_hint,=0A=
 &nbsp; &nbsp;char **file_type_out);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
The older <span style=3D"font-family: Consolas, &quot;Courier New&quot;, mo=
nospace;"><code style=3D"font-family: Consolas, &quot;Courier New&quot;, mo=
nospace;">cl_scan*()</code></span>&nbsp;functions are now deprecated and ma=
y be removed in a future release. See
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
clamav.h</code></span>&nbsp;for more details.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWAf63446d2-5b60-b26e-f=
e76-9644a15826e6" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
libclamav: Added a new engine option to toggle temp directory recursion.</d=
iv>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Temp directory recursion is the idea that each object scanned in ClamAV's r=
ecursive extract/scan process will get a new temp subdirectory, mimicking t=
he nesting structure of the file.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Temp directory recursion was introduced in ClamAV 0.103 and is enabled when=
ever <span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospa=
ce;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
--leave-temps</code></span>&nbsp;/
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
LeaveTemporaryFiles</code></span>&nbsp;is enabled.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
In ClamAV 1.5, an application linking to libclamav can separately enable te=
mp directory recursion if they wish. For ClamScan and ClamD, it will remain=
 tied to
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
--leave-temps</code></span>&nbsp;/
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
LeaveTemporaryFiles</code></span>&nbsp;options.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
The new temp directory recursion option can be enabled with:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, &quot;Courier New&quot;, monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, &quot;Cour=
ier New&quot;, monospace; display: inline-block;">cl_engine_set_num(engine,=
 CL_ENGINE_TMPDIR_RECURSION, 1);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA6fec7a57-52a8-4777-b=
56e-7e0f02df6e77" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
libclamav: Added a class of scan callback functions that can be added with =
the following API function:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, &quot;Courier New&quot;, monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, &quot;Cour=
ier New&quot;, monospace; display: inline-block;">void cl_engine_set_scan_c=
allback(struct cl_engine *engine, clcb_scan callback, cl_scan_callback_t lo=
cation);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
The scan callback location may be configured using the following five value=
s:</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Each callback may alter scan behavior using the following return codes:</di=
v>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Each callback is given a pointer to the current scan layer from which they =
can get previous layers, can get the layer's fmap, and then various attribu=
tes of the layer and of the fmap. To make this possible, there are new APIs=
 to query scan-layer details and
 fmap details:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, &quot;Courier New&quot;, monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, &quot;Cour=
ier New&quot;, monospace; display: inline-block;"> &nbsp;cl_error_t cl_fmap=
_set_name(cl_fmap_t *map, const char *name);=0A=
 &nbsp;cl_error_t cl_fmap_get_name(cl_fmap_t *map, const char **name_out);=
=0A=
 &nbsp;cl_error_t cl_fmap_set_path(cl_fmap_t *map, const char *path);=0A=
 &nbsp;cl_error_t cl_fmap_get_path(cl_fmap_t *map, const char **path_out, s=
ize_t *offset_out, size_t *len_out);=0A=
 &nbsp;cl_error_t cl_fmap_get_fd(const cl_fmap_t *map, int *fd_out, size_t =
*offset_out, size_t *len_out);=0A=
 &nbsp;cl_error_t cl_fmap_get_size(const cl_fmap_t *map, size_t *size_out);=
=0A=
 &nbsp;cl_error_t cl_fmap_set_hash(const cl_fmap_t *map, const char *hash_a=
lg, char hash);=0A=
 &nbsp;cl_error_t cl_fmap_have_hash(const cl_fmap_t *map, const char *hash_=
alg, bool *have_hash_out);=0A=
 &nbsp;cl_error_t cl_fmap_will_need_hash_later(const cl_fmap_t *map, const =
char *hash_alg);=0A=
 &nbsp;cl_error_t cl_fmap_get_hash(const cl_fmap_t *map, const char *hash_a=
lg, char **hash_out);=0A=
 &nbsp;cl_error_t cl_fmap_get_data(const cl_fmap_t *map, size_t offset, siz=
e_t len, const uint8_t **data_out, size_t *data_len_out);=0A=
 &nbsp;cl_error_t cl_scan_layer_get_fmap(cl_scan_layer_t *layer, cl_fmap_t =
**fmap_out);=0A=
 &nbsp;cl_error_t cl_scan_layer_get_parent_layer(cl_scan_layer_t *layer, cl=
_scan_layer_t **parent_layer_out);=0A=
 &nbsp;cl_error_t cl_scan_layer_get_type(cl_scan_layer_t *layer, const char=
 **type_out);=0A=
 &nbsp;cl_error_t cl_scan_layer_get_recursion_level(cl_scan_layer_t *layer,=
 uint32_t *recursion_level_out);=0A=
 &nbsp;cl_error_t cl_scan_layer_get_object_id(cl_scan_layer_t *layer, uint6=
4_t *object_id_out);=0A=
 &nbsp;cl_error_t cl_scan_layer_get_last_alert(cl_scan_layer_t *layer, cons=
t char **alert_name_out);=0A=
 &nbsp;cl_error_t cl_scan_layer_get_attributes(cl_scan_layer_t *layer, uint=
32_t *attributes_out);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
This deprecates, but does not immediately remove, the existing scan callbac=
ks:</div>
<pre style=3D"margin-top: 0px; padding: 16px; border-width: 0.8px; border-s=
tyle: solid; border-color: rgb(229, 229, 229); border-radius: 3px;" role=3D=
"presentation" class=3D"elementToProof"><div style=3D"font-family: Consolas=
, &quot;Courier New&quot;, monospace;" class=3D"elementToProof"><span style=
=3D"line-height: 1.357em;"><code style=3D"font-family: Consolas, &quot;Cour=
ier New&quot;, monospace; display: inline-block;"> &nbsp;void cl_engine_set=
_clcb_pre_cache(struct cl_engine *engine, clcb_pre_cache callback);=0A=
 &nbsp;void cl_engine_set_clcb_file_inspection(struct cl_engine *engine, cl=
cb_file_inspection callback);=0A=
 &nbsp;void cl_engine_set_clcb_pre_scan(struct cl_engine *engine, clcb_pre_=
scan callback);=0A=
 &nbsp;void cl_engine_set_clcb_post_scan(struct cl_engine *engine, clcb_pos=
t_scan callback);=0A=
 &nbsp;void cl_engine_set_clcb_virus_found(struct cl_engine *engine, clcb_v=
irus_found callback);=0A=
 &nbsp;void cl_engine_set_clcb_hash(struct cl_engine *engine, clcb_hash cal=
lback);=0A=
</code></span></div></pre>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
There is an interactive test program to demonstrate the new callbacks. See:=
 <span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;"=
>
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
examples/ex_scan_callbacks.c</code></span></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA5a2a637e-d9d9-cff8-c=
1af-5950153c6d44" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc; flex-direction: column; display: flex;" data-line=3D"2=
99">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;"><code style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;">CL_SCAN_CALLBACK_PRE_HASH</code></span>: Occurs just =
after basic file-type detection and before any hashes have
 been calculated either for the cache or the gen-json metadata.</li><li sty=
le=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri,=
 Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direction: lt=
r; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;"><code style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;">CL_SCAN_CALLBACK_PRE_SCAN</code></span>: Occurs befor=
e parser modules run and before pattern matching.</li><li style=3D"font-fam=
ily: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sa=
ns-serif; font-size: 12pt; color: rgb(0, 0, 0); direction: ltr; align-self:=
 start; text-indent: 0px; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;"><code style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;">CL_SCAN_CALLBACK_POST_SCAN</code></span>: Occurs afte=
r pattern matching and after running parser modules. A.k.a.
 the scan is complete for this layer.</li><li style=3D"font-family: Aptos, =
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; fo=
nt-size: 12pt; color: rgb(0, 0, 0); direction: ltr; align-self: start; text=
-indent: 0px; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;"><code style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;">CL_SCAN_CALLBACK_ALERT</code></span>: Occurs each tim=
e an alert (detection) would be triggered during a scan.</li><li style=3D"f=
ont-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvet=
ica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direction: ltr; alig=
n-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;"><code style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;">CL_SCAN_CALLBACK_FILE_TYPE</code></span>: Occurs each=
 time the file type determination is refined. This may happen
 more than once per layer.</li><li style=3D"font-family: Aptos, Aptos_Embed=
dedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12=
pt; color: rgb(0, 0, 0); direction: ltr; text-indent: 0px; margin: 0px 0px =
0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
CL_BREAK</code></span>: Scan aborted by callback. The rest of the scan is s=
kipped. This does not mark the file as clean or infected,
 it just skips the rest of the scan.</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
CL_SUCCESS</code></span>&nbsp;/
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
CL_CLEAN</code></span>: File scan will continue.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
For <span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospac=
e;"><code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospac=
e;">CL_SCAN_CALLBACK_ALERT</code></span>: This means you want to ignore thi=
s specific alert and keep scanning.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
This is different than <span style=3D"font-family: Consolas, &quot;Courier =
New&quot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
CL_VERIFIED</code></span>&nbsp;because it does not affect prior or future a=
lerts. Return
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
CL_VERIFIED</code></span>&nbsp;instead if you want to remove prior alerts f=
or this layer and skip the rest of the scan for this layer.</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
CL_VIRUS</code></span>: This means you do not trust the file. A new alert w=
ill be added.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
For <span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospac=
e;"><code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospac=
e;">CL_SCAN_CALLBACK_ALERT</code></span>: This means you agree with the ale=
rt and no extra alert is needed.</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
CL_VERIFIED</code></span>: Layer explicitly trusted by the callback and pre=
vious alerts removed for THIS layer. You might want to do
 this if you trust the hash or verified a digital signature. The rest of th=
e scan will be skipped for THIS layer. For contained files, this does NOT m=
ean that the parent or adjacent layers are trusted.</div>
</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Signature names that start with &quot;Weak.&quot; will no longer alert. Ins=
tead, they will be tracked internally and can be found in scan metadata JSO=
N. This is a step towards enabling alerting signatures to depend on prior W=
eak indicator matches in the current layer
 or in child layers.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWAa5cb0bb8-f6a6-7583-0=
10e-9434418dc196" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
For the &quot;Generate Metadata JSON&quot; feature:</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA8315bc02-585f-7762-0=
c4b-6ea8c3a70387" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc;" data-line=3D"386">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
The &quot;Viruses&quot; array of alert names has been replaced by two new a=
rrays that include additional details beyond just signature name:</div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc; flex-direction: column; display: flex;" data-line=3D"3=
88">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
&quot;Indicators&quot; records three types of indicators:</li><ul style=3D"=
direction: ltr; text-align: left; margin: 0px; padding-right: 2.5em; paddin=
g-left: 2.5em; list-style-position: initial; list-style-type: disc; flex-di=
rection: column; display: flex;" data-line=3D"389">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
<b>Strong</b>&nbsp;indicators are for traditional alerting signature matche=
s and will halt the scan, except in all-match mode.</li><li style=3D"font-f=
amily: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, =
sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direction: ltr; align-sel=
f: start; text-indent: 0px; margin: 0px 0px 0.25em;">
<b>Potentially Unwanted</b>&nbsp;indicators will only cause an alert at the=
 end of the scan unless a Strong indicator is found. They are treated the s=
ame as Strong indicators in all-match mode.</li><li style=3D"font-family: A=
ptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-ser=
if; font-size: 12pt; color: rgb(0, 0, 0); direction: ltr; align-self: start=
; text-indent: 0px; margin: 0px 0px 0.25em;">
<b>Weak</b>&nbsp;indicators do not alert and will be leveraged in a future =
version as a condition for logical signature matches.</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
&quot;Alerts&quot; records only alerting indicators. Events that trust a fi=
le, such as false positive signatures, will remove affected indicators, and=
 mark them as &quot;Ignored&quot; in the &quot;Indicators&quot; array.</li>=
</ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Add new option to calculate and record additional hash types when the &quot=
;generate metadata JSON&quot; feature is enabled:</div>
</li><ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; =
padding-right: 2.5em; padding-left: 2.5em; list-style-position: initial; li=
st-style-type: disc; flex-direction: column; display: flex;" data-line=3D"4=
02">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
libclamav option: <span role=3D"presentation" style=3D"font-family: Consola=
s, &quot;Courier New&quot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
CL_SCAN_GENERAL_STORE_EXTRA_HASHES</code></span></li><li style=3D"font-fami=
ly: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, san=
s-serif; font-size: 12pt; color: rgb(0, 0, 0); direction: ltr; align-self: =
start; text-indent: 0px; margin: 0px 0px 0.25em;">
ClamScan option: <span role=3D"presentation" style=3D"font-family: Consolas=
, &quot;Courier New&quot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
--json-store-extra-hashes</code></span>&nbsp;(default off)</li><li style=3D=
"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helv=
etica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direction: ltr; al=
ign-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;"><code style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;">clamd.conf</code></span>&nbsp;option:
<span role=3D"presentation" style=3D"font-family: Consolas, &quot;Courier N=
ew&quot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
JsonStoreExtraHashes</code></span>&nbsp;(default 'no')</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
The file hash is now stored as &quot;sha2-256&quot; instead of &quot;FileMD=
5&quot;. If you enable the &quot;extra hashes&quot; option, then it will al=
so record &quot;md5&quot; and &quot;sha1&quot;.</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Each object scanned now has a unique &quot;Object ID&quot;.</div>
</li></ul>
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Sigtool: Renamed the sigtool option <span style=3D"font-family: Consolas, &=
quot;Courier New&quot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
--sha256</code></span>&nbsp;to
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
--sha2-256</code></span>. The original option is still functional but is de=
precated.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA9b3539fd-970a-47b1-d=
0a0-cccc261995c0" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li></ul>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin: 24px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Ap=
tos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: =
rgb(0, 0, 0);" class=3D"elementToProof" id=3D"other-improvements">
<b>Other improvements</b></div>
<ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; paddi=
ng-right: 2.5em; padding-left: 2.5em; list-style-position: initial; list-st=
yle-type: disc;" data-line=3D"420">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Set a limit on the max-recursion config option. Users will no longer be abl=
e to set max-recursion higher than 100. This change prevents errors on star=
t up or crashes if encountering a file with that many layers of recursion.<=
/div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1264" class=3D"OWAAutoLink" id=3D"OWA3c13d5c6-2912-10cc-3=
1b9-06e0f784edc1" href=3D"https://github.com/Cisco-Talos/clamav/pull/1264">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Build system: CMake improvements to support compiling for the AIX platform.=
 This change is courtesy of GitHub user KamathForAIX.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1387" class=3D"OWAAutoLink" id=3D"OWAcb3fe27d-2a21-0b95-6=
a12-69ed37a5ecbf" href=3D"https://github.com/Cisco-Talos/clamav/pull/1387">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Improve support for extracting malformed zip archives. This change is court=
esy of Frederick Sell.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1460" class=3D"OWAAutoLink" id=3D"OWA2bcaf055-aa27-002f-4=
41d-4f1e16b8de11" href=3D"https://github.com/Cisco-Talos/clamav/pull/1460">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Windows: Code quality improvement for the ClamScan and ClamDScan <span styl=
e=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
--move</code></span>&nbsp;and
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
--remove</code></span>&nbsp;options. This change is courtesy of Maxim Suhan=
ov.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1470" class=3D"OWAAutoLink" id=3D"OWA9d01600b-bf5f-4ecd-5=
fe8-2cac776c02e4" href=3D"https://github.com/Cisco-Talos/clamav/pull/1470">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added file type recognition for an initial set of AI model file types.</div=
>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
The file type is accessible to applications using libclamav via the scan ca=
llback functions and as an optional output parameter to the scan functions:
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
cl_scanfile_ex()</code></span>,
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
cl_scanmap_ex()</code></span>, and
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
cl_scandesc_ex()</code></span>.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
When scanning these files, type will now show &quot;CL_TYPE_AI_MODEL&quot; =
instead of &quot;CL_TYPE_BINARY_DATA&quot;.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1476" class=3D"OWAAutoLink" id=3D"OWA4111942d-456d-7e8e-9=
242-46f7a9e5afb2" href=3D"https://github.com/Cisco-Talos/clamav/pull/1476">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added support for inline comments in ClamAV configuration files. This chang=
e is courtesy of GitHub user userwiths.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1308" class=3D"OWAAutoLink" id=3D"OWA9464f40a-295e-0c47-c=
f4e-cae32e8ef9b4" href=3D"https://github.com/Cisco-Talos/clamav/pull/1308">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Disabled the MyDoom hardcoded/heuristic detection because of false positive=
s.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1495" class=3D"OWAAutoLink" id=3D"OWA6b7582ac-7854-5453-5=
c5f-17693d3135c0" href=3D"https://github.com/Cisco-Talos/clamav/pull/1495">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Sigtool: Added support for creating <span style=3D"font-family: Consolas, &=
quot;Courier New&quot;, monospace;">
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
.cdiff</code></span>&nbsp;and
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
.script</code></span>&nbsp;patch files for CVDs that have underscores in th=
e CVD name. Also improved support for relative paths with the
<span style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
<code style=3D"font-family: Consolas, &quot;Courier New&quot;, monospace;">=
--diff</code></span>&nbsp;command.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1541" class=3D"OWAAutoLink" id=3D"OWAf26094e1-7cd7-6962-c=
2b8-8b2b096cf08f" href=3D"https://github.com/Cisco-Talos/clamav/pull/1541">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Windows: Improved support for file names with UTF-8 characters not found in=
 the ANSI or OEM code pages when printing scan results or showing activity =
in the ClamDTOP monitoring utility. Fixed a bug with opening files with suc=
h names with the Sigtool utility.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1461" class=3D"OWAAutoLink" id=3D"OWA5bdc9dd9-fad1-b957-b=
2df-38f96c7934b7" href=3D"https://github.com/Cisco-Talos/clamav/pull/1461">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1537" class=3D"OWAAutoLink" id=3D"OWA276e8337-7391-f2a7-9=
d26-c1adc8e2f53d" href=3D"https://github.com/Cisco-Talos/clamav/pull/1537">=
GitHub pull request #2</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Improved the code quality of the ZIP module. Added inline documentation.</d=
iv>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1548" class=3D"OWAAutoLink" id=3D"OWA01af6715-9a02-38c8-2=
264-12af8951b2d2" href=3D"https://github.com/Cisco-Talos/clamav/pull/1548">=
GitHub pull request #1</a></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1552" class=3D"OWAAutoLink" id=3D"OWA080a9607-3f41-7bf2-3=
683-75135568b0ee" href=3D"https://github.com/Cisco-Talos/clamav/pull/1552">=
GitHub pull request #2</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Always run scan callbacks for embedded files. Embedded files are found with=
in other files through signature matches instead of by parsing. They will n=
ow be processed the same way and then they can trigger application callback=
s (e.g., &quot;pre-scan&quot;, &quot;post-scan&quot;,
 etc.).</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
This change will impact scans with both the &quot;leave-temps&quot; feature=
 and the &quot;force-to-disk&quot; feature enabled, resulting in additional=
 temporary files.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWAa6bfd472-fff7-ba1e-e=
f79-2fb7b13b171f" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Added DevContainer templates to the ClamAV Git repository in order to make =
it easier to set up AlmaLinux or Debian development environments.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1462" class=3D"OWAAutoLink" id=3D"OWAeac2ac24-962c-ea25-4=
d3f-e9d9384f0fa1" href=3D"https://github.com/Cisco-Talos/clamav/pull/1462">=
GitHub pull request</a></div>
</li></ul>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin: 24px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Ap=
tos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: =
rgb(0, 0, 0);" class=3D"elementToProof" id=3D"bug-fixes">
<b>Bug fixes</b></div>
<ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; paddi=
ng-right: 2.5em; padding-left: 2.5em; list-style-position: initial; list-st=
yle-type: disc;" data-line=3D"501">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Reduced email multipart message parser complexity.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1347" class=3D"OWAAutoLink" id=3D"OWAb2f1fffe-7b54-ee0a-1=
fdf-9eed6fe507b8" href=3D"https://github.com/Cisco-Talos/clamav/pull/1347">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Fixed possible undefined behavior in inflate64 module. The inflate64 module=
 is a modified version of the zlib library, taken from version 1.2.3 with s=
ome customization and with some cherry-picked fixes. This adds one addition=
al fix from zlib 1.2.9. Thank you
 to TITAN Team for reporting this issue.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1469" class=3D"OWAAutoLink" id=3D"OWA4f264ad1-e7fe-d507-e=
955-86ed2c6e5198" href=3D"https://github.com/Cisco-Talos/clamav/pull/1469">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Fixed a bug in ClamD that broke reporting of memory usage on Linux. The STA=
TS command can be used to monitor ClamD directly or through ClamDTOP. The m=
emory stats feature does not work on all platforms (e.g., Windows).</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1465" class=3D"OWAAutoLink" id=3D"OWA469e69d0-56c0-4cc5-6=
85d-c876b4886152" href=3D"https://github.com/Cisco-Talos/clamav/pull/1465">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Windows: Fixed a build issue when the same library dependency is found in t=
wo different locations.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1453" class=3D"OWAAutoLink" id=3D"OWA39e46d41-7c04-6eb6-2=
c44-ac86b12fbae2" href=3D"https://github.com/Cisco-Talos/clamav/pull/1453">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Fixed an infinite loop when scanning some email files in debug-mode. This f=
ix is courtesy of Yoann Lecuyer.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1445" class=3D"OWAAutoLink" id=3D"OWAce6c0913-219e-047d-7=
53d-cd68f0662737" href=3D"https://github.com/Cisco-Talos/clamav/pull/1445">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Fixed a stack buffer overflow bug in the phishing signature load process. T=
his fix is courtesy of GitHub user Shivam7-1.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1486" class=3D"OWAAutoLink" id=3D"OWA42eceebe-2ddb-4dc0-0=
ba1-624b37ac1e82" href=3D"https://github.com/Cisco-Talos/clamav/pull/1486">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Fixed a race condition in the Freshclam feature tests. This fix is courtesy=
 of GitHub user rma-x.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1513" class=3D"OWAAutoLink" id=3D"OWA41e899d6-8785-fb66-a=
c31-e5603031dc73" href=3D"https://github.com/Cisco-Talos/clamav/pull/1513">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Windows: Fixed a 5-byte heap buffer overread in the Windows unit tests. Thi=
s fix is courtesy of GitHub user Sophie0x2E.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1542" class=3D"OWAAutoLink" id=3D"OWA8ade4dde-1ba1-5737-8=
5ea-773519df9e3d" href=3D"https://github.com/Cisco-Talos/clamav/pull/1542">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
Fix double-extraction of OOXML-based office documents.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA69861e15-9e8a-1202-d=
25b-52109369e442" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); d=
irection: ltr; text-indent: 0px; margin: 0px 0px 0.25em;">
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em;" role=3D"presentation" class=3D"elementToProo=
f">
ClamBC: Fixed crashes on startup.</div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin-to=
p: 0px; margin-bottom: 0.7em; color: rgb(0, 95, 184);" role=3D"presentation=
" class=3D"elementToProof">
<a style=3D"color: rgb(0, 95, 184);" data-href=3D"https://github.com/Cisco-=
Talos/clamav/pull/1532" class=3D"OWAAutoLink" id=3D"OWA8b7ea716-560e-679d-b=
d98-52c08bb21a4f" href=3D"https://github.com/Cisco-Talos/clamav/pull/1532">=
GitHub pull request</a></div>
</li></ul>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; line-heig=
ht: 1.25; margin: 24px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Ap=
tos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: =
rgb(0, 0, 0);" class=3D"elementToProof" id=3D"acknowledgments">
<b>Acknowledgments</b></div>
<div style=3D"direction: ltr; text-align: left; text-indent: 0px; margin: 0=
px 0px 16px; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=
=3D"elementToProof">
Special thanks to the following people for code contributions and bug repor=
ts:</div>
<ul style=3D"direction: ltr; text-align: left; margin: 0px 0px 0.7em; paddi=
ng-right: 2.5em; padding-left: 2.5em; list-style-position: initial; list-st=
yle-type: disc; flex-direction: column; display: flex;" data-line=3D"555">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); direct=
ion: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.25em;">
b1tg</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontS=
ervice, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0=
); direction: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.2=
5em;">
ChaoticByte</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_=
MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(=
0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0px =
0px 0.25em;">
Frederick Sell</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Apt=
os_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: r=
gb(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0=
px 0px 0.25em;">
KamathForAIX</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos=
_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb=
(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0px=
 0px 0.25em;">
Mark Carey at SAP</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, =
Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color=
: rgb(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin=
: 0px 0px 0.25em;">
Maxim Suhanov</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Apto=
s_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rg=
b(0, 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0p=
x 0px 0.25em;">
rma-x</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFont=
Service, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, =
0); direction: ltr; align-self: start; text-indent: 0px; margin: 0px 0px 0.=
25em;">
Shivam7-1</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MS=
FontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0,=
 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0px 0p=
x 0.25em;">
Sophie0x2E</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_M=
SFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0=
, 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0px 0=
px 0.25em;">
TITAN Team</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_M=
SFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0=
, 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0px 0=
px 0.25em;">
userwiths</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MS=
FontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0,=
 0, 0); direction: ltr; align-self: start; text-indent: 0px; margin: 0px 0p=
x 0.25em;">
Yoann Lecuyer</li></ul>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div id=3D"Signature">
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0);">
Respectfully,</div>
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0);">
Val</div>
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0);">
<br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Valerie Snyder (sh=
e/they)</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">ClamAV Development=
</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Talos</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Cisco Systems, Inc=
.</span><br>
</div>
</div>
</body>
</html>

--_000_CH3PR11MB8750A6128542C2A00A343393C633ACH3PR11MB8750namp_--

--===============5516589023394447032==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________

clamav-announce mailing list
[email protected]
https://lists.clamav.net/mailman/listinfo/clamav-announce

http://www.clamav.net/contact.html#ml

--===============5516589023394447032==--