ClamAV 1.5.2 and 1.4.4 security patch versions published
"Valerie Snyder \(valsnyde\) via clamav-users" <[email protected]> Wed, 4 Mar 2026 18:35:34 +0000
| Newsgroups | gmane.comp.security.virus.clamav.user |
|---|---|
| Message-ID | <CH3PR11MB875099C72AB63F1E7D4355AEDE7CA__46332.8372150258$1772649408$gmane$org@CH3PR11MB8750.namprd11.prod.outlook.com> |
--===============4595612091574824409==
Content-Language: en-US
Content-Type: multipart/alternative;
boundary="_000_CH3PR11MB875099C72AB63F1E7D4355AEDE7CACH3PR11MB8750namp_"
--_000_CH3PR11MB875099C72AB63F1E7D4355AEDE7CACH3PR11MB8750namp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Read this online at https://blog.clamav.net/2026/03/clamav-152-and-144-secu=
rity-patch.html
Today, we are publishing the 1.5.2 and 1.4.4 security patch versions.
The release files for the patch versions are available for download on the =
ClamAV downloads<https://www.clamav.net/downloads> page, on the GitHub Rele=
ase page<https://github.com/Cisco-Talos/clamav/releases>, and through Docke=
r Hub with both Alpine<https://hub.docker.com/r/clamav/clamav/> and Debian<=
https://hub.docker.com/r/clamav/clamav-debian/> containers. The images on D=
ocker Hub may not be immediately available on release day. Continue reading=
to learn what changed in each version.
1.5.2
ClamAV 1.5.2 is a patch release with the following fixes:
* CVE-2026-20031<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2=
026-20031>: Fixed an error handling bug in the HTML file parser that may cr=
ash the program and cause a denial-of-service (DoS) condition. This issue w=
as introduced in version 1.1.0. The fix is included in 1.5.2 and 1.4.4.
* Fixed a possible infinite loop when scanning some JPEG files by upgra=
ding affected ClamAV dependency, a Rust image library.
* Unfortunately, this change requires a newer Rust compiler for ClamAV.
The minimum Rust version for ClamAV 1.4.3 was 1.85.1.
The minimum Rust version for ClamAV 1.4.4 is now 1.87.0.
* Fixed a possible crash on Windows when scanning some files while usin=
g the LeaveTemporaryFiles and TemporaryDirectory features.
* The CVD verification process will now ignore certificate files in the=
CVD certs directory when the user lacks read permissions.
* Freshclam: Fix CLD verification bug with PrivateMirror option.
* Upgraded the Rust bytes dependency to a newer version to resolve RUST=
SEC-2026-0007 advisory.
*
Fixed a possible crash caused by invalid pointer alignment on some platform=
s. This fix is courtesy of Hsuan-Ming Chen at Synology PSIRT.
1.4.4
ClamAV 1.4.4 is a patch release with the following fixes:
* CVE-2026-20031<https://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2=
026-20031>: Fixed an error handling bug in the HTML file parser that may cr=
ash the program and cause a DoS condition. This issue was introduced in ver=
sion 1.1.0. The fix is included in 1.5.2 and 1.4.4.
* Fixed a possible crash when scanning some TIFF files by upgrading the=
affected ClamAV dependency, a Rust image library.
* Unfortunately, this change requires a newer Rust compiler for ClamAV.
The minimum Rust version for ClamAV 1.4.3 was 1.85.1.
The minimum Rust version for ClamAV 1.4.4 is now 1.87.0.
* Upgraded the Rust bytes dependency to a newer version to resolve RUST=
SEC-2026-0007 advisory.
* Fixed a possible crash caused by invalid pointer alignment on some pl=
atforms. This fix is courtesy of Hsuan-Ming Chen at Synology PSIRT.
Respectfully,
Val
Valerie Snyder (she/they)
ClamAV Development
Talos
Cisco Systems, Inc.
--_000_CH3PR11MB875099C72AB63F1E7D4355AEDE7CACH3PR11MB8750namp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 10pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<i>Read this online at <a href=3D"https://blog.clamav.net/2026/03/clamav-15=
2-and-144-security-patch.html">
https://blog.clamav.net/2026/03/clamav-152-and-144-security-patch.html</a><=
/i></div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div style=3D"margin-top: 1em; margin-bottom: 1em; font-family: Aptos, Apto=
s_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-s=
ize: 12pt; color: rgb(0, 0, 0);" class=3D"elementToProof">
Today, we are publishing the 1.5.2 and 1.4.4 security patch versions. =
</div>
<div style=3D"margin-top: 1em; margin-bottom: 1em; font-family: Aptos, Apto=
s_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-s=
ize: 12pt;" class=3D"elementToProof">
<span style=3D"color: rgb(0, 0, 0);">The release files for the patch versio=
ns are available for download on the
</span><span style=3D"color: rgb(239, 62, 66);"><a style=3D"color: rgb(239,=
62, 66);" rel=3D"nofollow" class=3D"OWAAutoLink" id=3D"OWAab663232-3b67-68=
1e-8b7c-f4e4bddf0211" target=3D"_blank" href=3D"https://www.clamav.net/down=
loads">ClamAV downloads</a></span><span style=3D"color: rgb(0, 0, 0);">&nbs=
p;page,
on the </span><span style=3D"color: rgb(239, 62, 66);"><a style=3D"color: =
rgb(239, 62, 66);" rel=3D"nofollow" class=3D"OWAAutoLink" id=3D"OWA6c623ff6=
-2bfd-ec11-abaf-71e277ba3f12" target=3D"_blank" href=3D"https://github.com/=
Cisco-Talos/clamav/releases">GitHub Release page</a></span><span style=3D"c=
olor: rgb(0, 0, 0);">,
and through Docker Hub with both </span><span style=3D"color: rgb(239, 62,=
66);"><a style=3D"color: rgb(239, 62, 66);" rel=3D"nofollow" class=3D"OWAA=
utoLink" id=3D"OWA02d21e64-b558-8902-12b2-47db3643ff23" target=3D"_blank" h=
ref=3D"https://hub.docker.com/r/clamav/clamav/">Alpine</a></span><span styl=
e=3D"color: rgb(0, 0, 0);"> and
</span><span style=3D"color: rgb(239, 62, 66);"><a style=3D"color: rgb(239,=
62, 66);" rel=3D"nofollow" class=3D"OWAAutoLink" id=3D"OWA83f30d7d-eb17-7a=
ad-9d7c-7526ec60763d" target=3D"_blank" href=3D"https://hub.docker.com/r/cl=
amav/clamav-debian/">Debian</a></span><span style=3D"color: rgb(0, 0, 0);">=
containers.
The images on Docker Hub may not be immediately available on release day. =
Continue reading to learn what changed in each version. </span></div>
<div style=3D"text-align: left; line-height: normal; margin: 0px 0px 30px; =
font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helve=
tica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=3D"elementTo=
Proof">
<b>1.5.2 </b></div>
<div style=3D"margin-top: 1em; margin-bottom: 1em; font-family: Aptos, Apto=
s_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-s=
ize: 12pt; color: rgb(0, 0, 0);" class=3D"elementToProof">
ClamAV 1.5.2 is a patch release with the following fixes: </div>
<ul style=3D"text-align: left; margin: 0.5em 0px; padding-right: 2.5em; pad=
ding-left: 2.5em; list-style-position: initial; list-style-type: disc;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); text-i=
ndent: 0px; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"color: rgb(239, 62, 66);"><a style=3D"=
color: rgb(239, 62, 66);" rel=3D"nofollow" class=3D"OWAAutoLink" id=3D"OWAb=
b460c21-0474-68b0-cf5c-43fe60822af8" target=3D"_blank" href=3D"https://cve.=
mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2026-20031">CVE-2026-20031</a></sp=
an>:
Fixed an error handling bug in the HTML file parser that may crash the pro=
gram and cause a denial-of-service (DoS) condition. This issue was introduc=
ed in version 1.1.0. The fix is included in 1.5.2 and 1.4.4. </li><li =
style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calib=
ri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); text-inden=
t: 0px; margin: 0px 0px 0.25em;">
Fixed a possible infinite loop when scanning some JPEG files by upgrading a=
ffected ClamAV dependency, a Rust image library. </li><li style=
=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, H=
elvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); text-indent: 0p=
x; margin: 0px 0px 0.25em;">
Unfortunately, this change requires a newer Rust compiler for ClamAV. =
<br>
The minimum Rust version for ClamAV 1.4.3 was 1.85.1. <br>
The minimum Rust version for ClamAV 1.4.4 is now 1.87.0. </li><li styl=
e=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, =
Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); text-indent: 0=
px; margin: 0px 0px 0.25em;">
Fixed a possible crash on Windows when scanning some files while using the&=
nbsp;LeaveTemporaryFiles and TemporaryDirectory features.&nb=
sp;</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontSe=
rvice, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0)=
; text-indent: 0px; margin: 0px 0px 0.25em;">
The CVD verification process will now ignore certificate files in the CVD c=
erts directory when the user lacks read permissions. </li><li style=3D=
"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helv=
etica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); text-indent: 0px; =
margin: 0px 0px 0.25em;">
Freshclam: Fix CLD verification bug with PrivateMirror option. </li><l=
i style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Cal=
ibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); text-ind=
ent: 0px; margin: 0px 0px 0.25em;">
Upgraded the Rust bytes dependency to a newer version to resolve =
RUSTSEC-2026-0007 advisory. </li><li style=3D"font-family: Aptos, Apto=
s_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-s=
ize: 12pt; color: rgb(0, 0, 0); text-indent: 0px; margin: 0px 0px 0.25em;">
<div role=3D"presentation">Fixed a possible crash caused by invalid pointer=
alignment on some platforms. This fix is courtesy of Hsuan-Ming Chen at Sy=
nology PSIRT. </div>
</li></ul>
<div style=3D"margin-right: 0px; margin-left: 0px; font-family: Aptos, Apto=
s_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-s=
ize: 12pt; color: rgb(0, 0, 0);">
<b><br>
</b></div>
<div style=3D"text-align: left; line-height: normal; margin: 0px 0px 30px; =
font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helve=
tica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=3D"elementTo=
Proof">
<b>1.4.4 </b></div>
<div style=3D"margin-top: 1em; margin-bottom: 1em; font-family: Aptos, Apto=
s_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-s=
ize: 12pt; color: rgb(0, 0, 0);" class=3D"elementToProof">
ClamAV 1.4.4 is a patch release with the following fixes: </div>
<ul style=3D"text-align: left; margin: 0.5em 0px; padding-right: 2.5em; pad=
ding-left: 2.5em; list-style-position: initial; list-style-type: disc;">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); text-i=
ndent: 0px; margin: 0px 0px 0.25em;">
<span role=3D"presentation" style=3D"color: rgb(239, 62, 66);"><a style=3D"=
color: rgb(239, 62, 66);" rel=3D"nofollow" class=3D"OWAAutoLink" id=3D"OWA7=
16a4666-93c1-5414-bc2f-b73361f21b3d" target=3D"_blank" href=3D"https://cve.=
mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2026-20031">CVE-2026-20031</a></sp=
an>:
Fixed an error handling bug in the HTML file parser that may crash the pro=
gram and cause a DoS condition. This issue was introduced in version 1.1.0.=
The fix is included in 1.5.2 and 1.4.4. </li><li style=3D"font-family=
: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-=
serif; font-size: 12pt; color: rgb(0, 0, 0); text-indent: 0px; margin: 0px =
0px 0.25em;">
Fixed a possible crash when scanning some TIFF files by upgrading the affec=
ted ClamAV dependency, a Rust image library. </li><li style=3D"font-fa=
mily: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, s=
ans-serif; font-size: 12pt; color: rgb(0, 0, 0); text-indent: 0px; margin: =
0px 0px 0.25em;">
Unfortunately, this change requires a newer Rust compiler for ClamAV.<br>
The minimum Rust version for ClamAV 1.4.3 was 1.85.1.<br>
The minimum Rust version for ClamAV 1.4.4 is now 1.87.0. </li><li styl=
e=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, =
Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); text-indent: 0=
px; margin: 0px 0px 0.25em;">
Upgraded the Rust bytes dependency to a newer version to resolve =
RUSTSEC-2026-0007 advisory. </li><li style=3D"font-family: Aptos, Apto=
s_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-s=
ize: 12pt; color: rgb(0, 0, 0); text-indent: 0px; margin: 0px 0px 0.25em;">
Fixed a possible crash caused by invalid pointer alignment on some platform=
s. This fix is courtesy of Hsuan-Ming Chen at Synology PSIRT. </li></u=
l>
<div style=3D"margin-top: 1em; margin-bottom: 1em; font-family: Aptos, Apto=
s_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-s=
ize: 12pt; color: rgb(0, 0, 0);" class=3D"elementToProof">
<br>
</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div class=3D"elementToProof" id=3D"Signature">
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0);" class=3D"elementToProof">
Respectfully,</div>
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0);" class=3D"elementToProof">
Val</div>
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0);" class=3D"elementToProof">
<br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Valerie Snyder (sh=
e/they)</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">ClamAV Development=
</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Talos</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Cisco Systems, Inc=
.</span><br>
</div>
</div>
</body>
</html>
--_000_CH3PR11MB875099C72AB63F1E7D4355AEDE7CACH3PR11MB8750namp_--
--===============4595612091574824409==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users
Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation
https://docs.clamav.net/#mailing-lists-and-chat
--===============4595612091574824409==--