openSUSE-SU-2026:21252-1: important: Security update for clamav
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <[email protected]> |
openSUSE security update: security update for clamav
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21252-1
Rating: important
References:
* bsc#1270085
* bsc#1270088
* bsc#1270089
* bsc#1270091
* bsc#1270092
* bsc#1270106
* bsc#1270107
* bsc#1270138
Cross-References:
* CVE-2026-20213
* CVE-2026-20214
* CVE-2026-20215
* CVE-2026-20216
* CVE-2026-20217
* CVE-2026-20243
* CVE-2026-20244
* CVE-2026-41676
CVSS scores:
* CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 8 vulnerabilities and has 8 bug fixes can now be installed.
Description:
This update for clamav fixes the following issues:
Update to version 1.5.3.
Security issues fixed:
- CVE-2026-20213: out-of-bounds write due to improper boundary checks for content in PE files during scanning
(bsc#1270107).
- CVE-2026-20214: out-of-bounds write due to improper boundary checks for content in FSG files during scanning
(bsc#1270085).
- CVE-2026-20215: out-of-bounds write due to improper boundary checks for content in 7z files during scanning
(bsc#1270088).
- CVE-2026-20216: denial of service due to improper handling of temporary resources during InstallShield file scanning
(bsc#1270089).
- CVE-2026-20217: out-of-bounds write due to improper boundary checks for content in PESpin files during scanning
(bsc#1270091).
- CVE-2026-20243: out-of-bounds write due to improper boundary checks for content in ALZ files during scanning
(bsc#1270092).
- CVE-2026-20244: integer overflow and DoS due to improper boundary checks for content in DMG files during scanning
(bsc#1270106).
- CVE-2026-41676: buffer overflow due to missing checks via `Deriver:derive`, `PkeyCtxRef:derive` and OpenSSL 1.1.1
(bsc#1270138).
Other updates and bugfixes:
- Version 1.5.3:
* Fixed a bug in the PESpin unpacker cleanup path that could free pointers into the scanned file buffer and crash the
scanner.
* Fixed an integer overflow in PE rebuild size calculations that could be reached through a malformed Aspack-packed PE
file and lead to a heap buffer overflow write.
* Fixed an InstallShield archive extraction limit bypass that could write far more temporary data than intended and
exhaust temporary storage.
* Fixed an FSG unpacker loop underflow that could write past the section array while scanning a malformed PE file.
* Fixed ALZ parser size handling bugs that could cause malformed ALZ archives to panic, abort the scanner, or skip
expected scan-limit handling.
* Fixed a 7z parser substream count overflow that could under-allocate parser metadata arrays and write past them
while reading a malformed archive.
* Fixed 32-bit DMG parser size checks that could let a short mish stripe table pass validation and crash 32-bit
scanner builds.
* Hardened clamscan, clamdscan, and clamonacc quarantine actions against time-of-check/time-of-use races that could
redirect copied, moved, or removed files under unsafe quarantine directory configurations.
* Upgraded the Rust tar dependency to resolve the RUSTSEC-2026-0067 and RUSTSEC-2026-0068 advisories, and upgraded the
Rust openssl dependency to resolve CVE-2026-41676.
* Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static
library dependencies.
* Metadata preclass scans now run before the final scan verdict.
* ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path.
* ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket.
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1173=1
Package List:
- openSUSE Leap 16.0:
clamav-1.5.3-160000.1.1
clamav-devel-1.5.3-160000.1.1
clamav-docs-html-1.5.3-160000.1.1
clamav-milter-1.5.3-160000.1.1
libclamav12-1.5.3-160000.1.1
libclammspack0-1.5.3-160000.1.1
libfreshclam4-1.5.3-160000.1.1
References:
* https://www.suse.com/security/cve/CVE-2026-20213.html
* https://www.suse.com/security/cve/CVE-2026-20214.html
* https://www.suse.com/security/cve/CVE-2026-20215.html
* https://www.suse.com/security/cve/CVE-2026-20216.html
* https://www.suse.com/security/cve/CVE-2026-20217.html
* https://www.suse.com/security/cve/CVE-2026-20243.html
* https://www.suse.com/security/cve/CVE-2026-20244.html
* https://www.suse.com/security/cve/CVE-2026-41676.html