openSUSE-SU-2026:21252-1: important: Security update for clamav

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for clamav
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21252-1
Rating: important
References:

  * bsc#1270085
  * bsc#1270088
  * bsc#1270089
  * bsc#1270091
  * bsc#1270092
  * bsc#1270106
  * bsc#1270107
  * bsc#1270138



Cross-References:

  * CVE-2026-20213
  * CVE-2026-20214
  * CVE-2026-20215
  * CVE-2026-20216
  * CVE-2026-20217
  * CVE-2026-20243
  * CVE-2026-20244
  * CVE-2026-41676



CVSS scores:

  * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
  * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N

Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 8 vulnerabilities and has 8 bug fixes can now be installed.

Description:

This update for clamav fixes the following issues:

Update to version 1.5.3.

Security issues fixed:

- CVE-2026-20213: out-of-bounds write due to improper boundary checks for content in PE files during scanning
  (bsc#1270107).
- CVE-2026-20214: out-of-bounds write due to improper boundary checks for content in FSG files during scanning
  (bsc#1270085).
- CVE-2026-20215: out-of-bounds write due to improper boundary checks for content in 7z files during scanning
  (bsc#1270088).
- CVE-2026-20216: denial of service due to improper handling of temporary resources during InstallShield file scanning
  (bsc#1270089).
- CVE-2026-20217: out-of-bounds write due to improper boundary checks for content in PESpin files during scanning
  (bsc#1270091).
- CVE-2026-20243: out-of-bounds write due to improper boundary checks for content in ALZ files during scanning
  (bsc#1270092).
- CVE-2026-20244: integer overflow and DoS due to improper boundary checks for content in DMG files during scanning
  (bsc#1270106).
- CVE-2026-41676: buffer overflow due to missing checks via `Deriver:derive`, `PkeyCtxRef:derive` and OpenSSL 1.1.1
  (bsc#1270138).

Other updates and bugfixes:

- Version 1.5.3:
 * Fixed a bug in the PESpin unpacker cleanup path that could free pointers into the scanned file buffer and crash the
   scanner.
 * Fixed an integer overflow in PE rebuild size calculations that could be reached through a malformed Aspack-packed PE
   file and lead to a heap buffer overflow write.
 * Fixed an InstallShield archive extraction limit bypass that could write far more temporary data than intended and
   exhaust temporary storage.
 * Fixed an FSG unpacker loop underflow that could write past the section array while scanning a malformed PE file.
 * Fixed ALZ parser size handling bugs that could cause malformed ALZ archives to panic, abort the scanner, or skip
   expected scan-limit handling.
 * Fixed a 7z parser substream count overflow that could under-allocate parser metadata arrays and write past them
   while reading a malformed archive.
 * Fixed 32-bit DMG parser size checks that could let a short mish stripe table pass validation and crash 32-bit
   scanner builds.
 * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time-of-check/time-of-use races that could
   redirect copied, moved, or removed files under unsafe quarantine directory configurations.
 * Upgraded the Rust tar dependency to resolve the RUSTSEC-2026-0067 and RUSTSEC-2026-0068 advisories, and upgraded the
   Rust openssl dependency to resolve CVE-2026-41676.
 * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static
   library dependencies.
 * Metadata preclass scans now run before the final scan verdict.
 * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path.
 * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket.


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-1173=1

Package List:

- openSUSE Leap 16.0:

  clamav-1.5.3-160000.1.1
  clamav-devel-1.5.3-160000.1.1
  clamav-docs-html-1.5.3-160000.1.1
  clamav-milter-1.5.3-160000.1.1
  libclamav12-1.5.3-160000.1.1
  libclammspack0-1.5.3-160000.1.1
  libfreshclam4-1.5.3-160000.1.1

References:

  * https://www.suse.com/security/cve/CVE-2026-20213.html
  * https://www.suse.com/security/cve/CVE-2026-20214.html
  * https://www.suse.com/security/cve/CVE-2026-20215.html
  * https://www.suse.com/security/cve/CVE-2026-20216.html
  * https://www.suse.com/security/cve/CVE-2026-20217.html
  * https://www.suse.com/security/cve/CVE-2026-20243.html
  * https://www.suse.com/security/cve/CVE-2026-20244.html
  * https://www.suse.com/security/cve/CVE-2026-41676.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.