Release date:
2026-09-13 09:22:56 UTC
Description:
* SECURITY UPDATE: heap buffer overflow via an integer overflow in the PE
rebuilder
- debian/patches/CVE-2026-20213.patch: sum rebuilt section sizes in a
64-bit temporary and reject packed section totals or allocations that
exceed CLI_MAX_ALLOCATION in libclamav/rebuildpe.c.
- CVE-2026-20213
* SECURITY UPDATE: out-of-bounds write via a section loop underflow in the
FSG unpacker
- debian/patches/CVE-2026-20214.patch: iterate the section loop with
t < sectcnt instead of t <= sectcnt - 1, which underflows when sectcnt
is zero, in libclamav/pe.c.
- CVE-2026-20214
* SECURITY UPDATE: heap buffer overflow via a 7z substream count overflow
- debian/patches/CVE-2026-20215.patch: reject archives whose total
unpack-stream count would overflow UInt32 before it is accumulated in
libclamav/7z/7zIn.c.
- CVE-2026-20215
* SECURITY UPDATE: denial of service via unenforced extraction limits in
the InstallShield parser
- debian/patches/CVE-2026-20216.patch: apply cli_checklimits() to header
parsing and to cab extraction output, and guard the output size
accumulator against overflow, in libclamav/ishield.c.
- CVE-2026-20216
* SECURITY UPDATE: invalid free via incorrect cleanup bitmap tracking in
the PESpin unpacker
- debian/patches/CVE-2026-20217.patch: shift the bitmap that the cleanup
loop tests, not the unrelated bitman variable, in libclamav/spin.c.
- CVE-2026-20217
* SECURITY UPDATE: denial of service via size handling errors in the ALZ
parser
- debian/patches/CVE-2026-20243.patch: harden ALZ size arithmetic,
extract stored, bzip2 and deflate members under scan budgets, use
bounded flate2 reads and drop the inflate dependency, in
libclamav_rust/src/{alz,scanners,util,sys}.rs, libclamav_rust/Cargo.toml,
libclamav_rust/build.rs, libclamav/libclamav.map and Cargo.lock.
- CVE-2026-20243
* SECURITY UPDATE: out-of-bounds read via integer overflow in the DMG mish
size checks on 32-bit platforms
- debian/patches/CVE-2026-20244.patch: compute the expected mish block
length in a 64-bit integer, keep the XML range check in subtraction
form and avoid overflow in the base64 buffer size, in libclamav/dmg.c.
- CVE-2026-20244
Updated packages:
-
clamav_1.4.3+dfsg-1~deb11u1+tuxcare.els1_amd64.deb
sha:6252e8ab4d664ea1447447922007ceab3ec17563
-
clamav-base_1.4.3+dfsg-1~deb11u1+tuxcare.els1_all.deb
sha:1e06ba6ccb536e8a339ba9c4d3d669e1c93757f5
-
clamav-daemon_1.4.3+dfsg-1~deb11u1+tuxcare.els1_amd64.deb
sha:8bb76dbbea994564fc416d0edc3cc5c950486e1a
-
clamav-doc_1.4.3+dfsg-1~deb11u1+tuxcare.els1_all.deb
sha:f589c41443726f36c0f9ac2e422d86a065e9fafa
-
clamav-docs_1.4.3+dfsg-1~deb11u1+tuxcare.els1_all.deb
sha:ff92a48358560e7ae7663648307e4e1def8e998d
-
clamav-freshclam_1.4.3+dfsg-1~deb11u1+tuxcare.els1_amd64.deb
sha:31c83d75a69ac64d893245a0f2c80d4306754481
-
clamav-milter_1.4.3+dfsg-1~deb11u1+tuxcare.els1_amd64.deb
sha:eea84319207f3a99d63e5d2909985e1191255a94
-
clamav-testfiles_1.4.3+dfsg-1~deb11u1+tuxcare.els1_all.deb
sha:e5996f723b108ea278b22e313ed6c10cd5504b43
-
clamdscan_1.4.3+dfsg-1~deb11u1+tuxcare.els1_amd64.deb
sha:4aeb41e6753fb40e25089d9407a7f7d0697c3562
-
libclamav-dev_1.4.3+dfsg-1~deb11u1+tuxcare.els1_amd64.deb
sha:d2cd099e34e3c20448a45c7d6fe51070d39e070d
-
libclamav12_1.4.3+dfsg-1~deb11u1+tuxcare.els1_amd64.deb
sha:9ea70edf987c16e44850b14ba674225d10b5a9a5
-
clamav_1.4.3+dfsg-1~deb11u1+tuxcare.els1_arm64.deb
sha:43643ba06d224dee0deef5e840c1e1df4b9ba3b8
-
clamav-daemon_1.4.3+dfsg-1~deb11u1+tuxcare.els1_arm64.deb
sha:9b5f11908264eeefb9d2b01ef5d37fb26778a9d3
-
clamav-freshclam_1.4.3+dfsg-1~deb11u1+tuxcare.els1_arm64.deb
sha:6c30d08f2bcea80b20093e74d85797931dfec9df
-
clamav-milter_1.4.3+dfsg-1~deb11u1+tuxcare.els1_arm64.deb
sha:fe90c46937db3a1e330e0909f24784b9abcca5fc
-
clamdscan_1.4.3+dfsg-1~deb11u1+tuxcare.els1_arm64.deb
sha:5c893039898dd4cc711df30a1c588557f269c7b0
-
libclamav-dev_1.4.3+dfsg-1~deb11u1+tuxcare.els1_arm64.deb
sha:76433f52728d3a31d47a429ddfce105a94dd273a
-
libclamav12_1.4.3+dfsg-1~deb11u1+tuxcare.els1_arm64.deb
sha:b779c378b36a91d26777414fc779bd3714faa02e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.