Explore top 10 tips to secure your open-source projects now. Read More
×
Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0271.html Type: security Affected Mageia releases: 10 CVE: CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244 Description: The updated packages fix security vulnerabilities: PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20213) FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20214) 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20215) InstallShield File Format Processing Resource Exhaustion Vulnerability. (CVE-2026-20216) PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20217) ALZ Archive Processing Denial of Service Vulnerability. (CVE-2026-20243) DMG File Processing Denial of Service Vulnerability. (CVE-2026-20244) References: - https://bugs.mageia.org/show_bug.cgi?id=35841 - https://lists.fedoraproject.org/archives/list/
An update that solves eight vulnerabilities can now be installed.. # Security update for clamav Announcement ID: SUSE-SU-2026:2833-1 Release Date: 2026-07-09T19:11:01Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues * CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107). * CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085). * CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088). * CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089). * CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091). * CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092). * CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106). * CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270138). Changes for clamav: * Update to 1.5.3: * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. *Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2833=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2833=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-debuginfo-1.5.3-3.56.1 * libfreshclam4-debuginfo-1.5.3-3.56.1 * clamav-devel-1.5.3-3.56.1 * clamav-debuginfo-1.5.3-3.56.1 * libclamav12-1.5.3-3.56.1 * libclamav12-debuginfo-1.5.3-3.56.1 * clamav-milter-1.5.3-3.56.1 * clamav-1.5.3-3.56.1 * clamav-milter-debuginfo-1.5.3-3.56.1 * clamav-debugsource-1.5.3-3.56.1 * libfreshclam4-1.5.3-3.56.1 * libclammspack0-1.5.3-3.56.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * clamav-docs-html-1.5.3-3.56.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libclammspack0-debuginfo-1.5.3-3.56.1 * libfreshclam4-debuginfo-1.5.3-3.56.1 * clamav-devel-1.5.3-3.56.1 * clamav-debuginfo-1.5.3-3.56.1 * libclamav12-1.5.3-3.56.1 * clamav-milter-1.5.3-3.56.1 * libclamav12-debuginfo-1.5.3-3.56.1 * clamav-1.5.3-3.56.1 * clamav-debugsource-1.5.3-3.56.1 * clamav-milter-debuginfo-1.5.3-3.56.1 * libfreshclam4-1.5.3-3.56.1 * libclammspack0-1.5.3-3.56.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * clamav-docs-html-1.5.3-3.56.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html *https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html * https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 . This important update for clamav addresses eight distinct security issues in SUSE Linux. Install now to safeguard your system.. clamav update, security issues, SUSE Linux, vulnerability patch, software vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves eight vulnerabilities can now be installed.. # Security update for clamav Announcement ID: SUSE-SU-2026:2834-1 Release Date: 2026-07-09T19:12:56Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues * CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107). * CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085). * CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088). * CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089). * CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091). * CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092). * CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106). * CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL1.1.1 (bsc#1270138). Changes for clamav: * Update to 1.5.3: * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2834=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2834=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2834=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2834=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2834=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2834=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2834=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2834=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2834=1 ## Package List: * SUSE LinuxEnterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * openSUSE Leap 15.4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 *SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSELinux Enterprise Server for SAP Applications 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 *libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html * https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 . An important security update for ClamAV to address multiple issues including denial of service vulnerabilities.. clamav update important security SUSE. . Severity: Important. LinuxSecurity.com Team
An update that solves eight vulnerabilities can now be installed.. # Security update for clamav Announcement ID: SUSE-SU-2026:2834-1 Release Date: 2026-07-09T19:12:56Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues * CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107). * CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085). * CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088). * CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089). * CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091). * CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092). * CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106). * CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL1.1.1 (bsc#1270138). Changes for clamav: * Update to 1.5.3: * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2834=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2834=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2834=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2834=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2834=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2834=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2834=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2834=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2834=1 ## Package List: * SUSE LinuxEnterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * openSUSE Leap 15.4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 *SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSELinux Enterprise Server for SAP Applications 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 *libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html * https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 . An important security update for clamav in openSUSE addresses eight vulnerabilities and enhances system safety.. clamav update, SUSE advisory, security patch, openSUSE vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves eight vulnerabilities can now be installed.. # Security update for clamav Announcement ID: SUSE-SU-2026:2835-1 Release Date: 2026-07-09T19:13:18Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues * CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107). * CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085). * CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088). * CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089). * CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091). * CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092). * CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106). * CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270138). Changes for clamav: * Update to 1.5.3: * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Raised the minimum requiredCMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2835=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2835=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2835=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2835=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * Basesystem Module 15-SP7 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 *clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * openSUSE Leap 15.6 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html *https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 . # Security update for clamav Announcement ID: SUSE-SU-2026:2835-1 Release Date: 2026-07-09T19:13:18Z. update, solves, eight, vulnerabilities, installed, security, clamav, annou. . Severity: Important. LinuxSecurity.com Team
An update that solves eight vulnerabilities can now be installed.. # Security update for clamav Announcement ID: SUSE-SU-2026:2835-1 Release Date: 2026-07-09T19:13:18Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues * CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107). * CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085). * CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088). * CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089). * CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091). * CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092). * CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106). * CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270138). Changes for clamav: * Update to 1.5.3: * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Raised the minimum requiredCMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2835=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2835=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2835=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2835=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * Basesystem Module 15-SP7 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 *clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * openSUSE Leap 15.6 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html *https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 . An important security update for clamav addresses eight vulnerabilities to prevent potential service issues on SUSE.. clamav security update, suse fixes, denial of service vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in ClamAV.. ========================================================================== Ubuntu Security Notice USN-8517-1 July 08, 2026 clamav vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in ClamAV. Software Description: - clamav: Anti-virus utility for Unix Details: It was discovered that ClamAV incorrectly handled certain PE files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20213, CVE-2026-20214, CVE-2026-20217) It was discovered that ClamAV incorrectly handled certain 7z archive files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20215) It was discovered that ClamAV incorrectly handled extraction limits for certain InstallShield archives. A remote attacker could possibly use this issue to cause ClamAV to use excessive resources, leading to a denial of service. (CVE-2026-20216) It was discovered that ClamAV incorrectly handled certain ALZ archive files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20243) It was discovered that ClamAV incorrectly handled certain DMG files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20244) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS clamav 1.5.3+dfsg-0ubuntu0.26.04.1 Ubuntu 24.04 LTS clamav 1.5.3+dfsg-0ubuntu0.24.04.1 Ubuntu 22.04 LTS clamav 1.5.3+dfsg-0ubuntu0.22.04.2 This update uses a new upstream release, which includes additional bug fixes. In general, astandard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8517-1 CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244 Package Information: https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1 https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1 https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2 . Several security issues in ClamAV can lead to system crashes. Ensure to update your Ubuntu systems to remediate these risks.. ClamAV Updates, Ubuntu Security, Denial of Service Risks, ClamAV Vulnerabilities, Ubuntu Advisory. . Severity: Important. LinuxSecurity.com Team
An update that solves 8 vulnerabilities and has 8 bug fixes can now be installed.. openSUSE security update: security update for clamav ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21252-1 Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 8 vulnerabilities and has 8 bug fixes can now be installed. Description: This update for clamav fixes the following issues: Update to version 1.5.3. Security issues fixed: - CVE-2026-20213: out-of-bounds write due to improper boundary checks for content in PE files during scanning (bsc#1270107). - CVE-2026-20214: out-of-bounds write due to improper boundary checks for content in FSG files during scanning (bsc#1270085). - CVE-2026-20215: out-of-bounds write due to improper boundary checks for content in 7z files during scanning (bsc#1270088). - CVE-2026-20216: denial of service dueto improper handling of temporary resources during InstallShield file scanning (bsc#1270089). - CVE-2026-20217: out-of-bounds write due to improper boundary checks for content in PESpin files during scanning (bsc#1270091). - CVE-2026-20243: out-of-bounds write due to improper boundary checks for content in ALZ files during scanning (bsc#1270092). - CVE-2026-20244: integer overflow and DoS due to improper boundary checks for content in DMG files during scanning (bsc#1270106). - CVE-2026-41676: buffer overflow due to missing checks via `Deriver:derive`, `PkeyCtxRef:derive` and OpenSSL 1.1.1 (bsc#1270138). Other updates and bugfixes: - Version 1.5.3: * Fixed a bug in the PESpin unpacker cleanup path that could free pointers into the scanned file buffer and crash the scanner. * Fixed an integer overflow in PE rebuild size calculations that could be reached through a malformed Aspack-packed PE file and lead to a heap buffer overflow write. * Fixed an InstallShield archive extraction limit bypass that could write far more temporary data than intended and exhaust temporary storage. * Fixed an FSG unpacker loop underflow that could write past the section array while scanning a malformed PE file. * Fixed ALZ parser size handling bugs that could cause malformed ALZ archives to panic, abort the scanner, or skip expected scan-limit handling. * Fixed a 7z parser substream count overflow that could under-allocate parser metadata arrays and write past them while reading a malformed archive. * Fixed 32-bit DMG parser size checks that could let a short mish stripe table pass validation and crash 32-bit scanner builds. * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time-of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Upgraded the Rust tar dependency to resolve the RUSTSEC-2026-0067 and RUSTSEC-2026-0068 advisories, and upgraded the Rust openssl dependency to resolveCVE-2026-41676. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1173=1 Package List: - openSUSE Leap 16.0: clamav-1.5.3-160000.1.1 clamav-devel-1.5.3-160000.1.1 clamav-docs-html-1.5.3-160000.1.1 clamav-milter-1.5.3-160000.1.1 libclamav12-1.5.3-160000.1.1 libclammspack0-1.5.3-160000.1.1 libfreshclam4-1.5.3-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html * https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html . Severity update for clamav in openSUSE fixes 8 security issues including buffer overflow and DoS vulnerabilities. Install recommended patches.. clamav security update, openSUSE vulnerabilities, important patch release, clamav DoS fix, openSUSE advisory security. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.