Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 232 articles for you...
203

Mageia 10 Clamav Moderate Memory Corruption Issues Advisory 2026-0271

Security update. Publication date: 19 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0271.html Type: security Affected Mageia releases: 10 CVE: CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244 Description: The updated packages fix security vulnerabilities: PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20213) FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20214) 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20215) InstallShield File Format Processing Resource Exhaustion Vulnerability. (CVE-2026-20216) PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20217) ALZ Archive Processing Denial of Service Vulnerability. (CVE-2026-20243) DMG File Processing Denial of Service Vulnerability. (CVE-2026-20244) References: - https://bugs.mageia.org/show_bug.cgi?id=35841 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/N4HZVOZRQX4MIQVALYKDCGBZUHHVH4QN/ - https://github.com/Cisco-Talos/clamav/releases/tag/clamav-1.4.5 - https://www.cve.org/CVERecord?id=CVE-2026-20213 - https://www.cve.org/CVERecord?id=CVE-2026-20214 - https://www.cve.org/CVERecord?id=CVE-2026-20215 - https://www.cve.org/CVERecord?id=CVE-2026-20216 - https://www.cve.org/CVERecord?id=CVE-2026-20217 - https://www.cve.org/CVERecord?id=CVE-2026-20243 - https://www.cve.org/CVERecord?id=CVE-2026-20244 SRPMS: - 10/core/clamav-1.4.5-1.mga10 . Mageia security update addresses multiple Out-of-Bounds Memory Corruption and Denial of Service issues in clamav.. Mageia update, clamav security, memory corruption issue, denial of service, security fix. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jul 19, 2026 moderate Mageia
100

SUSE ClamAV Important Denial of Service Issues Vuln 2026-2833-1

An update that solves eight vulnerabilities can now be installed.. # Security update for clamav Announcement ID: SUSE-SU-2026:2833-1 Release Date: 2026-07-09T19:11:01Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues * CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107). * CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085). * CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088). * CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089). * CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091). * CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092). * CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106). * CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270138). Changes for clamav: * Update to 1.5.3: * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. *Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2833=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2833=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-debuginfo-1.5.3-3.56.1 * libfreshclam4-debuginfo-1.5.3-3.56.1 * clamav-devel-1.5.3-3.56.1 * clamav-debuginfo-1.5.3-3.56.1 * libclamav12-1.5.3-3.56.1 * libclamav12-debuginfo-1.5.3-3.56.1 * clamav-milter-1.5.3-3.56.1 * clamav-1.5.3-3.56.1 * clamav-milter-debuginfo-1.5.3-3.56.1 * clamav-debugsource-1.5.3-3.56.1 * libfreshclam4-1.5.3-3.56.1 * libclammspack0-1.5.3-3.56.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * clamav-docs-html-1.5.3-3.56.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libclammspack0-debuginfo-1.5.3-3.56.1 * libfreshclam4-debuginfo-1.5.3-3.56.1 * clamav-devel-1.5.3-3.56.1 * clamav-debuginfo-1.5.3-3.56.1 * libclamav12-1.5.3-3.56.1 * clamav-milter-1.5.3-3.56.1 * libclamav12-debuginfo-1.5.3-3.56.1 * clamav-1.5.3-3.56.1 * clamav-debugsource-1.5.3-3.56.1 * clamav-milter-debuginfo-1.5.3-3.56.1 * libfreshclam4-1.5.3-3.56.1 * libclammspack0-1.5.3-3.56.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * clamav-docs-html-1.5.3-3.56.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html *https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html * https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 . This important update for clamav addresses eight distinct security issues in SUSE Linux. Install now to safeguard your system.. clamav update, security issues, SUSE Linux, vulnerability patch, software vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 10, 2026 Important SuSE
100

SUSE ClamAV Significant Denial of Service Security Patch 2026-2834-1

An update that solves eight vulnerabilities can now be installed.. # Security update for clamav Announcement ID: SUSE-SU-2026:2834-1 Release Date: 2026-07-09T19:12:56Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues * CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107). * CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085). * CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088). * CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089). * CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091). * CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092). * CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106). * CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL1.1.1 (bsc#1270138). Changes for clamav: * Update to 1.5.3: * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2834=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2834=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2834=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2834=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2834=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2834=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2834=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2834=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2834=1 ## Package List: * SUSE LinuxEnterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * openSUSE Leap 15.4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 *SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSELinux Enterprise Server for SAP Applications 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 *libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html * https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 . An important security update for ClamAV to address multiple issues including denial of service vulnerabilities.. clamav update important security SUSE. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 10, 2026 Important SuSE
202

openSUSE clamav Important Denial of Service Fix 2026-2834-1

An update that solves eight vulnerabilities can now be installed.. # Security update for clamav Announcement ID: SUSE-SU-2026:2834-1 Release Date: 2026-07-09T19:12:56Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues * CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107). * CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085). * CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088). * CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089). * CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091). * CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092). * CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106). * CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL1.1.1 (bsc#1270138). Changes for clamav: * Update to 1.5.3: * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2834=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2834=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2834=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2834=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2834=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2834=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2834=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2834=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2834=1 ## Package List: * SUSE LinuxEnterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * openSUSE Leap 15.4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 *SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSELinux Enterprise Server for SAP Applications 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 *libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html * https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 . An important security update for clamav in openSUSE addresses eight vulnerabilities and enhances system safety.. clamav update, SUSE advisory, security patch, openSUSE vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 10, 2026 Important OpenSUSE
202

openSUSE Clamav Important Denial of Service Issues Fix 2026-2835-1

An update that solves eight vulnerabilities can now be installed.. # Security update for clamav Announcement ID: SUSE-SU-2026:2835-1 Release Date: 2026-07-09T19:13:18Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues * CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107). * CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085). * CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088). * CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089). * CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091). * CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092). * CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106). * CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270138). Changes for clamav: * Update to 1.5.3: * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Raised the minimum requiredCMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2835=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2835=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2835=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2835=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * Basesystem Module 15-SP7 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 *clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * openSUSE Leap 15.6 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html *https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 . # Security update for clamav Announcement ID: SUSE-SU-2026:2835-1 Release Date: 2026-07-09T19:13:18Z. update, solves, eight, vulnerabilities, installed, security, clamav, annou. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 10, 2026 Important OpenSUSE
100

SUSE ClamAV Important Denial of Service Vulnerability Fix 2026-2835-1

An update that solves eight vulnerabilities can now be installed.. # Security update for clamav Announcement ID: SUSE-SU-2026:2835-1 Release Date: 2026-07-09T19:13:18Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues * CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107). * CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085). * CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088). * CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089). * CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091). * CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092). * CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106). * CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270138). Changes for clamav: * Update to 1.5.3: * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Raised the minimum requiredCMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2835=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2835=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2835=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2835=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * Basesystem Module 15-SP7 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 *clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * openSUSE Leap 15.6 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html *https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 . An important security update for clamav addresses eight vulnerabilities to prevent potential service issues on SUSE.. clamav security update, suse fixes, denial of service vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 10, 2026 Important SuSE
172

Ubuntu 26.04 ClamAV Important Denial Of Service Vulnerabilities USN-8517-1

Several security issues were fixed in ClamAV.. ========================================================================== Ubuntu Security Notice USN-8517-1 July 08, 2026 clamav vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in ClamAV. Software Description: - clamav: Anti-virus utility for Unix Details: It was discovered that ClamAV incorrectly handled certain PE files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20213, CVE-2026-20214, CVE-2026-20217) It was discovered that ClamAV incorrectly handled certain 7z archive files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20215) It was discovered that ClamAV incorrectly handled extraction limits for certain InstallShield archives. A remote attacker could possibly use this issue to cause ClamAV to use excessive resources, leading to a denial of service. (CVE-2026-20216) It was discovered that ClamAV incorrectly handled certain ALZ archive files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20243) It was discovered that ClamAV incorrectly handled certain DMG files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20244) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS clamav 1.5.3+dfsg-0ubuntu0.26.04.1 Ubuntu 24.04 LTS clamav 1.5.3+dfsg-0ubuntu0.24.04.1 Ubuntu 22.04 LTS clamav 1.5.3+dfsg-0ubuntu0.22.04.2 This update uses a new upstream release, which includes additional bug fixes. In general, astandard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8517-1 CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244 Package Information: https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.26.04.1 https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.24.04.1 https://launchpad.net/ubuntu/+source/clamav/1.5.3+dfsg-0ubuntu0.22.04.2 . Several security issues in ClamAV can lead to system crashes. Ensure to update your Ubuntu systems to remediate these risks.. ClamAV Updates, Ubuntu Security, Denial of Service Risks, ClamAV Vulnerabilities, Ubuntu Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 08, 2026 Important Ubuntu
202

openSUSE ClamAV Important Buffer Overflow and DoS Issues 2026-21252-1

An update that solves 8 vulnerabilities and has 8 bug fixes can now be installed.. openSUSE security update: security update for clamav ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21252-1 Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 8 vulnerabilities and has 8 bug fixes can now be installed. Description: This update for clamav fixes the following issues: Update to version 1.5.3. Security issues fixed: - CVE-2026-20213: out-of-bounds write due to improper boundary checks for content in PE files during scanning (bsc#1270107). - CVE-2026-20214: out-of-bounds write due to improper boundary checks for content in FSG files during scanning (bsc#1270085). - CVE-2026-20215: out-of-bounds write due to improper boundary checks for content in 7z files during scanning (bsc#1270088). - CVE-2026-20216: denial of service dueto improper handling of temporary resources during InstallShield file scanning (bsc#1270089). - CVE-2026-20217: out-of-bounds write due to improper boundary checks for content in PESpin files during scanning (bsc#1270091). - CVE-2026-20243: out-of-bounds write due to improper boundary checks for content in ALZ files during scanning (bsc#1270092). - CVE-2026-20244: integer overflow and DoS due to improper boundary checks for content in DMG files during scanning (bsc#1270106). - CVE-2026-41676: buffer overflow due to missing checks via `Deriver:derive`, `PkeyCtxRef:derive` and OpenSSL 1.1.1 (bsc#1270138). Other updates and bugfixes: - Version 1.5.3: * Fixed a bug in the PESpin unpacker cleanup path that could free pointers into the scanned file buffer and crash the scanner. * Fixed an integer overflow in PE rebuild size calculations that could be reached through a malformed Aspack-packed PE file and lead to a heap buffer overflow write. * Fixed an InstallShield archive extraction limit bypass that could write far more temporary data than intended and exhaust temporary storage. * Fixed an FSG unpacker loop underflow that could write past the section array while scanning a malformed PE file. * Fixed ALZ parser size handling bugs that could cause malformed ALZ archives to panic, abort the scanner, or skip expected scan-limit handling. * Fixed a 7z parser substream count overflow that could under-allocate parser metadata arrays and write past them while reading a malformed archive. * Fixed 32-bit DMG parser size checks that could let a short mish stripe table pass validation and crash 32-bit scanner builds. * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time-of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Upgraded the Rust tar dependency to resolve the RUSTSEC-2026-0067 and RUSTSEC-2026-0068 advisories, and upgraded the Rust openssl dependency to resolveCVE-2026-41676. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1173=1 Package List: - openSUSE Leap 16.0: clamav-1.5.3-160000.1.1 clamav-devel-1.5.3-160000.1.1 clamav-docs-html-1.5.3-160000.1.1 clamav-milter-1.5.3-160000.1.1 libclamav12-1.5.3-160000.1.1 libclammspack0-1.5.3-160000.1.1 libfreshclam4-1.5.3-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html * https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html . Severity update for clamav in openSUSE fixes 8 security issues including buffer overflow and DoS vulnerabilities. Install recommended patches.. clamav security update, openSUSE vulnerabilities, important patch release, clamav DoS fix, openSUSE advisory security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 08, 2026 Important OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200