{"schema_version":"1.7.5","id":"SUSE-SU-2026:2833-1","published":"2026-07-09T19:10:57Z","modified":"2026-07-10T10:00:08.945516733Z","related":["CVE-2026-20213","CVE-2026-20214","CVE-2026-20215","CVE-2026-20216","CVE-2026-20217","CVE-2026-20243","CVE-2026-20244","CVE-2026-41676"],"upstream":["CVE-2026-20213","CVE-2026-20214","CVE-2026-20215","CVE-2026-20216","CVE-2026-20217","CVE-2026-20243","CVE-2026-20244","CVE-2026-41676"],"summary":"Security update for clamav","details":"This update for clamav fixes the following issues\n\n- CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service\n  (bsc#1270107).\n- CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service\n  (bsc#1270085).\n- CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service\n  (bsc#1270088).\n- CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of\n  service (bsc#1270089).\n- CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service\n  (bsc#1270091).\n- CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service\n  (bsc#1270092).\n- CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service\n  on 32-bit platforms only (bsc#1270106).\n- CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1\n  (bsc#1270138).\n\nChanges for clamav:\n\n- Update to 1.5.3:\n    \n  * Hardened clamscan, clamdscan, and clamonacc quarantine actions against\n    time-of-check/time-of-use races that could redirect copied, moved, or removed\n    files under unsafe quarantine directory configurations.\n  * Raised the minimum required CMake version to 3.17 to fix Linux builds with\n    libcurl v8.21.0 when linking static library dependencies.\n  * Metadata preclass scans now run before the final scan verdict.\n  * ClamOnAcc: Fixed errors when recursively excluded paths are children of an\n    included path.\n  * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide\n in the same bucket.\n","affected":[{"package":{"name":"clamav","ecosystem":"SUSE:Linux Enterprise Server 12 SP5-LTSS","purl":"pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.3-3.56.1"}]}],"ecosystem_specific":{"binaries":[{"clamav":"1.5.3-3.56.1","clamav-devel":"1.5.3-3.56.1","clamav-docs-html":"1.5.3-3.56.1","clamav-milter":"1.5.3-3.56.1","libclamav12":"1.5.3-3.56.1","libclammspack0":"1.5.3-3.56.1","libfreshclam4":"1.5.3-3.56.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2833-1.json"}},{"package":{"name":"clamav","ecosystem":"SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5","purl":"pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.3-3.56.1"}]}],"ecosystem_specific":{"binaries":[{"clamav":"1.5.3-3.56.1","clamav-devel":"1.5.3-3.56.1","clamav-docs-html":"1.5.3-3.56.1","clamav-milter":"1.5.3-3.56.1","libclamav12":"1.5.3-3.56.1","libclammspack0":"1.5.3-3.56.1","libfreshclam4":"1.5.3-3.56.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2833-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262833-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270088"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270089"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270091"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270092"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270106"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270107"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270138"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20213"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20214"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20215"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20216"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20217"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20243"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20244"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41676"}]}