{"schema_version":"1.7.5","id":"SUSE-SU-2026:2835-1","published":"2026-07-09T19:13:18Z","modified":"2026-07-10T10:00:09.066289728Z","related":["CVE-2026-20213","CVE-2026-20214","CVE-2026-20215","CVE-2026-20216","CVE-2026-20217","CVE-2026-20243","CVE-2026-20244","CVE-2026-41676"],"upstream":["CVE-2026-20213","CVE-2026-20214","CVE-2026-20215","CVE-2026-20216","CVE-2026-20217","CVE-2026-20243","CVE-2026-20244","CVE-2026-41676"],"summary":"Security update for clamav","details":"This update for clamav fixes the following issues\n\n- CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service\n  (bsc#1270107).\n- CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service\n  (bsc#1270085).\n- CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service\n  (bsc#1270088).\n- CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of\n  service (bsc#1270089).\n- CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service\n  (bsc#1270091).\n- CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service\n  (bsc#1270092).\n- CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service\n  on 32-bit platforms only (bsc#1270106).\n- CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1\n  (bsc#1270138).\n\nChanges for clamav:\n\n- update to 1.5.3:\n    \n * Hardened clamscan, clamdscan, and clamonacc quarantine actions against\n time-of-check/time-of-use races that could redirect copied, moved, or removed\n files under unsafe quarantine directory configurations.\n * Raised the minimum required CMake version to 3.17 to fix Linux builds with\n libcurl v8.21.0 when linking static library dependencies.\n * Metadata preclass scans now run before the final scan verdict.\n * ClamOnAcc: Fixed errors when recursively excluded paths are children of an\n included path.\n * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide\n in the same bucket.\n","affected":[{"package":{"name":"clamav","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.3-150600.18.28.1"}]}],"ecosystem_specific":{"binaries":[{"clamav":"1.5.3-150600.18.28.1","clamav-devel":"1.5.3-150600.18.28.1","clamav-docs-html":"1.5.3-150600.18.28.1","clamav-milter":"1.5.3-150600.18.28.1","libclamav12":"1.5.3-150600.18.28.1","libclammspack0":"1.5.3-150600.18.28.1","libfreshclam4":"1.5.3-150600.18.28.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2835-1.json"}},{"package":{"name":"clamav","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.3-150600.18.28.1"}]}],"ecosystem_specific":{"binaries":[{"clamav":"1.5.3-150600.18.28.1","clamav-devel":"1.5.3-150600.18.28.1","clamav-docs-html":"1.5.3-150600.18.28.1","clamav-milter":"1.5.3-150600.18.28.1","libclamav12":"1.5.3-150600.18.28.1","libclammspack0":"1.5.3-150600.18.28.1","libfreshclam4":"1.5.3-150600.18.28.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2835-1.json"}},{"package":{"name":"clamav","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/clamav&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.3-150600.18.28.1"}]}],"ecosystem_specific":{"binaries":[{"clamav":"1.5.3-150600.18.28.1","clamav-devel":"1.5.3-150600.18.28.1","clamav-docs-html":"1.5.3-150600.18.28.1","clamav-milter":"1.5.3-150600.18.28.1","libclamav12":"1.5.3-150600.18.28.1","libclammspack0":"1.5.3-150600.18.28.1","libfreshclam4":"1.5.3-150600.18.28.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2835-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262835-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270088"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270089"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270091"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270092"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270106"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270107"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270138"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20213"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20214"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20215"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20216"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20217"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20243"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20244"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41676"}]}