{"schema_version":"1.7.5","id":"openSUSE-SU-2026:21252-1","published":"2026-07-07T16:59:27Z","modified":"2026-07-09T10:00:10.943640114Z","related":["CVE-2026-20213","CVE-2026-20214","CVE-2026-20215","CVE-2026-20216","CVE-2026-20217","CVE-2026-20243","CVE-2026-20244","CVE-2026-41676"],"upstream":["CVE-2026-20213","CVE-2026-20214","CVE-2026-20215","CVE-2026-20216","CVE-2026-20217","CVE-2026-20243","CVE-2026-20244","CVE-2026-41676"],"summary":"Security update for clamav","details":"This update for clamav fixes the following issues:\n\nUpdate to version 1.5.3.\n\nSecurity issues fixed:\n\n- CVE-2026-20213: out-of-bounds write due to improper boundary checks for content in PE files during scanning\n  (bsc#1270107).\n- CVE-2026-20214: out-of-bounds write due to improper boundary checks for content in FSG files during scanning\n  (bsc#1270085).\n- CVE-2026-20215: out-of-bounds write due to improper boundary checks for content in 7z files during scanning\n  (bsc#1270088).\n- CVE-2026-20216: denial of service due to improper handling of temporary resources during InstallShield file scanning\n  (bsc#1270089).\n- CVE-2026-20217: out-of-bounds write due to improper boundary checks for content in PESpin files during scanning\n  (bsc#1270091).\n- CVE-2026-20243: out-of-bounds write due to improper boundary checks for content in ALZ files during scanning\n  (bsc#1270092).\n- CVE-2026-20244: integer overflow and DoS due to improper boundary checks for content in DMG files during scanning\n  (bsc#1270106).\n- CVE-2026-41676: buffer overflow due to missing checks via `Deriver:derive`, `PkeyCtxRef:derive` and OpenSSL 1.1.1\n  (bsc#1270138).\n\nOther updates and bugfixes:\n\n- Version 1.5.3:\n * Fixed a bug in the PESpin unpacker cleanup path that could free pointers into the scanned file buffer and crash the\n   scanner.\n * Fixed an integer overflow in PE rebuild size calculations that could be reached through a malformed Aspack-packed PE\n   file and lead to a heap buffer overflow write.\n * Fixed an InstallShield archive extraction limit bypass that could write far more temporary data than intended and\n   exhaust temporary storage.\n * Fixed an FSG unpacker loop underflow that could write past the section array while scanning a malformed PE file.\n * Fixed ALZ parser size handling bugs that could cause malformed ALZ archives to panic, abort the scanner, or skip\n   expected scan-limit handling.\n * Fixed a 7z parser substream count overflow that could under-allocate parser metadata arrays and write past them\n   while reading a malformed archive.\n * Fixed 32-bit DMG parser size checks that could let a short mish stripe table pass validation and crash 32-bit\n   scanner builds.\n * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time-of-check/time-of-use races that could\n   redirect copied, moved, or removed files under unsafe quarantine directory configurations.\n * Upgraded the Rust tar dependency to resolve the RUSTSEC-2026-0067 and RUSTSEC-2026-0068 advisories, and upgraded the\n   Rust openssl dependency to resolve CVE-2026-41676.\n * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static\n   library dependencies.\n * Metadata preclass scans now run before the final scan verdict.\n * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path.\n * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket.\n","affected":[{"package":{"name":"clamav","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/clamav&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.3-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"clamav":"1.5.3-160000.1.1","clamav-devel":"1.5.3-160000.1.1","clamav-docs-html":"1.5.3-160000.1.1","clamav-milter":"1.5.3-160000.1.1","libclamav12":"1.5.3-160000.1.1","libclammspack0":"1.5.3-160000.1.1","libfreshclam4":"1.5.3-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21252-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270088"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270089"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270091"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270092"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270106"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270107"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270138"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20213"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20214"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20215"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20216"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20217"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20243"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20244"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41676"}]}