ClamAV 1.5.4 and 1.4.6


1

On August 7, patch releases of the free antivirus package were published ClamAV 1.5.4 and 1.4.6The new versions focus on security: eight CVEs have been closed in the current 1.5 branch, six of which have also been fixed in the supported 1.4 branch. Additionally, a clamd vulnerability that could lead to process memory disclosure has been fixed.

В Clam AV 1.5.4 The following vulnerabilities have been fixed:

  • CVE-2026-20337 — An error in ZIP directory size accounting could lead to an out-of-bounds heap write when indexing local file headers. ClamAV versions 1.5.0–1.5.3 are vulnerable.
  • CVE-2026-20338 — A memory management error when merging ZIP directory entries could lead to incorrect memory release when processing a specially crafted archive. This only affected the 1.5 branch.
  • CVE-2026-20345 — An indexing error when converting GPT partition names allowed reading or writing data outside the partition's stack-based structure. This issue has been present since ClamAV 0.98.2.
  • CVE-2026-20339 — An integer overflow in the PESpin unpacker could lead to the allocation of an undersized buffer, followed by an out-of-bounds write when restoring a PE file. The vulnerability existed since ClamAV 0.90.
  • CVE-2026-20346 - An integer underflow in the PDF parser could cause a process crash when reading an invalid hexadecimal string.
  • CVE-2026-20347 — An integer overflow and undefined behavior vulnerability in the Mach-O analyzer could cause the scanner to crash when scanning a specially crafted file.
  • CVE-2026-20348 — Size checking errors in the XAR parser could cause memory over-allocation or exceed scan limits when unpacking a corrupted table of contents.
  • CVE-2025-8088 — the upstream fix has been moved to the UnRAR library supplied with ClamAV. Windows Path separators within NTFS alternate stream names could allow data to be extracted beyond the ClamAV temporary directory.

В Clam AV 1.4.6 Six of the listed vulnerabilities have been fixed: CVE-2026-20345, CVE-2026-20339, CVE-2026-20346, CVE-2026-20347, CVE-2026-20348 и CVE-2025-8088Two problems with the ZIP handler - CVE-2026-20337 и CVE-2026-20338 — relate to the 1.5 branch code and are therefore not relevant for 1.4.

Separately, the developers fixed a long-standing issue with the command's thread safety. clamd STATSWhen scanning and querying statistics simultaneously, a race condition could lead to data disclosure from process memory or a daemon crash. This bug has been present in ClamAV since version 0.95. The handling of partial socket writes when sending large STATS responses has also been fixed. The fix is ​​included in both new versions.

Safe operations for moving files to quarantine and deleting them are now supported again for FreeBSD. 1.5.4 also fixes an OpenSSL context leak when using legacy hashing functions in some configurations, particularly when the default provider is unavailable in a FIPS environment. The crossbeam-epoch Rust dependency has been updated in both branches to resolve a warning. RUSTSEC-2026-0204.

ClamAV is a cross-platform, free antivirus suite and malware detection library suite widely used in Linux- and mail servers. The project is distributed under the license GNU GPLv2.

Source: linux.org.ru

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster