[CLSA-2026:1784305797] clamav1.4: Fix of 6 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-17 16:48:30 UTC
Description:
- CVE-2026-20213: fix integer overflow in Aspack-triggered PE rebuild size calculation leading to a heap buffer overflow - CVE-2026-20214: fix FSG unpacker section loop underflow causing an out-of-bounds write - CVE-2026-20215: fix 7z substream count overflow causing under-allocation and heap buffer overflow - CVE-2026-20216: enforce InstallShield extraction limits against cumulative decompressed output - CVE-2026-20217: fix PESpin unpacker cleanup bitmap tracking causing invalid free - CVE-2026-20243: fix ALZ archive parser out-of-bounds buffer write and scan-limit bypass leading to denial of service via crafted ALZ file
Updated packages:
  • clamav1.4-1.4.4-1.amzn2.0.1.tuxcare.els1.x86_64.rpm
    sha:6362adbe78f5a7c269333f701d7ee6d24afd19f2b60847ff3fd6d441b2d1417e
  • clamav1.4-data-1.4.4-1.amzn2.0.1.tuxcare.els1.noarch.rpm
    sha:58db99b1642b713513634ef152e8da3cf0ec77e0ef4988614476e2d06a2b79d6
  • clamav1.4-devel-1.4.4-1.amzn2.0.1.tuxcare.els1.x86_64.rpm
    sha:c9009a4dea51c6f2bf91389f518d068a35cd10a9ec7e4da3e3ae67a108f466d7
  • clamav1.4-doc-1.4.4-1.amzn2.0.1.tuxcare.els1.noarch.rpm
    sha:f5be8e9c8470669a97be87f4823e61b62f08d20913d3a7b517c78abfc497222b
  • clamav1.4-filesystem-1.4.4-1.amzn2.0.1.tuxcare.els1.noarch.rpm
    sha:d7649f3e2e7158496fb809763847f8f7ab79e948be25ded679110d76c4a86bef
  • clamav1.4-freshclam-1.4.4-1.amzn2.0.1.tuxcare.els1.x86_64.rpm
    sha:6dd27638c6e56146c46de225f006ab9495f73b6f98dc8b23eb1dd6c094e0a4bb
  • clamav1.4-lib-1.4.4-1.amzn2.0.1.tuxcare.els1.x86_64.rpm
    sha:ee8206e6d2a127a1b4072909b2e7c9ba1edfcf89b4efcc282381cb724a9d305d
  • clamav1.4-milter-1.4.4-1.amzn2.0.1.tuxcare.els1.x86_64.rpm
    sha:735d5562a177490c5228e11bc19a9d7bc68d0f6030519cd2f639ef8afaacd4d8
  • clamd1.4-1.4.4-1.amzn2.0.1.tuxcare.els1.x86_64.rpm
    sha:17e42bd7c58a7977d422ca056b1e5c3c833264e86ecc030d1a3e35c524b5c48e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.