Release date:
2026-07-16 14:04:28 UTC
Description:
* SECURITY UPDATE: Out-of-bounds write via 7z substream count overflow
- debian/patches/CVE-2026-20215.patch: reject 7z archives whose total
unpack-stream count would overflow UInt32 before it is accumulated in
libclamav/7z/7zIn.c
- CVE-2026-20215
* SECURITY UPDATE: Denial of service via InstallShield extraction size-limit bypass
- debian/patches/CVE-2026-20216.patch: enforce maxfilesize and maxscansize
against the cumulative inflated output and propagate hard-stop limit
errors out of is_extract_cab() in libclamav/ishield.c
- CVE-2026-20216
* SECURITY UPDATE: Invalid free in the PESpin unpacker cleanup loop
- debian/patches/CVE-2026-20217.patch: shift the working bitmap instead of
bitman in the PESpin cleanup loop so only unpacker-allocated sections are
freed in libclamav/spin.c
- CVE-2026-20217
Updated packages:
-
clamav_1.4.3+dfsg-0ubuntu0.18.04.1+tuxcare.els3_amd64.deb
sha:a2a1b30c78c998d75d342e1b98256690ecb6d8fa
-
clamav-base_1.4.3+dfsg-0ubuntu0.18.04.1+tuxcare.els3_all.deb
sha:1b17b7f5b75c9381ac72d1f31c1a41ba98f16777
-
clamav-daemon_1.4.3+dfsg-0ubuntu0.18.04.1+tuxcare.els3_amd64.deb
sha:d502d7402aad3e0de39c6934c33ca7118d99f4a3
-
clamav-doc_1.4.3+dfsg-0ubuntu0.18.04.1+tuxcare.els3_all.deb
sha:910525589fe4fdfbd617742f79376dda2296e977
-
clamav-docs_1.4.3+dfsg-0ubuntu0.18.04.1+tuxcare.els3_all.deb
sha:77a5647631fa94dd8e46c2dc8b9da322a7b3bfc4
-
clamav-freshclam_1.4.3+dfsg-0ubuntu0.18.04.1+tuxcare.els3_amd64.deb
sha:cbba4bbcd02fe271105a13e8b9b62f2431fe88a5
-
clamav-milter_1.4.3+dfsg-0ubuntu0.18.04.1+tuxcare.els3_amd64.deb
sha:9b0369b0e3fa1036e4bf46c741e78f28fbb3044c
-
clamav-testfiles_1.4.3+dfsg-0ubuntu0.18.04.1+tuxcare.els3_all.deb
sha:0bcacab7f72c06ec69a970fb432c8093fa255903
-
clamdscan_1.4.3+dfsg-0ubuntu0.18.04.1+tuxcare.els3_amd64.deb
sha:0f4c93a8261f7898311a62379f36de9ba82e5225
-
libclamav-dev_1.4.3+dfsg-0ubuntu0.18.04.1+tuxcare.els3_amd64.deb
sha:6c324125900421874ae7418f2c20ecafbd0f83ea
-
libclamav12_1.4.3+dfsg-0ubuntu0.18.04.1+tuxcare.els3_amd64.deb
sha:ebf205a531a16eb608f1a23b4f746dbd3508e9f3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.