gpp_maybe Security update for clamav
SUSE-SLE-Micro-5.5-2026-4208


This update for clamav fixes the following issues: - CVE-2026-20337: Improper boundary checks for content in zip archive parser (bsc#1274597). - CVE-2026-20338: invalid free due to bad ownership handling when merging ZIP catalogue records (bsc#1274598). - CVE-2026-20339: integer overflow in the PESpin unpacker leads to undersized allocation and heap out-of-bounds write (bsc#1274599). - CVE-2026-20345: out-of-bounds read/write via indexing error when converting GPT partition names (bsc#1274600). - CVE-2026-20346: integer underflow when parsing malformed PDF hex strings causes a crash (bsc#1274601). - CVE-2026-20347: integer overflow and undefined behavior when scanning malformed Mach-O files causes a crash (bsc#1274602). - CVE-2026-20348: improper size handling in the XAR parser allows excessive allocation and scan-limit bypass (bsc#1274603). - CVE-2026-46671: onenote_parser: Path traversal in `Parser:parse_notebook` allows reading files outside the notebook directory (bsc#1271922). - CVE-2025-8088: rejects path separators in NTFS alternate data stream names to prevent extraction outside ClamAV's temporary scan directory on Windows. Changes for clamav: Update to 1.5.4: * Fixed thread-safety issues in the clamd STATS command that could disclose process memory or crash the daemon while scans and STATS requests run concurrently. Also fixed partial socket-write handling used for large STATS responses. * FreeBSD: Restored support for safe quarantine move and remove actions while preserving protection against source-path replacement races. * Fixed an OpenSSL library-context leak in legacy hashing helpers when a requested message digest cannot be fetched, such as when the default provider is unavailable in a FIPS-enabled environment. * Upgraded the Rust crossbeam-epoch dependency to resolve the RUSTSEC-2026-0204 advisory.


cloud_download Downloads

SUSE Linux Enterprise Micro 5.5 aarch64
  • Packages
    clamav
    Antivirus Toolkit
    1.5.4-150400.13.11.1 lock rpm lock src
    libclamav12
    ClamAV antivirus engine runtime
    1.5.4-150400.13.11.1 lock rpm
    libclammspack0
    ClamAV antivirus engine runtime
    1.5.4-150400.13.11.1 lock rpm
    libclamunrar12
    ClamAV antivirus RAR support
    1.5.4-150400.13.11.1 lock rpm
    libfreshclam4
    ClamAV updater library
    1.5.4-150400.13.11.1 lock rpm
SUSE Linux Enterprise Micro 5.5 ppc64le
  • Packages
    clamav
    Antivirus Toolkit
    1.5.4-150400.13.11.1 lock rpm lock src
    libclamav12
    ClamAV antivirus engine runtime
    1.5.4-150400.13.11.1 lock rpm
    libclammspack0
    ClamAV antivirus engine runtime
    1.5.4-150400.13.11.1 lock rpm
    libclamunrar12
    ClamAV antivirus RAR support
    1.5.4-150400.13.11.1 lock rpm
    libfreshclam4
    ClamAV updater library
    1.5.4-150400.13.11.1 lock rpm
SUSE Linux Enterprise Micro 5.5 s390x
  • Packages
    clamav
    Antivirus Toolkit
    1.5.4-150400.13.11.1 lock rpm lock src
    libclamav12
    ClamAV antivirus engine runtime
    1.5.4-150400.13.11.1 lock rpm
    libclammspack0
    ClamAV antivirus engine runtime
    1.5.4-150400.13.11.1 lock rpm
    libclamunrar12
    ClamAV antivirus RAR support
    1.5.4-150400.13.11.1 lock rpm
    libfreshclam4
    ClamAV updater library
    1.5.4-150400.13.11.1 lock rpm
SUSE Linux Enterprise Micro 5.5 x86_64
  • Packages
    clamav
    Antivirus Toolkit
    1.5.4-150400.13.11.1 lock rpm lock src
    libclamav12
    ClamAV antivirus engine runtime
    1.5.4-150400.13.11.1 lock rpm
    libclammspack0
    ClamAV antivirus engine runtime
    1.5.4-150400.13.11.1 lock rpm
    libclamunrar12
    ClamAV antivirus RAR support
    1.5.4-150400.13.11.1 lock rpm
    libfreshclam4
    ClamAV updater library
    1.5.4-150400.13.11.1 lock rpm