Your message dated Sun, 23 Aug 2026 17:06:07 +0000
with message-id <[email protected]>
and subject line Bug#1143939: fixed in clamav 1.4.6+dfsg-1
has caused the Debian Bug report #1143939,
regarding clamav: CVE-2026-20339 CVE-2026-20345 CVE-2026-20346 CVE-2026-20347
CVE-2026-20348
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1143939: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143939
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: clamav
X-Debbugs-CC: [email protected]
Severity: grave
Tags: security
Hi,
The following vulnerabilities were published for clamav.
CVE-2026-20339[0]:
| A vulnerability in the PESpin file format parser of ClamAV could
| allow an unauthenticated, remote attacker to cause a DoS condition
| or possibly other expanded impacts as a result of memory
| corruption on an affected device. This vulnerability is due to
| improper boundary checks for content in PESpin files during
| scanning, which may result in an integer overflow. An attacker could
| exploit this vulnerability by submitting a crafted file that
| contains PESpin content to be scanned by ClamAV on an affected
| device. A successful exploit could allow the attacker to cause the
| ClamAV scanning process to terminate, resulting in a DoS condition
| on the affected software.
CVE-2026-20345[1]:
| A vulnerability in the GPT file format parser of ClamAV could allow
| an unauthenticated, remote attacker to cause a DoS condition or
| possibly other expanded impacts as a result of memory
| corruption on an affected device. This vulnerability is due to
| improper handling of an endian conversion operation, which may
| result in an out-of-bounds buffer write. An attacker could exploit
| this vulnerability by submitting a crafted GPT file to be scanned by
| ClamAV on an affected device. A successful exploit could allow the
| attacker to cause the ClamAV scanning process to terminate,
| resulting in a DoS condition on the affected software.
CVE-2026-20346[2]:
| A vulnerability in the PDF file format parser of ClamAV could allow
| an unauthenticated, remote attacker to cause a DoS condition or
| possibly other expanded impacts as a result of memory
| corruption on an affected device. This vulnerability is due to
| improper boundary checks for content in PDF files during scanning,
| which may result in an out-of-bounds buffer read. An attacker could
| exploit this vulnerability by submitting a crafted PDF file to be
| scanned by ClamAV on an affected device. A successful exploit could
| allow the attacker to cause the ClamAV scanning process to
| terminate, resulting in a DoS condition on the affected software.
CVE-2026-20347[3]:
| A vulnerability in the Mach-O file format parser of ClamAV could
| allow an unauthenticated, remote attacker to cause a DoS condition
| or possibly other expanded impacts as a result of memory
| corruption on an affected device. This vulnerability is due to
| improper boundary checks for content in Mach-O files during
| scanning, which may result in an out-of-bounds buffer read. An
| attacker could exploit this vulnerability by submitting a crafted
| Mach-O file to be scanned by ClamAV on an affected device. A
| successful exploit could allow the attacker to cause the ClamAV
| scanning process to terminate, resulting in a DoS condition on the
| affected software.
CVE-2026-20348[4]:
| A vulnerability in the XAR file format parser of ClamAV could allow
| an unauthenticated, remote attacker to cause a DoS condition or
| possibly other expanded impacts as a result of memory
| corruption on an affected device. This vulnerability is due to
| improper boundary checks for content in XAR files during scanning.
| An attacker could exploit this vulnerability by submitting a crafted
| file that contains XAR content to be scanned by ClamAV on an
| affected device. A successful exploit could allow the attacker to
| cause the ClamAV scanning process to terminate, resulting in a DoS
| condition on the affected software.
https://blog.clamav.net/2026/08/clamav-154-and-146-security-patch.html
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-20339
https://www.cve.org/CVERecord?id=CVE-2026-20339
[1] https://security-tracker.debian.org/tracker/CVE-2026-20345
https://www.cve.org/CVERecord?id=CVE-2026-20345
[2] https://security-tracker.debian.org/tracker/CVE-2026-20346
https://www.cve.org/CVERecord?id=CVE-2026-20346
[3] https://security-tracker.debian.org/tracker/CVE-2026-20347
https://www.cve.org/CVERecord?id=CVE-2026-20347
[4] https://security-tracker.debian.org/tracker/CVE-2026-20348
https://www.cve.org/CVERecord?id=CVE-2026-20348
Please adjust the affected versions in the BTS as needed.
--- End Message ---
--- Begin Message ---
Source: clamav
Source-Version: 1.4.6+dfsg-1
Done: Sebastian Andrzej Siewior <[email protected]>
We believe that the bug you reported is fixed in the latest version of
clamav, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Sebastian Andrzej Siewior <[email protected]> (supplier of updated clamav
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 23 Aug 2026 18:32:02 +0200
Source: clamav
Architecture: source
Version: 1.4.6+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: ClamAV Team <[email protected]>
Changed-By: Sebastian Andrzej Siewior <[email protected]>
Closes: 1143939
Changes:
clamav (1.4.6+dfsg-1) unstable; urgency=medium
.
[ Edmund Lodewijks ]
* Import 1.4.6 (Closes: #1143939)
- CVE-2026-20345 ("Fixed an indexing error while converting GPT
partition names")
- CVE-2026-20339 ("Fixed an integer overflow in the PESpin unpacker")
- CVE-2026-20346 ("Fixed an integer underflow in the PDF parser")
- CVE-2026-20347 ("Fixed undefined behavior and integer overflow in the
Mach-O parser")
- CVE-2026-20348 ("Fixed XAR parser size handling")
- Fixed thread-safety issues in the clamd STATS command that could
disclose process memory or crash the daemon
Checksums-Sha1:
d062bc1b22bdac859f68e7a5d2629d7437edf0b0 3042 clamav_1.4.6+dfsg-1.dsc
d076f78137f51afc0dbb7b67ec476c3c62487089 27698332 clamav_1.4.6+dfsg.orig.tar.xz
cd2cf544237f6fcb02455625ff003f43e5419c24 522048
clamav_1.4.6+dfsg-1.debian.tar.xz
Checksums-Sha256:
e105a6e31c4df5a4e3e2af330e2f5bcf2678582f9423b2bba2af8d94deeef315 3042
clamav_1.4.6+dfsg-1.dsc
09823124e9bae5d602699c2a2fe5d4876298283cf3e7f8982973571843572468 27698332
clamav_1.4.6+dfsg.orig.tar.xz
11e6f5229f254e8799df4c320fa94c0b20370688231050d960eb6cb71a1b9671 522048
clamav_1.4.6+dfsg-1.debian.tar.xz
Files:
ed13bef81e8ebb00301f93dcbcdd04ac 3042 utils optional clamav_1.4.6+dfsg-1.dsc
1342952a4063eee18d239cd7761ef0ff 27698332 utils optional
clamav_1.4.6+dfsg.orig.tar.xz
46077c44cfe3c9a9e921a437625a7bca 522048 utils optional
clamav_1.4.6+dfsg-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAmqLILMACgkQBWQfF1cS
+ltc3Av/RdC2pPxeBj1tMKQvwi9iOASHnlPevbepWk/cuC4l6w27NC5ujvNz/nuy
x/VSkTc3CxRSH9ZhM9+uBHoSwLI1zWImUAn9RuoA2gBXG435GagnBZZmbbXC38Dw
jz8nWq0bSjY8+tm1tq4dInABOrUmmC4GSbV+DKCWus2TOOlIHM6y4kJXB4ePCcAA
AOZfq84MZUhkZET4/hzVqtimm9TXDt6yqkJQ9+T6hMSofCGjpRirAQOizm3dDLOX
GS+78CYmJSl/XPiHgdA4Il8R928AX20qKSROV/i9F5NXVWfvXgUrHJJdAHdIzp8L
SVO2ZhfIeplO8GF2Wu2QyBX18bGJWMTw+5Ff4nTzJvZpTrwZnEW4Rg6bl5dOMqLl
OvBF6yOe+w1FMx0q/tJ6GrUvdFHkBV3pZFL96WC202XAfXVHHBEAQDhp6q9AoOrG
nSmI063hbrDaWMiqkgTTdb1KR0m0whsPeOTREQUhEw4Sr4YA/rplEHh/f4bgapvn
mRyJK4Rq
=B+J3
-----END PGP SIGNATURE-----
pgpIkhrzDim2G.pgp
Description: PGP signature
--- End Message ---
_______________________________________________
Pkg-clamav-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-clamav-devel