#1143939 clamav: CVE-2026-20339 CVE-2026-20345 CVE-2026-20346 CVE-2026-20347 CVE-2026-20348 #1143939
- Package:
- src:clamav
- Source:
- src:clamav
- Submitter:
- Moritz Mühlenhoff
- Date:
- 2026-08-23 17:09:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for clamav. CVE-2026-20339[0]: | A vulnerability in the PESpin file format parser of ClamAV could | allow an unauthenticated, remote attacker to cause a DoS condition | or possibly other expanded impacts as a result of memory | corruption on an affected device. This vulnerability is due to | improper boundary checks for content in PESpin files during | scanning, which may result in an integer overflow. An attacker could | exploit this vulnerability by submitting a crafted file that | contains PESpin content to be scanned by ClamAV on an affected | device. A successful exploit could allow the attacker to cause the | ClamAV scanning process to terminate, resulting in a DoS condition | on the affected software. CVE-2026-20345[1]: | A vulnerability in the GPT file format parser of ClamAV could allow | an unauthenticated, remote attacker to cause a DoS condition or | possibly other expanded impacts as a result of memory | corruption on an affected device. This vulnerability is due to | improper handling of an endian conversion operation, which may | result in an out-of-bounds buffer write. An attacker could exploit | this vulnerability by submitting a crafted GPT file to be scanned by | ClamAV on an affected device. A successful exploit could allow the | attacker to cause the ClamAV scanning process to terminate, | resulting in a DoS condition on the affected software. CVE-2026-20346[2]: | A vulnerability in the PDF file format parser of ClamAV could allow | an unauthenticated, remote attacker to cause a DoS condition or | possibly other expanded impacts as a result of memory | corruption on an affected device. This vulnerability is due to | improper boundary checks for content in PDF files during scanning, | which may result in an out-of-bounds buffer read. An attacker could | exploit this vulnerability by submitting a crafted PDF file to be | scanned by ClamAV on an affected device. A successful exploit could | allow the attacker to cause the ClamAV scanning process to | terminate, resulting in a DoS condition on the affected software. CVE-2026-20347[3]: | A vulnerability in the Mach-O file format parser of ClamAV could | allow an unauthenticated, remote attacker to cause a DoS condition | or possibly other expanded impacts as a result of memory | corruption on an affected device. This vulnerability is due to | improper boundary checks for content in Mach-O files during | scanning, which may result in an out-of-bounds buffer read. An | attacker could exploit this vulnerability by submitting a crafted | Mach-O file to be scanned by ClamAV on an affected device. A | successful exploit could allow the attacker to cause the ClamAV | scanning process to terminate, resulting in a DoS condition on the | affected software. CVE-2026-20348[4]: | A vulnerability in the XAR file format parser of ClamAV could allow | an unauthenticated, remote attacker to cause a DoS condition or | possibly other expanded impacts as a result of memory | corruption on an affected device. This vulnerability is due to | improper boundary checks for content in XAR files during scanning. | An attacker could exploit this vulnerability by submitting a crafted | file that contains XAR content to be scanned by ClamAV on an | affected device. A successful exploit could allow the attacker to | cause the ClamAV scanning process to terminate, resulting in a DoS | condition on the affected software. https://blog.clamav.net/2026/08/clamav-154-and-146-security-patch.html If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-20339 https://www.cve.org/CVERecord?id=CVE-2026-20339 [1] https://security-tracker.debian.org/tracker/CVE-2026-20345 https://www.cve.org/CVERecord?id=CVE-2026-20345 [2] https://security-tracker.debian.org/tracker/CVE-2026-20346 https://www.cve.org/CVERecord?id=CVE-2026-20346 [3] https://security-tracker.debian.org/tracker/CVE-2026-20347 https://www.cve.org/CVERecord?id=CVE-2026-20347 [4] https://security-tracker.debian.org/tracker/CVE-2026-20348 https://www.cve.org/CVERecord?id=CVE-2026-20348 Please adjust the affected versions in the BTS as needed.
Control: tags -1 fixed-upstream JFTR, these are all fixed upstream in release 1.4.6, cf. <https://github.com/Cisco-Talos/clamav/releases#release-clamav-1.4.6>. Cheers, Flo
Hello all,
clamav 1.4.5+dfsg-3 is flagged for autoremoval from testing on 2026-09-21
because of this bug, and it takes seven reverse dependencies with it:
c-icap-modules, clamassassin, clamsmtp, clamtk, cyrus-imapd, e2guardian and
libclamunrar. I was working on the cyrus-imapd patch, and thought I'd
also see if a contribution to clamav would be welcome.
Since I am not familiar with the git-dpm workflow, I just built it the
way I know, as a plain source package (I am still new to packaging for
Debian).
Upstream 1.4.6 (2026-08-07) fixes all five CVEs. Since the packaging
branch had no 1.4.6 work yet, I have prepared 1.4.6+dfsg-1. I do not
have upload rights, so I uploaded it to mentors.
Source package: https://mentors.debian.net/package/clamav/
I have kept the diff to the minimum a security update needs, but also
included commit 97a37bb2 from Salsa (d/ci: Disable blhc).
A debdiff is attached to this email.
Build: I built this with sbuild in unstable.
Tests: The upstream testsuite passes (6/6 test suites, plus the Rust
unit tests).
Lintian: Compared to 1.4.5+dfsg-3, lintian reports two new tags:
`no-nmu-in-changelog` and `source-nmu-has-incorrect-version-number`.
Both are due to my name being in the changelog, but I am not a
Maintainer or Uploader.
Some points that I think are noteworthy:
* All four patches in debian/patches/series still apply to 1.4.6; none have
been merged upstream. Only 0004-unit_tests-Don-t-set-TMP.patch needed a
refresh (3-line offset).
* No ABI break. LIBCLAMAV_CURRENT:REVISION:AGE is 12:3:0 in both 1.4.5 and
1.4.6. The SONAME stays libclamav.so.12.
* Your guard in override_dh_auto_configure did its job and stopped my first
build: CL_FLEVEL went 215 -> 216 in 1.4.6. I followed the same treatment
as 478677ef ("d: Update symbols") for the 1.4.5 bump -- the four 1.4.5
minvers in debian/libclamav12.symbols (CLAMAV_PRIVATE, cl_retflevel@
CLAMAV_PUBLIC, FRESHCLAM_PRIVATE, FRESHCLAM_PUBLIC) go to 1.4.6, and the
CL_FLEVEL literal in debian/rules goes to 216. Please do sanity-check
that, as I was trying to copy what has been done before.
* CVE-2025-8088 is not relevant to Debian: it is Windows-only. The security
tracker marks it NOT-FOR-US. I have not mentioned it in the changelog.
* I did not do anything with git-dpm, and therefore didn't touch
d/.git-dpm (it still has the 1.4.5 import).
* debian/rules runs debconf-updatepo in the `clean` target, so a plain
"dpkg-buildpackage -S" rewrites all twenty debian/po/*.po files. When I
did a diff between the newly built package and 1.4.5+dfsg-3, I saw all
these new .po files, which surprised me. Looking at that 1.4.5+dfsg-3
source package in the
archive, it still has POT-Creation-Date 2021-02-21, so I reckon these
don't usually get updated by the clamav team. Therefore, I rebuilt with
`-nc` and restored the .po files, so that the change is minimal. I just
wanted to write this out.
If it is easier for you to just do the 1.4.6 import yourselves and ignore my
package entirely, that is completely fine. Please let me know, and I
will remove it from mentors.
I hope that the changelog is written correctly. I presumed that the
clamav-team will upload the package, if they so desire. If they drop it,
fine. If someone else uploads it as an NMU, then the changelog will be
changed accordingly I'm sure.
Kind regards,
Edmund
Forgot to attach a proper debdiff, so here it is.
We believe that the bug you reported is fixed in the latest version of
clamav, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1143939@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Sebastian Andrzej Siewior <sebastian@breakpoint.cc> (supplier of updated clamav package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 23 Aug 2026 18:32:02 +0200
Source: clamav
Architecture: source
Version: 1.4.6+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: ClamAV Team <pkg-clamav-devel@lists.alioth.debian.org>
Changed-By: Sebastian Andrzej Siewior <sebastian@breakpoint.cc>
Closes: 1143939
Changes:
clamav (1.4.6+dfsg-1) unstable; urgency=medium
.
[ Edmund Lodewijks ]
* Import 1.4.6 (Closes: #1143939)
- CVE-2026-20345 ("Fixed an indexing error while converting GPT
partition names")
- CVE-2026-20339 ("Fixed an integer overflow in the PESpin unpacker")
- CVE-2026-20346 ("Fixed an integer underflow in the PDF parser")
- CVE-2026-20347 ("Fixed undefined behavior and integer overflow in the
Mach-O parser")
- CVE-2026-20348 ("Fixed XAR parser size handling")
- Fixed thread-safety issues in the clamd STATS command that could
disclose process memory or crash the daemon
Checksums-Sha1:
d062bc1b22bdac859f68e7a5d2629d7437edf0b0 3042 clamav_1.4.6+dfsg-1.dsc
d076f78137f51afc0dbb7b67ec476c3c62487089 27698332 clamav_1.4.6+dfsg.orig.tar.xz
cd2cf544237f6fcb02455625ff003f43e5419c24 522048 clamav_1.4.6+dfsg-1.debian.tar.xz
Checksums-Sha256:
e105a6e31c4df5a4e3e2af330e2f5bcf2678582f9423b2bba2af8d94deeef315 3042 clamav_1.4.6+dfsg-1.dsc
09823124e9bae5d602699c2a2fe5d4876298283cf3e7f8982973571843572468 27698332 clamav_1.4.6+dfsg.orig.tar.xz
11e6f5229f254e8799df4c320fa94c0b20370688231050d960eb6cb71a1b9671 522048 clamav_1.4.6+dfsg-1.debian.tar.xz
Files:
ed13bef81e8ebb00301f93dcbcdd04ac 3042 utils optional clamav_1.4.6+dfsg-1.dsc
1342952a4063eee18d239cd7761ef0ff 27698332 utils optional clamav_1.4.6+dfsg.orig.tar.xz
46077c44cfe3c9a9e921a437625a7bca 522048 utils optional clamav_1.4.6+dfsg-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAmqLILMACgkQBWQfF1cS
+ltc3Av/RdC2pPxeBj1tMKQvwi9iOASHnlPevbepWk/cuC4l6w27NC5ujvNz/nuy
x/VSkTc3CxRSH9ZhM9+uBHoSwLI1zWImUAn9RuoA2gBXG435GagnBZZmbbXC38Dw
jz8nWq0bSjY8+tm1tq4dInABOrUmmC4GSbV+DKCWus2TOOlIHM6y4kJXB4ePCcAA
AOZfq84MZUhkZET4/hzVqtimm9TXDt6yqkJQ9+T6hMSofCGjpRirAQOizm3dDLOX
GS+78CYmJSl/XPiHgdA4Il8R928AX20qKSROV/i9F5NXVWfvXgUrHJJdAHdIzp8L
SVO2ZhfIeplO8GF2Wu2QyBX18bGJWMTw+5Ff4nTzJvZpTrwZnEW4Rg6bl5dOMqLl
OvBF6yOe+w1FMx0q/tJ6GrUvdFHkBV3pZFL96WC202XAfXVHHBEAQDhp6q9AoOrG
nSmI063hbrDaWMiqkgTTdb1KR0m0whsPeOTREQUhEw4Sr4YA/rplEHh/f4bgapvn
mRyJK4Rq
=B+J3
-----END PGP SIGNATURE-----