Advisories ยป MGASA-2026-0348

Updated clamav packages fix security vulnerabilities

Publication date: 31 Aug 2026
Modification date: 31 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-20345 , CVE-2026-20339 , CVE-2026-20346 , CVE-2026-20347 , CVE-2026-20348

Description

n indexing error while converting GPT partition names that could read or
write beyond a stack-allocated partition entry. (CVE-2026-20345)
An integer overflow in the PESpin unpacker that could allocate an
undersized buffer and then write beyond it while rebuilding a PE file.
(CVE-2026-20339)
An integer underflow in the PDF parser that could cause a crash while
reading a malformed hex string. (CVE-2026-20346)
Undefined behavior and integer overflow in the Mach-O parser that could
cause a crash while scanning a malformed Mach-O file. (CVE-2026-20347)
XAR parser size handling that could request an excessive allocation or
exceed scan limits while decompressing a malformed table of contents.
(CVE-2026-20348)
                

References

SRPMS

10/core