Updated clamav packages fix security vulnerabilities
Publication date: 31 Aug 2026Modification date: 31 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-20345 , CVE-2026-20339 , CVE-2026-20346 , CVE-2026-20347 , CVE-2026-20348
Description
n indexing error while converting GPT partition names that could read or
write beyond a stack-allocated partition entry. (CVE-2026-20345)
An integer overflow in the PESpin unpacker that could allocate an
undersized buffer and then write beyond it while rebuilding a PE file.
(CVE-2026-20339)
An integer underflow in the PDF parser that could cause a crash while
reading a malformed hex string. (CVE-2026-20346)
Undefined behavior and integer overflow in the Mach-O parser that could
cause a crash while scanning a malformed Mach-O file. (CVE-2026-20347)
XAR parser size handling that could request an excessive allocation or
exceed scan limits while decompressing a malformed table of contents.
(CVE-2026-20348)
References
- https://bugs.mageia.org/show_bug.cgi?id=36180
- https://blog.clamav.net/2026/08/clamav-154-and-146-security-patch.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OQHYDS3XT2PKXIDL3B6FNNJ3JT27FJ2T/
- https://www.cve.org/CVERecord?id=CVE-2026-20345
- https://www.cve.org/CVERecord?id=CVE-2026-20339
- https://www.cve.org/CVERecord?id=CVE-2026-20346
- https://www.cve.org/CVERecord?id=CVE-2026-20347
- https://www.cve.org/CVERecord?id=CVE-2026-20348
SRPMS
10/core
- clamav-1.4.6-1.mga10