|
|
Log in / Subscribe / Register

Mageia alert MGASA-2026-0348 (clamav)

From:  Mageia Updates <updates-announce@ml.mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2026-0348: Updated clamav packages fix security vulnerabilities
Date:  Mon, 31 Aug 2026 21:41:18 +0200
Message-ID:  <20260831194118.507309FEBA@duvel.mageia.org>
Archive-link:  Article

MGASA-2026-0348 - Updated clamav packages fix security vulnerabilities Publication date: 31 Aug 2026 URL: https://advisories.mageia.org/MGASA-2026-0348.html Type: security Affected Mageia releases: 10 CVE: CVE-2026-20345, CVE-2026-20339, CVE-2026-20346, CVE-2026-20347, CVE-2026-20348 Description: n indexing error while converting GPT partition names that could read or write beyond a stack-allocated partition entry. (CVE-2026-20345) An integer overflow in the PESpin unpacker that could allocate an undersized buffer and then write beyond it while rebuilding a PE file. (CVE-2026-20339) An integer underflow in the PDF parser that could cause a crash while reading a malformed hex string. (CVE-2026-20346) Undefined behavior and integer overflow in the Mach-O parser that could cause a crash while scanning a malformed Mach-O file. (CVE-2026-20347) XAR parser size handling that could request an excessive allocation or exceed scan limits while decompressing a malformed table of contents. (CVE-2026-20348) References: - https://bugs.mageia.org/show_bug.cgi?id=36180 - https://blog.clamav.net/2026/08/clamav-154-and-146-securi... - https://lists.fedoraproject.org/archives/list/package-ann... - https://www.cve.org/CVERecord?id=CVE-2026-20345 - https://www.cve.org/CVERecord?id=CVE-2026-20339 - https://www.cve.org/CVERecord?id=CVE-2026-20346 - https://www.cve.org/CVERecord?id=CVE-2026-20347 - https://www.cve.org/CVERecord?id=CVE-2026-20348 SRPMS: - 10/core/clamav-1.4.6-1.mga10


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds