New ClamAV security patch closes seven scanner bugs dating back two decades
ID: 3ae99595-0375-598e-bb5f-5ee86bd718d8
STIX ID: report--3ae99595-0375-598e-bb5f-5ee86bd718d8
Feed Name: Help Net Security
ClamAV 1.5.3 and 1.4.5 address seven security flaws and several hardening changes: multiple PE packer/PE parsing bugs (CVE-2026-20213, CVE-2026-20214, CVE-2026-20217) causing integer overflows, buffer overflows, and use-after-free/crash conditions; archive and disk-image parsing issues (CVE-2026-20215, CVE-2026-20243, CVE-2026-20216, CVE-2026-20244) that can corrupt memory, bypass extraction limits, or crash 32-bit builds; and a quarantine time-of-check/time-of-use race condition—releases also include dependency updates, build fixes, and metadata scan ordering changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
