logo

New ClamAV security patch closes seven scanner bugs dating back two decades

ID: 3ae99595-0375-598e-bb5f-5ee86bd718d8

STIX ID: report--3ae99595-0375-598e-bb5f-5ee86bd718d8

Feed Name: Help Net Security

Threat Score
55/100

Date Published: 2026-07-05

Date Updated: 2026-07-06

Author: Sinisa Markovic

...
...

ClamAV 1.5.3 and 1.4.5 address seven security flaws and several hardening changes: multiple PE packer/PE parsing bugs (CVE-2026-20213, CVE-2026-20214, CVE-2026-20217) causing integer overflows, buffer overflows, and use-after-free/crash conditions; archive and disk-image parsing issues (CVE-2026-20215, CVE-2026-20243, CVE-2026-20216, CVE-2026-20244) that can corrupt memory, bypass extraction limits, or crash 32-bit builds; and a quarantine time-of-check/time-of-use race condition—releases also include dependency updates, build fixes, and metadata scan ordering changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.