[From nobody Fri Jul  3 22:51:08 2026
Received: (at submit) by bugs.debian.org; 2 Jul 2026 18:55:43 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-10.0 required=4.0 tests=BAYES_00,FROMDEVELOPER,
 NO_RELAYS,XMAILER_REPORTBUG autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 48; hammy, 148; neutral, 51; spammy,
 2. spammytokens:0.978-+--nbsp, 0.941-+--H*r:bugs.debian.org
 hammytokens:0.000-+--H*F:U*carnil, 0.000-+--XDebbugsCc,
 0.000-+--X-Debbugs-Cc, 0.000-+--H*Ad:N*Bug, 0.000-+--H*Ad:N*Tracking
Return-path: &lt;carnil@debian.org&gt;
Received: via submission by buxtehude.debian.org with esmtp (Exim 4.96)
 (envelope-from &lt;carnil@debian.org&gt;) id 1wfMZa-00FCsL-2y
 for submit@bugs.debian.org; Thu, 02 Jul 2026 18:55:43 +0000
Content-Type: text/plain; charset=&quot;us-ascii&quot;
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Salvatore Bonaccorso &lt;carnil@debian.org&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: clamav: CVE-2026-20213 CVE-2026-20214 CVE-2026-20215 CVE-2026-20216
 CVE-2026-20217 CVE-2026-20243 CVE-2026-20244
Message-ID: &lt;178301853840.1636192.16847648216941757062.reportbug@eldamar.lan&gt;
X-Mailer: reportbug 13.2.0+nmu1
Date: Thu, 02 Jul 2026 20:55:38 +0200
Delivered-To: submit@bugs.debian.org

Source: clamav
Version: 1.4.4+dfsg-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team &lt;team@security.debian.org&gt;

Hi,

The following vulnerabilities were published for clamav.

CVE-2026-20213[0]:
| A vulnerability in the PE file format parser of ClamAV could allow
| an unauthenticated, remote attacker to cause a DoS condition, or
| possibly other expanded impacts, resulting from memory corruption on
| an affected device.    This vulnerability is due to improper
| boundary checks for content in PE files during scanning, which may
| result in an out-of-bounds buffer write. An attacker could exploit
| this vulnerability by submitting a crafted file that contains PE
| content to be scanned by ClamAV on an affected device. A successful
| exploit could allow the attacker to cause the ClamAV scanning
| process to terminate, resulting in a DoS condition on the affected
| software.


CVE-2026-20214[1]:
| A vulnerability in the FSG file format parser of ClamAV could allow
| an unauthenticated, remote attacker to cause a DoS condition, or
| possibly other expanded impacts, resulting from memory corruption on
| an affected device.    This vulnerability is due to improper
| boundary checks for content in FSG files during scanning, which may
| result in an out-of-bounds buffer write. An attacker could exploit
| this vulnerability by submitting a crafted file that contains
| portable executable content compressed with FSG to be scanned by
| ClamAV on an affected device. A successful exploit could allow the
| attacker to cause the ClamAV scanning process to terminate,
| resulting in a DoS condition on the affected software.


CVE-2026-20215[2]:
| A vulnerability in the 7z file format parser of ClamAV could allow
| an unauthenticated, remote attacker to cause a DoS condition, or
| possibly other expanded impacts, resulting from memory corruption on
| an affected device.    This vulnerability is due to improper
| boundary checks for content in 7z files during scanning, which may
| result in an out-of-bounds buffer write. An attacker could exploit
| this vulnerability by submitting a crafted file that contains
| 7z&nbsp;content to be scanned by ClamAV on an affected device. A
| successful exploit could allow the attacker to cause the ClamAV
| scanning process to terminate, resulting in a DoS condition on the
| affected software.


CVE-2026-20216[3]:
| A vulnerability in the InstallShield file format parser of ClamAV
| could allow an unauthenticated, remote attacker to cause a DoS
| condition on an affected device.    This vulnerability is due to
| improper handling of temporary resources during file scanning. An
| attacker could exploit this vulnerability by submitting a crafted
| InstallShield file to be scanned by ClamAV on an affected device. A
| successful exploit could allow the attacker to terminate the ClamAV
| scanning process and temporarily consume available system resources,
| resulting in a DoS condition on the affected software.


CVE-2026-20217[4]:
| A vulnerability in the PESpin file format parser of ClamAV could
| allow an unauthenticated, remote attacker to cause a DoS condition,
| or possibly other expanded impacts, resulting from memory corruption
| on an affected device.    This vulnerability is due to improper
| boundary checks for content in PESpin files during scanning, which
| may result in an out-of-bounds buffer write. An attacker could
| exploit this vulnerability by submitting a crafted file that
| contains PESpin content to be scanned by ClamAV on an affected
| device. A successful exploit could allow the attacker to cause the
| ClamAV scanning process to terminate, resulting in a DoS condition
| on the affected software.


CVE-2026-20243[5]:
| A vulnerability in the ALZ file format parser of ClamAV could allow
| an unauthenticated, remote attacker to cause a DoS condition, or
| possibly other expanded impacts, resulting from memory corruption on
| an affected device.    This vulnerability is due to improper
| boundary checks for content in ALZ files during scanning, which may
| result in an out-of-bounds buffer write. An attacker could exploit
| this vulnerability by submitting a crafted file that contains ALZ
| content to be scanned by ClamAV on an affected device. A successful
| exploit could allow the attacker to cause the ClamAV scanning
| process to terminate, resulting in a DoS condition on the affected
| software.


CVE-2026-20244[6]:
| A vulnerability in the DMG file format parser of ClamAV could allow
| an unauthenticated, remote attacker to cause a DoS condition, or
| possibly other expanded impacts, resulting from memory corruption on
| an affected device.    This vulnerability is due to improper
| boundary checks for content in DMG files during scanning, which may
| result in an integer overflow on 32-bit platforms only. An attacker
| could exploit this vulnerability by submitting a crafted file that
| contains DMG content to be scanned by ClamAV on an affected device.
| A successful exploit could allow the attacker to cause the ClamAV
| scanning process to terminate, resulting in a DoS condition on the
| affected software.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities &amp; Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-20213
    https://www.cve.org/CVERecord?id=CVE-2026-20213
[1] https://security-tracker.debian.org/tracker/CVE-2026-20214
    https://www.cve.org/CVERecord?id=CVE-2026-20214
[2] https://security-tracker.debian.org/tracker/CVE-2026-20215
    https://www.cve.org/CVERecord?id=CVE-2026-20215
[3] https://security-tracker.debian.org/tracker/CVE-2026-20216
    https://www.cve.org/CVERecord?id=CVE-2026-20216
[4] https://security-tracker.debian.org/tracker/CVE-2026-20217
    https://www.cve.org/CVERecord?id=CVE-2026-20217
[5] https://security-tracker.debian.org/tracker/CVE-2026-20243
    https://www.cve.org/CVERecord?id=CVE-2026-20243
[6] https://security-tracker.debian.org/tracker/CVE-2026-20244
    https://www.cve.org/CVERecord?id=CVE-2026-20244
[7] https://blog.clamav.net/2026/07/clamav-153-and-145-security-patch.html

Regards,
Salvatore
]