[Pkg-clamav-devel] Bug#1143939: clamav: CVE-2026-20339 CVE-2026-20345 CVE-2026-20346 CVE-2026-20347 CVE-2026-20348

Florian Ernst florian_ernst at gmx.net
Sun Aug 16 08:15:37 BST 2026


Control: tags -1 fixed-upstream

On Sat, Aug 08, 2026 at 06:34:21PM +0200, Moritz Mühlenhoff wrote:
> The following vulnerabilities were published for clamav.
> 
> CVE-2026-20339[0]:
> CVE-2026-20345[1]:
> CVE-2026-20346[2]:
> CVE-2026-20347[3]:
> CVE-2026-20348[4]:

JFTR, these are all fixed upstream in release 1.4.6, cf.
<https://github.com/Cisco-Talos/clamav/releases#release-clamav-1.4.6>.

Cheers,
Flo
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-clamav-devel/attachments/20260816/4c81a106/attachment.sig>


More information about the Pkg-clamav-devel mailing list