Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:1324-1

Опубликовано: 14 апр. 2026
Источник: suse-cvrf

Описание

Security update for clamav

This update for clamav fixes the following issues:

Update to clamav 1.5.2:

  • CVE-2026-20031: improper error handling in the HTML CSS module when splitting UTF-8 strings can lead to denial of service conditions via a crafted HTML file (bsc#1259207).

Non security issue:

  • Support transactional updates (jsc#PED-14819).
  • Require main and library packages to be of the same version and release (bsc#1258072).

Changelog:

  • Fixed a possible infinite loop when scanning some JPEG files by upgrading affected ClamAV dependency, a Rust image library.
  • The CVD verification process will now ignore certificate files in the CVD certs directory when the user lacks read permissions.
  • Freshclam: Fix CLD verification bug with PrivateMirror option.
  • Upgraded the Rust bytes dependency to a newer version to resolve RUSTSEC-2026-0007 advisory.
  • Fixed a possible crash caused by invalid pointer alignment on some platforms.
  • Minimal required Rust version is now 1.87.

Список пакетов

SUSE Linux Enterprise Server 12 SP5-LTSS
clamav-1.5.2-3.53.1
clamav-devel-1.5.2-3.53.1
clamav-docs-html-1.5.2-3.53.1
clamav-milter-1.5.2-3.53.1
libclamav12-1.5.2-3.53.1
libclammspack0-1.5.2-3.53.1
libfreshclam4-1.5.2-3.53.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
clamav-1.5.2-3.53.1
clamav-devel-1.5.2-3.53.1
clamav-docs-html-1.5.2-3.53.1
clamav-milter-1.5.2-3.53.1
libclamav12-1.5.2-3.53.1
libclammspack0-1.5.2-3.53.1
libfreshclam4-1.5.2-3.53.1

Описание

A vulnerability in the HTML Cascading Style Sheets (CSS) module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when splitting UTF-8 strings. An attacker could exploit this vulnerability by submitting a crafted HTML file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the scanning process.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:clamav-1.5.2-3.53.1
SUSE Linux Enterprise Server 12 SP5-LTSS:clamav-devel-1.5.2-3.53.1
SUSE Linux Enterprise Server 12 SP5-LTSS:clamav-docs-html-1.5.2-3.53.1
SUSE Linux Enterprise Server 12 SP5-LTSS:clamav-milter-1.5.2-3.53.1

Ссылки
Уязвимость SUSE-SU-2026:1324-1