Описание
Security update for clamav
This update for clamav fixes the following issues:
Update to clamav 1.5.2:
Security issue:
- CVE-2026-20031: improper error handling in the HTML CSS module when splitting UTF-8 strings can lead to denial of service conditions via a crafted HTML file (bsc#1259207).
Non security issue:
- Support transactional updates (jsc#PED-14819).
Changelog:
- Fixed a possible infinite loop when scanning some JPEG files by upgrading affected ClamAV dependency, a Rust image library.
- The CVD verification process will now ignore certificate files in the CVD certs directory when the user lacks read permissions.
- Freshclam: Fix CLD verification bug with PrivateMirror option.
- Upgraded the Rust bytes dependency to a newer version to resolve RUSTSEC-2026-0007 advisory.
- Fixed a possible crash caused by invalid pointer alignment on some platforms.
- Minimal required Rust version is now 1.87.
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15 SP7
clamav-1.5.2-150600.18.25.1
clamav-devel-1.5.2-150600.18.25.1
clamav-docs-html-1.5.2-150600.18.25.1
clamav-milter-1.5.2-150600.18.25.1
libclamav12-1.5.2-150600.18.25.1
libclammspack0-1.5.2-150600.18.25.1
libfreshclam4-1.5.2-150600.18.25.1
SUSE Linux Enterprise Server 15 SP6-LTSS
clamav-1.5.2-150600.18.25.1
clamav-devel-1.5.2-150600.18.25.1
clamav-docs-html-1.5.2-150600.18.25.1
clamav-milter-1.5.2-150600.18.25.1
libclamav12-1.5.2-150600.18.25.1
libclammspack0-1.5.2-150600.18.25.1
libfreshclam4-1.5.2-150600.18.25.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
clamav-1.5.2-150600.18.25.1
clamav-devel-1.5.2-150600.18.25.1
clamav-docs-html-1.5.2-150600.18.25.1
clamav-milter-1.5.2-150600.18.25.1
libclamav12-1.5.2-150600.18.25.1
libclammspack0-1.5.2-150600.18.25.1
libfreshclam4-1.5.2-150600.18.25.1
openSUSE Leap 15.6
clamav-1.5.2-150600.18.25.1
clamav-devel-1.5.2-150600.18.25.1
clamav-docs-html-1.5.2-150600.18.25.1
clamav-milter-1.5.2-150600.18.25.1
libclamav12-1.5.2-150600.18.25.1
libclammspack0-1.5.2-150600.18.25.1
libfreshclam4-1.5.2-150600.18.25.1
Ссылки
- Link for SUSE-SU-2026:1325-1
- E-Mail link for SUSE-SU-2026:1325-1
- SUSE Security Ratings
- SUSE Bug 1221954
- SUSE Bug 1258072
- SUSE Bug 1259207
- SUSE CVE CVE-2026-20031 page
Описание
A vulnerability in the HTML Cascading Style Sheets (CSS) module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when splitting UTF-8 strings. An attacker could exploit this vulnerability by submitting a crafted HTML file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the scanning process.
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:clamav-1.5.2-150600.18.25.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:clamav-devel-1.5.2-150600.18.25.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:clamav-docs-html-1.5.2-150600.18.25.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:clamav-milter-1.5.2-150600.18.25.1
Ссылки
- CVE-2026-20031
- SUSE Bug 1259207