Skip to content

chore(deps): update docker.io/clamav/clamav docker tag to v1.5.4 - #178

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/docker.io-clamav-clamav-1.x
Open

chore(deps): update docker.io/clamav/clamav docker tag to v1.5.4#178
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/docker.io-clamav-clamav-1.x

Conversation

@renovate

@renovate renovate Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
docker.io/clamav/clamav (source) patch 1.5.31.5.4

Release Notes

Cisco-Talos/clamav (docker.io/clamav/clamav)

v1.5.4: ClamAV 1.5.4

ClamAV 1.5.4 is a patch release with the following fixes:

  • CVE-2026-20337:
    Fixed ZIP catalogue capacity tracking that could write beyond a heap
    allocation while indexing local file headers.

    This issue affects ClamAV 1.5.0 through 1.5.3.
    The fix is included in 1.5.4.

    Thank you to Kevin Stubbings of the GitHub Security Lab team for identifying
    this issue.

  • CVE-2026-20345:
    Fixed an indexing error while converting GPT partition names that could
    read or write beyond a stack-allocated partition entry.

    This issue affects ClamAV 0.98.2 through 1.5.3.
    The fix is included in 1.4.6 and 1.5.4.

    Thank you to Atuin - Automated Vulnerability Discovery Engine, Tianchu Chen
    of Tencent Xuanwu Lab for identifying this issue.

  • CVE-2026-20339:
    Fixed an integer overflow in the PESpin unpacker that could allocate an
    undersized buffer and then write beyond it while rebuilding a PE file.

    This issue affects ClamAV 0.90 through 1.5.3.
    The fix is included in 1.4.6 and 1.5.4.

    Thank you to Feng Xue and, independently, Yazdan Soltani for identifying
    this issue.

  • CVE-2026-20338:
    Fixed ownership handling while merging ZIP catalogue records that could
    cause an invalid free while scanning a malformed archive.

    This issue affects ClamAV 1.5.0 through 1.5.3.
    The fix is included in 1.5.4.

    Thank you to Daggolu Rakesh and, independently, Yazdan Soltani for
    identifying this issue.

  • CVE-2026-20346:
    Fixed an integer underflow in the PDF parser that could cause a crash while
    reading a malformed hex string.

    This issue affects ClamAV 1.4.5 and earlier, and ClamAV 1.5.0 through
    1.5.3.
    The fix is included in 1.4.6 and 1.5.4.

    Thank you to Tristan (@​TristanInSec) for identifying this issue.

  • CVE-2026-20347:
    Fixed undefined behavior and integer overflow in the Mach-O parser that
    could cause a crash while scanning a malformed Mach-O file.

    This issue affects ClamAV 1.4.5 and earlier, and ClamAV 1.5.0 through
    1.5.3.
    The fix is included in 1.4.6 and 1.5.4.

    Thank you to Tristan (@​TristanInSec) for identifying this issue.

  • CVE-2026-20348:
    Fixed XAR parser size handling that could request an excessive allocation
    or exceed scan limits while decompressing a malformed table of contents.

    This issue affects ClamAV 0.98.1 through 1.5.3.
    The fix is included in 1.4.6 and 1.5.4.

    Thank you to leduckhuong for identifying this issue.

  • CVE-2025-8088:
    Adopted the upstream UnRAR project fix in ClamAV's bundled UnRAR library.
    The fix rejects path separators in NTFS alternate data stream names to
    prevent extraction outside ClamAV's temporary scan directory on Windows.

    This issue affects ClamAV 0.101.0 through 1.5.3.
    The fix is included in 1.4.6 and 1.5.4.

    Thank you to Yazdan Soltani for identifying that this issue affects ClamAV.

  • Fixed thread-safety issues in the clamd STATS command that could disclose
    process memory or crash the daemon while scans and STATS requests run
    concurrently. Also fixed partial socket-write handling used for large STATS
    responses.

    This issue affects ClamAV 0.95 through 1.5.3.
    The fix is included in 1.4.6 and 1.5.4.

  • FreeBSD: Restored support for safe quarantine move and remove actions while
    preserving protection against source-path replacement races.

    This issue affects ClamAV 1.4.5 and 1.5.3.
    The fix is included in 1.4.6 and 1.5.4.

  • Fixed an OpenSSL library-context leak in legacy hashing helpers when a
    requested message digest cannot be fetched, such as when the default
    provider is unavailable in a FIPS-enabled environment.

    This issue affects ClamAV 1.5.0 through 1.5.3.
    The fix is included in 1.5.4.

  • Upgraded the Rust crossbeam-epoch dependency to resolve the
    RUSTSEC-2026-0204 advisory.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/docker.io-clamav-clamav-1.x branch from 4cbd2cd to 6ac5488 Compare August 10, 2026 05:57
@renovate
renovate Bot force-pushed the renovate/docker.io-clamav-clamav-1.x branch 2 times, most recently from 3fbce16 to 20ef8ef Compare August 24, 2026 02:10
@renovate
renovate Bot force-pushed the renovate/docker.io-clamav-clamav-1.x branch from 20ef8ef to cece97e Compare August 31, 2026 11:03
@renovate
renovate Bot force-pushed the renovate/docker.io-clamav-clamav-1.x branch from cece97e to 941fa27 Compare September 7, 2026 07:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants