chore(deps): update docker.io/clamav/clamav docker tag to v1.5.4 - #178
Open
renovate[bot] wants to merge 1 commit into
Open
chore(deps): update docker.io/clamav/clamav docker tag to v1.5.4#178renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/docker.io-clamav-clamav-1.x
branch
from
August 10, 2026 05:57
4cbd2cd to
6ac5488
Compare
renovate
Bot
force-pushed
the
renovate/docker.io-clamav-clamav-1.x
branch
2 times, most recently
from
August 24, 2026 02:10
3fbce16 to
20ef8ef
Compare
renovate
Bot
force-pushed
the
renovate/docker.io-clamav-clamav-1.x
branch
from
August 31, 2026 11:03
20ef8ef to
cece97e
Compare
renovate
Bot
force-pushed
the
renovate/docker.io-clamav-clamav-1.x
branch
from
September 7, 2026 07:34
cece97e to
941fa27
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.5.3→1.5.4Release Notes
Cisco-Talos/clamav (docker.io/clamav/clamav)
v1.5.4: ClamAV 1.5.4ClamAV 1.5.4 is a patch release with the following fixes:
CVE-2026-20337:
Fixed ZIP catalogue capacity tracking that could write beyond a heap
allocation while indexing local file headers.
This issue affects ClamAV 1.5.0 through 1.5.3.
The fix is included in 1.5.4.
Thank you to Kevin Stubbings of the GitHub Security Lab team for identifying
this issue.
CVE-2026-20345:
Fixed an indexing error while converting GPT partition names that could
read or write beyond a stack-allocated partition entry.
This issue affects ClamAV 0.98.2 through 1.5.3.
The fix is included in 1.4.6 and 1.5.4.
Thank you to Atuin - Automated Vulnerability Discovery Engine, Tianchu Chen
of Tencent Xuanwu Lab for identifying this issue.
CVE-2026-20339:
Fixed an integer overflow in the PESpin unpacker that could allocate an
undersized buffer and then write beyond it while rebuilding a PE file.
This issue affects ClamAV 0.90 through 1.5.3.
The fix is included in 1.4.6 and 1.5.4.
Thank you to Feng Xue and, independently, Yazdan Soltani for identifying
this issue.
CVE-2026-20338:
Fixed ownership handling while merging ZIP catalogue records that could
cause an invalid free while scanning a malformed archive.
This issue affects ClamAV 1.5.0 through 1.5.3.
The fix is included in 1.5.4.
Thank you to Daggolu Rakesh and, independently, Yazdan Soltani for
identifying this issue.
CVE-2026-20346:
Fixed an integer underflow in the PDF parser that could cause a crash while
reading a malformed hex string.
This issue affects ClamAV 1.4.5 and earlier, and ClamAV 1.5.0 through
1.5.3.
The fix is included in 1.4.6 and 1.5.4.
Thank you to Tristan (@TristanInSec) for identifying this issue.
CVE-2026-20347:
Fixed undefined behavior and integer overflow in the Mach-O parser that
could cause a crash while scanning a malformed Mach-O file.
This issue affects ClamAV 1.4.5 and earlier, and ClamAV 1.5.0 through
1.5.3.
The fix is included in 1.4.6 and 1.5.4.
Thank you to Tristan (@TristanInSec) for identifying this issue.
CVE-2026-20348:
Fixed XAR parser size handling that could request an excessive allocation
or exceed scan limits while decompressing a malformed table of contents.
This issue affects ClamAV 0.98.1 through 1.5.3.
The fix is included in 1.4.6 and 1.5.4.
Thank you to leduckhuong for identifying this issue.
CVE-2025-8088:
Adopted the upstream UnRAR project fix in ClamAV's bundled UnRAR library.
The fix rejects path separators in NTFS alternate data stream names to
prevent extraction outside ClamAV's temporary scan directory on Windows.
This issue affects ClamAV 0.101.0 through 1.5.3.
The fix is included in 1.4.6 and 1.5.4.
Thank you to Yazdan Soltani for identifying that this issue affects ClamAV.
Fixed thread-safety issues in the
clamdSTATS command that could discloseprocess memory or crash the daemon while scans and STATS requests run
concurrently. Also fixed partial socket-write handling used for large STATS
responses.
This issue affects ClamAV 0.95 through 1.5.3.
The fix is included in 1.4.6 and 1.5.4.
FreeBSD: Restored support for safe quarantine move and remove actions while
preserving protection against source-path replacement races.
This issue affects ClamAV 1.4.5 and 1.5.3.
The fix is included in 1.4.6 and 1.5.4.
Fixed an OpenSSL library-context leak in legacy hashing helpers when a
requested message digest cannot be fetched, such as when the default
provider is unavailable in a FIPS-enabled environment.
This issue affects ClamAV 1.5.0 through 1.5.3.
The fix is included in 1.5.4.
Upgraded the Rust
crossbeam-epochdependency to resolve theRUSTSEC-2026-0204 advisory.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.