Home / mailings [USN-8788-1] ClamAV vulnerabilities
Posted on 21 September 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8788-1
September 21, 2026
clamav vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in ClamAV.
Software Description:
- clamav: Anti-virus utility for Unix
Details:
It was discovered that ClamAV incorrectly handled certain zip archive
files. A remote attacker could possibly use this issue to cause ClamAV
to crash, resulting in a denial of service. (CVE-2026-20337,
CVE-2026-20338)
It was discovered that ClamAV incorrectly handled certain PESpin files.
A remote attacker could possibly use this issue to cause ClamAV to
crash, resulting in a denial of service. (CVE-2026-20339)
It was discovered that ClamAV incorrectly handled certain GPT files. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2026-20345)
It was discovered that ClamAV incorrectly handled certain PDF files. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2026-20346)
It was discovered that ClamAV incorrectly handled certain Mach-O files.
A remote attacker could possibly use this issue to cause ClamAV to
crash, resulting in a denial of service. (CVE-2026-20347)
It was discovered that ClamAV incorrectly handled certain XAR files. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2026-20348)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
clamav 1.5.4+dfsg-0ubuntu0.26.04.1
Ubuntu 24.04 LTS
clamav 1.5.4+dfsg-0ubuntu0.24.04.1
Ubuntu 22.04 LTS
clamav 1.5.4+dfsg-0ubuntu0.22.04.1
This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
References:
https://ubuntu.com/security/notices/USN-8788-1
CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345,
CVE-2026-20346, CVE-2026-20347, CVE-2026-20348
Package Information:
https://launchpad.net/ubuntu/+source/clamav/1.5.4+dfsg-0ubuntu0.26.04.1
https://launchpad.net/ubuntu/+source/clamav/1.5.4+dfsg-0ubuntu0.24.04.1
https://launchpad.net/ubuntu/+source/clamav/1.5.4+dfsg-0ubuntu0.22.04.1
--===============2542995836740704687==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
