{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "* SECURITY UPDATE: heap buffer overflow via an integer overflow in the PE\n     rebuilder\n     - debian/patches/CVE-2026-20213.patch: sum rebuilt section sizes in a\n       64-bit temporary and reject packed section totals or allocations that\n       exceed CLI_MAX_ALLOCATION in libclamav/rebuildpe.c.\n     - CVE-2026-20213\n   * SECURITY UPDATE: out-of-bounds write via a section loop underflow in the\n     FSG unpacker\n     - debian/patches/CVE-2026-20214.patch: iterate the section loop with\n       t < sectcnt instead of t <= sectcnt - 1, which underflows when sectcnt\n       is zero, in libclamav/pe.c.\n     - CVE-2026-20214\n   * SECURITY UPDATE: heap buffer overflow via a 7z substream count overflow\n     - debian/patches/CVE-2026-20215.patch: reject archives whose total\n       unpack-stream count would overflow UInt32 before it is accumulated in\n       libclamav/7z/7zIn.c.\n     - CVE-2026-20215\n   * SECURITY UPDATE: denial of service via unenforced extraction limits in\n     the InstallShield parser\n     - debian/patches/CVE-2026-20216.patch: apply cli_checklimits() to header\n       parsing and to cab extraction output, and guard the output size\n       accumulator against overflow, in libclamav/ishield.c.\n     - CVE-2026-20216\n   * SECURITY UPDATE: invalid free via incorrect cleanup bitmap tracking in\n     the PESpin unpacker\n     - debian/patches/CVE-2026-20217.patch: shift the bitmap that the cleanup\n       loop tests, not the unrelated bitman variable, in libclamav/spin.c.\n     - CVE-2026-20217\n   * SECURITY UPDATE: denial of service via size handling errors in the ALZ\n     parser\n     - debian/patches/CVE-2026-20243.patch: harden ALZ size arithmetic,\n       extract stored, bzip2 and deflate members under scan budgets, use\n       bounded flate2 reads and drop the inflate dependency, in\n       libclamav_rust/src/{alz,scanners,util,sys}.rs, libclamav_rust/Cargo.toml,\n       libclamav_rust/build.rs, libclamav/libclamav.map and Cargo.lock.\n     - CVE-2026-20243\n   * SECURITY UPDATE: out-of-bounds read via integer overflow in the DMG mish\n     size checks on 32-bit platforms\n     - debian/patches/CVE-2026-20244.patch: compute the expected mish block\n       length in a 64-bit integer, keep the XML range check in subtraction\n       form and avoid overflow in the base64 buffer size, in libclamav/dmg.c.\n     - CVE-2026-20244",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789291359",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789291359"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian11els/advisories/2026/clsa-2026_1789291359.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-13T09:24:13Z",
      "generator": {
        "date": "2026-09-13T09:24:13Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1789291359",
      "initial_release_date": "2026-09-13T09:24:13Z",
      "revision_history": [
        {
          "date": "2026-09-13T09:24:13Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "Fix of 7 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 11",
                "product": {
                  "name": "Debian 11",
                  "product_id": "Debian-11",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:11:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                "product": {
                  "name": "libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                  "product_id": "libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libclamav-dev@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                "product": {
                  "name": "clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                  "product_id": "clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/clamav-daemon@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                "product": {
                  "name": "libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                  "product_id": "libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libclamav12@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                "product": {
                  "name": "clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                  "product_id": "clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/clamav-milter@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                "product": {
                  "name": "clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                  "product_id": "clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/clamdscan@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                "product": {
                  "name": "clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                  "product_id": "clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/clamav@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                "product": {
                  "name": "clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                  "product_id": "clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/clamav-freshclam@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=arm64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "arm64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                "product": {
                  "name": "libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                  "product_id": "libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libclamav-dev@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                "product": {
                  "name": "clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                  "product_id": "clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/clamav-daemon@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                "product": {
                  "name": "libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                  "product_id": "libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libclamav12@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                "product": {
                  "name": "clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                  "product_id": "clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/clamav-milter@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                "product": {
                  "name": "clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                  "product_id": "clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/clamdscan@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                "product": {
                  "name": "clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                  "product_id": "clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/clamav@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                "product": {
                  "name": "clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                  "product_id": "clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/clamav-freshclam@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
                "product": {
                  "name": "clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
                  "product_id": "clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/clamav-base@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
                "product": {
                  "name": "clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
                  "product_id": "clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/clamav-docs@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
                "product": {
                  "name": "clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
                  "product_id": "clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/clamav-doc@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
                "product": {
                  "name": "clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
                  "product_id": "clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/clamav-testfiles@1.4.3%2Bdfsg-1~deb11u1%2Btuxcare.els1?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
        },
        "product_reference": "libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64"
        },
        "product_reference": "libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all as a component of Debian 11",
          "product_id": "Debian-11:clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all"
        },
        "product_reference": "clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64"
        },
        "product_reference": "clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
        },
        "product_reference": "clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64"
        },
        "product_reference": "libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
        },
        "product_reference": "libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
        },
        "product_reference": "clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64"
        },
        "product_reference": "clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
        },
        "product_reference": "clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64"
        },
        "product_reference": "clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all as a component of Debian 11",
          "product_id": "Debian-11:clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all"
        },
        "product_reference": "clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all as a component of Debian 11",
          "product_id": "Debian-11:clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all"
        },
        "product_reference": "clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all as a component of Debian 11",
          "product_id": "Debian-11:clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all"
        },
        "product_reference": "clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64"
        },
        "product_reference": "clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
        },
        "product_reference": "clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
        },
        "product_reference": "clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64"
        },
        "product_reference": "clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-20214",
      "cwe": {
        "id": "CWE-120",
        "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
      },
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device.\r\n\r\nThis vulnerability is due to improper boundary checks for content in FSG files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains portable executable content compressed with FSG to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-20214"
        },
        {
          "category": "external",
          "summary": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR",
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR"
        }
      ],
      "release_date": "2026-07-01T17:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-13T09:22:41.658422Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789291359",
          "product_ids": [
            "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789291359"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-20244",
      "cwe": {
        "id": "CWE-120",
        "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
      },
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device.\r\n\r\nThis vulnerability is due to improper boundary checks for content in DMG files during scanning, which may result in an integer overflow on 32-bit platforms only. An attacker could exploit this vulnerability by submitting a crafted file that contains DMG content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-20244"
        },
        {
          "category": "external",
          "summary": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR",
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR"
        }
      ],
      "release_date": "2026-07-01T17:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-13T09:22:41.658422Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789291359",
          "product_ids": [
            "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789291359"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-20243",
      "cwe": {
        "id": "CWE-120",
        "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
      },
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device.\r\n\r\nThis vulnerability is due to improper boundary checks for content in ALZ files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains ALZ content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-20243"
        },
        {
          "category": "external",
          "summary": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR",
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR"
        }
      ],
      "release_date": "2026-07-01T17:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-13T09:22:41.658422Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789291359",
          "product_ids": [
            "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789291359"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-20213",
      "cwe": {
        "id": "CWE-120",
        "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
      },
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device.\r\n\r\nThis vulnerability is due to improper boundary checks for content in PE files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains PE content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-20213"
        },
        {
          "category": "external",
          "summary": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR",
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR"
        }
      ],
      "release_date": "2026-07-01T17:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-13T09:22:41.658422Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789291359",
          "product_ids": [
            "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789291359"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-20217",
      "cwe": {
        "id": "CWE-120",
        "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
      },
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device.\r\n\r\nThis vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains PESpin content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-20217"
        },
        {
          "category": "external",
          "summary": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR",
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR"
        }
      ],
      "release_date": "2026-07-01T17:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-13T09:22:41.658422Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789291359",
          "product_ids": [
            "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789291359"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-20216",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.\r\n\r\nThis vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a crafted InstallShield file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process and temporarily consume available system resources, resulting in a DoS condition on the affected software.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-20216"
        },
        {
          "category": "external",
          "summary": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR",
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR"
        }
      ],
      "release_date": "2026-07-01T17:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-13T09:22:41.658422Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789291359",
          "product_ids": [
            "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789291359"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-20215",
      "cwe": {
        "id": "CWE-120",
        "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
      },
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device.\r\n\r\nThis vulnerability is due to improper boundary checks for content in 7z files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains 7z&nbsp;content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
          "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
          "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
          "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-20215"
        },
        {
          "category": "external",
          "summary": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR",
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR"
        }
      ],
      "release_date": "2026-07-01T17:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-13T09:22:41.658422Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789291359",
          "product_ids": [
            "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-base-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-daemon-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-doc-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-docs-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-freshclam-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamav-milter-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:clamav-testfiles-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.all",
            "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:clamdscan-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:libclamav-dev-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64",
            "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.amd64",
            "Debian-11:libclamav12-0:1.4.3+dfsg-1~deb11u1+tuxcare.els1.arm64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789291359"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}