ClamAV

Cisco Systems, Inc.·Cisco.ClamAV

ClamAV® is an open-source antivirus engine for detecting trojans, viruses, malware & other malicious threats.

winget install --id Cisco.ClamAV --exact --source winget

Latest 1.5.4·August 7, 2026

Release Notes

ClamAV 1.5.4 is a patch release with the following fixes:

  • CVE-2026-20337: Fixed ZIP catalogue capacity tracking that could write beyond a heap allocation while indexing local file headers. This issue affects ClamAV 1.5.0 through 1.5.3. The fix is included in 1.5.4. Thank you to Kevin Stubbings of the GitHub Security Lab team for identifying this issue.
  • CVE-2026-20345: Fixed an indexing error while converting GPT partition names that could read or write beyond a stack-allocated partition entry. This issue affects ClamAV 0.98.2 through 1.5.3. The fix is included in 1.4.6 and 1.5.4. Thank you to Atuin - Automated Vulnerability Discovery Engine, Tianchu Chen of Tencent Xuanwu Lab for identifying this issue.
  • CVE-2026-20339: Fixed an integer overflow in the PESpin unpacker that could allocate an undersized buffer and then write beyond it while rebuilding a PE file. This issue affects ClamAV 0.90 through 1.5.3. The fix is included in 1.4.6 and 1.5.4. Thank you to Feng Xue and, independently, Yazdan Soltani for identifying this issue.
  • CVE-2026-20338: Fixed ownership handling while merging ZIP catalogue records that could cause an invalid free while scanning a malformed archive. This issue affects ClamAV 1.5.0 through 1.5.3. The fix is included in 1.5.4. Thank you to Daggolu Rakesh and, independently, Yazdan Soltani for identifying this issue.
  • CVE-2026-20346: Fixed an integer underflow in the PDF parser that could cause a crash while reading a malformed hex string. This issue affects ClamAV 1.4.5 and earlier, and ClamAV 1.5.0 through 1.5.3. The fix is included in 1.4.6 and 1.5.4. Thank you to Tristan (@TristanInSec) for identifying this issue.
  • CVE-2026-20347: Fixed undefined behavior and integer overflow in the Mach-O parser that could cause a crash while scanning a malformed Mach-O file. This issue affects ClamAV 1.4.5 and earlier, and ClamAV 1.5.0 through 1.5.3. The fix is included in 1.4.6 and 1.5.4. Thank you to Tristan (@TristanInSec) for identifying this issue.
  • CVE-2026-20348: Fixed XAR parser size handling that could request an excessive allocation or exceed scan limits while decompressing a malformed table of contents. This issue affects ClamAV 0.98.1 through 1.5.3. The fix is included in 1.4.6 and 1.5.4. Thank you to leduckhuong for identifying this issue.
  • CVE-2025-8088: Adopted the upstream UnRAR project fix in ClamAV's bundled UnRAR library. The fix rejects path separators in NTFS alternate data stream names to prevent extraction outside ClamAV's temporary scan directory on Windows. This issue affects ClamAV 0.101.0 through 1.5.3. The fix is included in 1.4.6 and 1.5.4. Thank you to Yazdan Soltani for identifying that this issue affects ClamAV.
  • Fixed thread-safety issues in the clamd STATS command that could disclose process memory or crash the daemon while scans and STATS requests run concurrently. Also fixed partial socket-write handling used for large STATS responses. This issue affects ClamAV 0.95 through 1.5.3. The fix is included in 1.4.6 and 1.5.4.
  • FreeBSD: Restored support for safe quarantine move and remove actions while preserving protection against source-path replacement races. This issue affects ClamAV 1.4.5 and 1.5.3. The fix is included in 1.4.6 and 1.5.4.
  • Fixed an OpenSSL library-context leak in legacy hashing helpers when a requested message digest cannot be fetched, such as when the default provider is unavailable in a FIPS-enabled environment. This issue affects ClamAV 1.5.0 through 1.5.3. The fix is included in 1.5.4.
  • Upgraded the Rust crossbeam-epoch dependency to resolve the RUSTSEC-2026-0204 advisory.

Installer type: wix

x86AD272158697498167C8A39FE1407B01A298ED830DA8E6833718B1DACA7EA7069
x64A025FA23A4B9D64FCE448D5A211AFCF30DC26BA6528186E6223D1B945F9D95D6
arm644D1A36CDDDD79294CC607D4B34DEE1600C497BD5679C334F4321C5C3616CA772

Details

Homepage
https://github.com/Cisco-Talos/clamav
License
GPL-2.0
Publisher
Cisco Systems, Inc.
Support
https://github.com/Cisco-Talos/clamav/issues

Tags

antivirusclamavopen-source

Older versions (9)

1.5.3
x865DC403D8597481BD1F6C541076CF9FA9A1B364E0FE4A1F5AFA00807708545374
x64DCE5C5EB819D67039043A9D8615D3A03642C7A33D1C517711E42AA0B64A980DD
arm645E0207F9E2108E41705EF55CDA126CF8C2516E1B6ADA1F93CBF3CFDD8DAFFDC4
1.5.2
x8651917991B6A92F00A0D8CB5F812715DAC2E5494245533917524CAF774F7A3B25
x64708FEAF31155BDE3D39F0CB65E093039B6CEE831E17CA47535582D5296637C25
arm645FE399DE3A4FC81C4A5B0CBA60B4369E12C2C6704CA92E5BB1FF30E39AAA5CF6
1.5.1
x86D82929AFC5D58FC443CC482AA2844255EF02C99291810665A7E8EE63BF7B33F3
x642247F5C8E2B9EDA917D6695F87331F87E6997CA8E502DAD1D2403D3405C059A8
arm6443F99CC819CD1C352CFE0CBA834CC0FA7D45EBF6D581D100BEC6F03BCAE51E1B
1.5.0
x860F957220A2A2C9032706977EB8E344EA1B789604B2787EB80DD70F2A4171584D
x643F12E39E647A301CD632002BB4125A14FE5F86314A91FCE09137AEC2C69D5894
arm64C33D06D3F44003133F04BA4E51CF39BAFBF04B2B564CFC61DBF2CFAC7A926122
1.4.2
x6465308FD2AD2D550206380E406FED22F74B49C35B3F39ED8CC28D52363C8F1F2B
1.3.1
x6490806B663B863AE32AAAA2B750F56DB10B91D876DE9081B666CD1863ED380179
1.3.0
x64DB99569EAF841A7118A7C9974DCB8879A70B7A04E91C510DC91D64D35D883481
1.1.0
x643AFADA801463199D9901E4445E92B486993C14C22CA179D17ABEC74D37E384BB
0.105.0
x64FE98FB8F5A195AA53520A9AA61A6D51E5A232A1FE5389B309278FC7604D49AD0