Alert GCSA-26164 - Aggiornamento di sicurezza per ClamAV

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ****************************************************************** alert ID: GCSA-26164 data: 11 agosto 2026 titolo: Aggiornamento di sicurezza per ClamAV ****************************************************************** :: Descrizione del problema Sono state rilasciate nuove versioni dell'antivirus open source ClamAV, che risolvono varie vulnerabilita'. Maggiori informazioni sono disponibili alla sezione "Riferimenti". :: Software / Dispositivi interessati ClamAV versioni precedenti alla 1.5.4 ClamAV versioni precedenti alla 1.4.6 Cisco Secure Endpoint Connector :: Impatto Attacco alla confidenzialita' dei dati (ID) Denial of Service (DoS) :: Soluzioni Aggiornare il prodotto alle ultime versioni https://www.clamav.net/downloads https://github.com/Cisco-Talos/clamav/releases Upgrading ClamAV https://docs.clamav.net/faq/faq-upgrade.html :: Riferimenti ClamAV Blog https://blog.clamav.net/2026/08/clamav-154-and-146-security-patch.html ClamAV Vulnerabilities Affecting Cisco Products https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26 SecurityWeek https://www.securityweek.com/cisco-warns-of-high-severity-clamav-vulnerabilities-with-public-poc/ Mitre CVE https://www.cve.org/CVERecord?id=CVE-2026-20337 https://www.cve.org/CVERecord?id=CVE-2026-20338 https://www.cve.org/CVERecord?id=CVE-2026-20339 https://www.cve.org/CVERecord?id=CVE-2026-20345 https://www.cve.org/CVERecord?id=CVE-2026-20346 https://www.cve.org/CVERecord?id=CVE-2026-20347 https://www.cve.org/CVERecord?id=CVE-2026-20348 https://www.cve.org/CVERecord?id=CVE-2025-8088 GARR CERT Security Alert - subscribe/unsubscribe: https://www.cert.garr.it/alert/ricevi-gli-alert-di-cert -----BEGIN PGP SIGNATURE----- iF0EAREIAB0WIQTGpdiR5MqstacBGHbBnEyTZRJgQgUCanrgewAKCRDBnEyTZRJg QjgTAJ9fEDUjFwMXpadBUoc+PUGGLT9qggCfYTKGXLmXQbIffbrWWhMTsryq8+M= =xLq4 -----END PGP SIGNATURE-----