Alpine: multiple clamav packages, multiple freshclam packages: security update to 1.4.6-r0

high Tenable Self-Hosted Container Security Plugin ID 445862

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute
arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was
discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET. (CVE-2025-8088)

- A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker
to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an
affected device. This vulnerability is due to improper boundary checks for content in PESpin files during
scanning, which may result in an integer overflow. An attacker could exploit this vulnerability by
submitting a crafted file that contains PESpin content to be scanned by ClamAV on an affected device. A
successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting
in a DoS condition on the affected software. (CVE-2026-20339)

- A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to
cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an
affected device. This vulnerability is due to improper handling of an endian conversion operation, which
may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a
crafted GPT file to be scanned by ClamAV on an affected device. A successful exploit could allow the
attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected
software. (CVE-2026-20345)

- A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to
cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an
affected device. This vulnerability is due to improper boundary checks for content in PDF files during
scanning, which may result in an out-of-bounds buffer read. An attacker could exploit this vulnerability
by submitting a crafted PDF file to be scanned by ClamAV on an affected device. A successful exploit could
allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the
affected software. (CVE-2026-20346)

Solution

Update the clamav library and its related packages to version 1.4.6-r0 or later.

See Also

https://security.alpinelinux.org/vuln/CVE-2025-8088

https://security.alpinelinux.org/vuln/CVE-2026-20339

https://security.alpinelinux.org/vuln/CVE-2026-20345

https://security.alpinelinux.org/vuln/CVE-2026-20346

https://security.alpinelinux.org/vuln/CVE-2026-20347

https://security.alpinelinux.org/vuln/CVE-2026-20348

Plugin Details

Severity: High

ID: 445862

Version: Revision 1.1

Type: Local

Published: 8/12/2026

Updated: 8/12/2026

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Critical

Score: 9.6

Percentile: 99.94

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-8088

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 8.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.4

Threat Score: 8.4

Threat Vector: CVSS:4.0/E:A

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 8/8/2025

CISA Known Exploited Vulnerability Due Dates: 9/2/2025

Reference Information

CVE: CVE-2025-8088, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, CVE-2026-20348