/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-vwrj-64x7-jjw5

Published

Last updated

https://images.chainguard.dev/security/CGA-vwrj-64x7-jjw5
Package

clamav-1.3

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2025-20260
  • GHSA-596c-w2jc-jmmx

Severity

9.8

Critical

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-20260

Updates

Status

Fix not planned

Impact

1.3 is EOL upstream (expected support periods are documented at https://docs.clamav.net/faq/faq-eol.html#version-support-matrix). As per https://blog.clamav.net/2025/06/clamav-143-and-109-security-patch.html users should upgrade to clamav-1.4 to receive the fix

Status

Pending upstream fix

Impact

Upstream have introduced a fix in version 1.4.3 and 1.0.9. However, they are still working on introducing the fix into the main and other supported branches. It's expected that this CVE will be fixed once version 1.3.3 is tagged and released

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing