ClamAV 1.5.4
ClamAV 1.5.4 is a patch release with the following fixes: CVE-2026-20337: Fixed ZIP catalogue capacity tracking that could write beyond a heap allocation while indexing local file headers. This issue affects ClamAV 1.5.0 through 1.5.3. The fix is included in 1.5.4. Thank you to Kevin Stubbings of the GitHub Security Lab team for identifying this issue. CVE-2026-20345: Fixed an indexing error while…