https://blog.clamav.net/2026/03/clamav-152-and-144-security-patch.html
Hello.
I know these ports are currently without a maintainer.
However, they are apparently vulnerable, as a security release was published 9 days ago:
https://blog.clamav.net/2026/03/clamav-152-and-144-security-patch.html
Is anyone already working on this update?
bye & Thanks
av.
=20e > clamav and clamav-lts.
=20
On 3/13/26 17:07, Ronald Klop wrote:
=20
Started a test build in local Poudriere with a naive version bump of th=
s were already do=C3=ACng it :)Let's see what happens.=20
No promises.
=20
Did you already test the new versions?
No.
I was about to do what you did, but thought I'd ask before, in case other=
=20
bye & Thanks
av.
=20
=20
=20
=20
It builds but packaging fails. I don't have time this weekend to look into
this further.
@work
done
Kurt Jaeger (pi@freebsd.org) wrote on Pi Day 2026 09:39:53 +0100 (CET):
It builds but packaging fails. I don't have time this weekend to look into
this further.
@work
done
Kindly apply to clamav-lts as well (probably requires straight-forward update to 1.4.4). Thanks.
Kurt Jaeger (pi@freebsd.org) wrote on Pi Day 2026 09:39:53 +0100 (CET):
It builds but packaging fails. I don't have time this weekend to look into
this further.
@work
done
Kindly apply to clamav-lts as well (probably requires straight-forward update to 1.4.4). Thanks.
What's the reason for having 1.4.4 besides 1.5.2 ?
Is there really that much of a difference ?
What's the reason for having 1.4.4 besides 1.5.2 ?
Is there really that much of a difference ?
Vendor provides both feature (1.5.2) and LTS (1.4.4) releases. https://docs.clamav.net/faq/faq-eol.html
It appears we a refollowing suit: In our terms, the feature release is security/clamav (updated yesterday to 1.5.2) and the LTS release is security/clamav-lts (still at 1.4.3).
CVE-2026-20031 is fixed in both 1.5.2 and 1.4.4: https://blog.clamav.net/2026/03/clamav-152-and-144-security-patch.html
I have no opinion about keeping or dropping clamav-lts but since we have it I suggest to fix CVE-2026-20031 likewise, which means 1.4.3 -> 1.4.4.
Hi!
What's the reason for having 1.4.4 besides 1.5.2 ?
Is there really that much of a difference ?
Vendor provides both feature (1.5.2) and LTS (1.4.4) releases. https://docs.clamav.net/faq/faq-eol.html
It appears we a refollowing suit: In our terms, the feature release is security/clamav (updated yesterday to 1.5.2) and the LTS release is security/clamav-lts (still at 1.4.3).
CVE-2026-20031 is fixed in both 1.5.2 and 1.4.4: https://blog.clamav.net/2026/03/clamav-152-and-144-security-patch.html
I have no opinion about keeping or dropping clamav-lts but since we have it I suggest to fix CVE-2026-20031 likewise, which means 1.4.3 -> 1.4.4.
Done.
| Sysop: | Amessyroom |
|---|---|
| Location: | Fayetteville, NC |
| Users: | 65 |
| Nodes: | 6 (0 / 6) |
| Uptime: | 06:44:19 |
| Calls: | 862 |
| Files: | 1,311 |
| D/L today: |
921 files (14,318M bytes) |
| Messages: | 264,702 |