Ok, thanks. Didn't know that.
https://security-tracker.debian.org/tracker/CVE-2026-20337 and https://security-tracker.debian.org/tracker/CVE-2026-20338 are empty. Both are causing a DoS, so I would assume a fix should be important, though.
There seems to have been an update as the date has changed in this output, but the version number itself is still the old one.
# clamd --version
ClamAV 1.4.4/28111/Wed Sep 2 08:24:01 2026
Would be nice to get some information if ClamAV on PMG...
You are right,
I just checked the Debian package tracker and version 1.4.6 is indeed flagged as "A new upstream version is available... consider packaging it.":
https://tracker.debian.org/pkg/clamav
Seems the Debian maintainers haven't compiled...
clamav-freshclam only updates the dabases, not the program itself, and the package seems to be modified by Proxmox, hence the "+pmg1".
Also, https://packages.debian.org/trixie/clamav names 1.4.3+dfsg-1 as the version for trixie.
Version 1.4.6 of ClamAV has been released:
https://blog.clamav.net/2026/08/clamav-154-and-146-security-patch.html
Currently, PMG is running 1.4.4.
# dpkg -l clamav | grep ii
ii clamav 1.4.4+dfsg-1~deb13u1+pmg1 amd64 anti-virus...