Hi,

today I moved my clamav-milter and clamd installation (linux container) to a 
brand new hardware.
Know I get this strange errors in the log any 3-5 minutes.

...
Oct 28 13:37:00 mil1 clamav-milter[23926]: clamfi_eom: FD send failed: Broken 
pipe
Oct 28 13:37:00 mil1 clamav-milter[23926]: FD send failed
Oct 28 13:37:05 mil1 clamav-milter[23926]: clamfi_eom: FD send failed: Broken 
pipe
Oct 28 13:37:05 mil1 clamav-milter[23926]: FD send failed
...

But I get also that viruses where found:
...
Oct 28 13:49:59 mil2 clamav-milter[27477]: Message from <ret...@domain.com> to 
<recipi...@domain.com> infected by Sanesecurity.Jurlbl.1686.UNOFFICIAL
Oct 28 13:50:57 mil2 clamav-milter[27477]: clamfi_eom: FD send failed: Broken 
pipe
Oct 28 13:50:57 mil2 clamav-milter[27477]: FD send failed
Oct 28 13:51:10 mil2 clamav-milter[27477]: Message from <retu...@domain.com> to 
<recipi...@domain.com> infected by Sanesecurity.Jurlbl.1999.UNOFFICIAL
Oct 28 13:52:55 mil2 clamav-milter[27477]: clamfi_eom: FD send failed: Broken 
pipe
Oct 28 13:52:55 mil2 clamav-milter[27477]: FD send failed
Oct 28 13:54:36 mil2 clamav-milter[27477]: Message from <sen...@domain.com> to 
<recipient@domain> infected by Sanesecurity.Junk.39029.UNOFFICIAL
...

It's very strange to me, that the error above came up first after starting the 
container on the new hardware.
The only thing that has been changes is kernel version and Host OS.

Old system:
Debian: Squeeze
Kernel: 3.2.17-vs2.3.2.9-rol-em64t

New system:
Debian: Jessie
Kernel: 3.18.21-vs2.3.7.4-rol-em64t-efigpt

ClamAV versions installed on the linux container (based on linux-vserver - 
http://linux-vserver.org):
ii clamav 0.98.7+dfsg-0+deb8u1 amd64 anti-virus utility for Unix - command-line 
interface
ii clamav-base 0.98.7+dfsg-0+deb8u1 all anti-virus utility for Unix - base 
package
ii clamav-daemon 0.98.7+dfsg-0+deb8u1 amd64 anti-virus utility for Unix - 
scanner daemon
ii clamav-freshclam 0.98.7+dfsg-0+deb8u1 amd64 anti-virus utility for Unix - 
virus database update utility
ii clamav-milter 0.98.7+dfsg-0+deb8u1 amd64 anti-virus utility for Unix - 
sendmail integration
ii clamdscan 0.98.7+dfsg-0+deb8u1 amd64 anti-virus utility for Unix - scanner 
client
ii libclamav6 0.98.7+dfsg-0+deb8u1 amd64 anti-virus utility for Unix - library

Clamav-milter and clamd temporary directories are located in different 
ram-disks.


Could it be that the errors are kernel related?

Many thanks
Urban Loesch
_______________________________________________
Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq

http://www.clamav.net/contact.html#ml

Reply via email to