Bug#1143939: clamav: CVE-2026-20339 CVE-2026-20345 CVE-2026-20346 CVE-2026-20347 CVE-2026-20348

Moritz Mühlenhoff <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <andajfb666Hn9KRD__38551.0448993713$1786206917$gmane$org@pisco.westfalen.local>
Source: clamav
X-Debbugs-CC: [email protected]
Severity: grave
Tags: security

Hi,

The following vulnerabilities were published for clamav.

CVE-2026-20339[0]:
| A vulnerability in the PESpin file format parser of ClamAV could
| allow an unauthenticated, remote attacker to cause a DoS condition
| or possibly other expanded impacts as a result of&nbsp;memory
| corruption on an affected device.    This vulnerability is due to
| improper boundary checks for content in PESpin files during
| scanning, which may result in an integer overflow. An attacker could
| exploit this vulnerability by submitting a crafted file that
| contains PESpin content to be scanned by ClamAV on an affected
| device. A successful exploit could allow the attacker to cause the
| ClamAV scanning process to terminate, resulting in a DoS condition
| on the affected software.

CVE-2026-20345[1]:
| A vulnerability in the GPT file format parser of ClamAV could allow
| an unauthenticated, remote attacker to cause a DoS condition or
| possibly other expanded impacts as a result of&nbsp;memory
| corruption on an affected device.    This vulnerability is due to
| improper handling of an endian conversion operation, which may
| result in an out-of-bounds buffer write. An attacker could exploit
| this vulnerability by submitting a crafted GPT file to be scanned by
| ClamAV on an affected device. A successful exploit could allow the
| attacker to cause the ClamAV scanning process to terminate,
| resulting in a DoS condition on the affected software.

CVE-2026-20346[2]:
| A vulnerability in the PDF file format parser of ClamAV could allow
| an unauthenticated, remote attacker to cause a DoS condition or
| possibly other expanded impacts as a result of&nbsp;memory
| corruption on an affected device.    This vulnerability is due to
| improper boundary checks for content in PDF files during scanning,
| which may result in an out-of-bounds buffer read. An attacker could
| exploit this vulnerability by submitting a crafted PDF file to be
| scanned by ClamAV on an affected device. A successful exploit could
| allow the attacker to cause the ClamAV scanning process to
| terminate, resulting in a DoS condition on the affected software.

CVE-2026-20347[3]:
| A vulnerability in the Mach-O file format parser of ClamAV could
| allow an unauthenticated, remote attacker to cause a DoS condition
| or possibly other expanded impacts as a result of&nbsp;memory
| corruption on an affected device.    This vulnerability is due to
| improper boundary checks for content in Mach-O files during
| scanning, which may result in an out-of-bounds buffer read. An
| attacker could exploit this vulnerability by submitting a crafted
| Mach-O file to be scanned by ClamAV on an affected device. A
| successful exploit could allow the attacker to cause the ClamAV
| scanning process to terminate, resulting in a DoS condition on the
| affected software.

CVE-2026-20348[4]:
| A vulnerability in the XAR file format parser of ClamAV could allow
| an unauthenticated, remote attacker to cause a DoS condition or
| possibly other expanded impacts as a result of&nbsp;memory
| corruption on an affected device.    This vulnerability is due to
| improper boundary checks for content in XAR files during scanning.
| An attacker could exploit this vulnerability by submitting a crafted
| file that contains XAR content to be scanned by ClamAV on an
| affected device. A successful exploit could allow the attacker to
| cause the ClamAV scanning process to terminate, resulting in a DoS
| condition on the affected software.

https://blog.clamav.net/2026/08/clamav-154-and-146-security-patch.html


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-20339
    https://www.cve.org/CVERecord?id=CVE-2026-20339
[1] https://security-tracker.debian.org/tracker/CVE-2026-20345
    https://www.cve.org/CVERecord?id=CVE-2026-20345
[2] https://security-tracker.debian.org/tracker/CVE-2026-20346
    https://www.cve.org/CVERecord?id=CVE-2026-20346
[3] https://security-tracker.debian.org/tracker/CVE-2026-20347
    https://www.cve.org/CVERecord?id=CVE-2026-20347
[4] https://security-tracker.debian.org/tracker/CVE-2026-20348
    https://www.cve.org/CVERecord?id=CVE-2026-20348

Please adjust the affected versions in the BTS as needed.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.