Out-of-bounds read in ClamAV - CVE-2025-20234

 

Out-of-bounds read in ClamAV - CVE-2025-20234

Published: June 18, 2025


Vulnerability identifier: #VU111271
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20234
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to perform a denial of service attack.

The vulnerability exists due to a boundary condition when handling UDF files. A remote attacker can pass a specially crafted UDF file to the application, trigger an out-of-bounds read error and read contents of memory on the system or perform a denial of service (DoS) attack.


Affected software

ClamAV
Secure Endpoint Connector for Mac
Secure Endpoint Connector for Linux
Secure Endpoint Private Cloud
Secure Endpoint Connector for Windows
Fedora
Ubuntu
RSA Authentication Manager
clamav
clamav (Ubuntu package)
squidclamav

How to mitigate CVE-2025-20234

Install updates from vendor's website.

ClamAV - update to 1.4.3
RSA Authentication Manager - update to 8.8 Patch 2
clamav - addressed in versions 1.0.9-1.el8, 1.0.9-1.el9, 1.0.9-1.fc41, 1.4.3-1.el10_1
clamav (Ubuntu package) - addressed in versions 1.4.3+dfsg-0ubuntu0.20.04.1+esm1, 1.4.3+dfsg-0ubuntu0.22.04.1, 1.4.3+dfsg-0ubuntu0.24.04.1, 1.4.3+dfsg-0ubuntu0.24.10.1, 1.4.3+dfsg-0ubuntu0.25.04.1
Secure Endpoint Connector for Mac - update to 1.26.1
Secure Endpoint Connector for Linux - update to 1.26.1
Secure Endpoint Private Cloud - update to 4.2.2
squidclamav - addressed in versions 7.5-1.el8, 7.5-1.el9
Secure Endpoint Connector for Windows - addressed in versions 7.5.21, 8.4.5

External References

Related Security Bulletins