Release of invalid pointer or reference in ClamAV - CVE-2026-20217
Published: July 1, 2026
Vulnerability identifier: #VU136659
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20217
CWE-ID: CWE-763
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to invalid pointer free in the PESpin unpacker cleanup path when scanning a crafted PE file. A remote attacker can provide a specially crafted file to cause a denial of service.
Affected software
ClamAV
Secure Endpoint Connector for Mac
Secure Endpoint Connector for Linux
Secure Endpoint Connector for Windows
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Fedora
Basesystem Module
openSUSE Leap
Ubuntu
clamav
clamav (Ubuntu package)
libfreshclam4-debuginfo
clamav-docs-html
libclammspack0
libfreshclam4
clamav-debugsource
clamav-milter-debuginfo
clamav-milter
libclamav12-debuginfo
libclamav12
clamav-debuginfo
clamav-devel
libclammspack0-debuginfo
Secure Endpoint Connector for Mac
Secure Endpoint Connector for Linux
Secure Endpoint Connector for Windows
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Fedora
Basesystem Module
openSUSE Leap
Ubuntu
clamav
clamav (Ubuntu package)
libfreshclam4-debuginfo
clamav-docs-html
libclammspack0
libfreshclam4
clamav-debugsource
clamav-milter-debuginfo
clamav-milter
libclamav12-debuginfo
libclamav12
clamav-debuginfo
clamav-devel
libclammspack0-debuginfo
How to mitigate CVE-2026-20217
Install security update from vendor's website.
ClamAV - addressed in versions 1.4.5, 1.5.3
clamav - addressed in versions 1.4.6-1.el8, 1.4.6-1.el9, 1.4.6-1.el10_3, 1.4.6-1.fc43
clamav (Ubuntu package) - addressed in versions 1.5.3+dfsg-0ubuntu0.22.04.2, 1.5.3+dfsg-0ubuntu0.24.04.1, 1.5.3+dfsg-0ubuntu0.26.04.1
libfreshclam4-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-docs-html - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclammspack0 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libfreshclam4 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-debugsource - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-milter-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-milter - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclamav12-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclamav12 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-devel - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclammspack0-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
Secure Endpoint Connector for Mac - update to 1.27.2
Secure Endpoint Connector for Linux - update to 1.29.0
Secure Endpoint Connector for Windows - update to 8.6.2
clamav - addressed in versions 1.4.6-1.el8, 1.4.6-1.el9, 1.4.6-1.el10_3, 1.4.6-1.fc43
clamav (Ubuntu package) - addressed in versions 1.5.3+dfsg-0ubuntu0.22.04.2, 1.5.3+dfsg-0ubuntu0.24.04.1, 1.5.3+dfsg-0ubuntu0.26.04.1
libfreshclam4-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-docs-html - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclammspack0 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libfreshclam4 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-debugsource - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-milter-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-milter - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclamav12-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclamav12 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-devel - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclammspack0-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
Secure Endpoint Connector for Mac - update to 1.27.2
Secure Endpoint Connector for Linux - update to 1.29.0
Secure Endpoint Connector for Windows - update to 8.6.2
External References
Related Security Bulletins
- Multiple vulnerabilities in ClamAV
- Cisco Secure Endpoint Connector update for ClamAV
- Ubuntu update for clamav
- SUSE update for clamav
- SUSE update for clamav
- SUSE update for clamav
- Fedora EPEL 8 update for clamav
- Fedora EPEL 9 update for clamav
- Fedora 43 update for clamav
- Fedora EPEL 10.3 update for clamav