Integer underflow in ClamAV - CVE-2026-20214
Published: July 1, 2026
Vulnerability identifier: #VU136662
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20214
CWE-ID: CWE-191
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer underflow in the FSG unpacker loop when scanning a malformed PE file. A remote attacker can provide a specially crafted file to execute arbitrary code.
The issue can write past the section array.
Affected software
ClamAV
Secure Endpoint Connector for Mac
Secure Endpoint Connector for Linux
Secure Endpoint Connector for Windows
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Fedora
Basesystem Module
openSUSE Leap
Ubuntu
clamav
clamav (Ubuntu package)
libfreshclam4-debuginfo
clamav-docs-html
libclammspack0
libfreshclam4
clamav-debugsource
clamav-milter-debuginfo
clamav-milter
libclamav12-debuginfo
libclamav12
clamav-debuginfo
clamav-devel
libclammspack0-debuginfo
Secure Endpoint Connector for Mac
Secure Endpoint Connector for Linux
Secure Endpoint Connector for Windows
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Fedora
Basesystem Module
openSUSE Leap
Ubuntu
clamav
clamav (Ubuntu package)
libfreshclam4-debuginfo
clamav-docs-html
libclammspack0
libfreshclam4
clamav-debugsource
clamav-milter-debuginfo
clamav-milter
libclamav12-debuginfo
libclamav12
clamav-debuginfo
clamav-devel
libclammspack0-debuginfo
How to mitigate CVE-2026-20214
Install security update from vendor's website.
ClamAV - addressed in versions 1.4.5, 1.5.3
clamav - addressed in versions 1.4.6-1.el8, 1.4.6-1.el9, 1.4.6-1.el10_3, 1.4.6-1.fc43
clamav (Ubuntu package) - addressed in versions 1.5.3+dfsg-0ubuntu0.22.04.2, 1.5.3+dfsg-0ubuntu0.24.04.1, 1.5.3+dfsg-0ubuntu0.26.04.1
libfreshclam4-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-docs-html - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclammspack0 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libfreshclam4 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-debugsource - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-milter-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-milter - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclamav12-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclamav12 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-devel - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclammspack0-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
Secure Endpoint Connector for Mac - update to 1.27.2
Secure Endpoint Connector for Linux - update to 1.29.0
Secure Endpoint Connector for Windows - update to 8.6.2
clamav - addressed in versions 1.4.6-1.el8, 1.4.6-1.el9, 1.4.6-1.el10_3, 1.4.6-1.fc43
clamav (Ubuntu package) - addressed in versions 1.5.3+dfsg-0ubuntu0.22.04.2, 1.5.3+dfsg-0ubuntu0.24.04.1, 1.5.3+dfsg-0ubuntu0.26.04.1
libfreshclam4-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-docs-html - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclammspack0 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libfreshclam4 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-debugsource - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-milter-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-milter - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclamav12-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclamav12 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-devel - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclammspack0-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
Secure Endpoint Connector for Mac - update to 1.27.2
Secure Endpoint Connector for Linux - update to 1.29.0
Secure Endpoint Connector for Windows - update to 8.6.2
External References
Related Security Bulletins
- Multiple vulnerabilities in ClamAV
- Cisco Secure Endpoint Connector update for ClamAV
- Ubuntu update for clamav
- SUSE update for clamav
- SUSE update for clamav
- SUSE update for clamav
- Fedora EPEL 8 update for clamav
- Fedora EPEL 9 update for clamav
- Fedora 43 update for clamav
- Fedora EPEL 10.3 update for clamav