Integer overflow in ClamAV - CVE-2026-20215
Published: July 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer overflow in the 7z parser substream count handling when parsing a malformed archive. A remote attacker can provide a specially crafted archive to execute arbitrary code.
The issue can under-allocate parser metadata arrays and write past them while reading the archive.
Affected software
Secure Endpoint Connector for Mac
Secure Endpoint Connector for Linux
Secure Endpoint Connector for Windows
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Fedora
Basesystem Module
openSUSE Leap
Ubuntu
clamav
clamav (Ubuntu package)
libfreshclam4-debuginfo
clamav-docs-html
libclammspack0
libfreshclam4
clamav-debugsource
clamav-milter-debuginfo
clamav-milter
libclamav12-debuginfo
libclamav12
clamav-debuginfo
clamav-devel
libclammspack0-debuginfo
How to mitigate CVE-2026-20215
clamav - addressed in versions 1.4.6-1.el8, 1.4.6-1.el9, 1.4.6-1.el10_3, 1.4.6-1.fc43
clamav (Ubuntu package) - addressed in versions 1.5.3+dfsg-0ubuntu0.22.04.2, 1.5.3+dfsg-0ubuntu0.24.04.1, 1.5.3+dfsg-0ubuntu0.26.04.1
libfreshclam4-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-docs-html - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclammspack0 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libfreshclam4 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-debugsource - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-milter-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-milter - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclamav12-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclamav12 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-devel - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclammspack0-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
Secure Endpoint Connector for Mac - update to 1.27.2
Secure Endpoint Connector for Linux - update to 1.29.0
Secure Endpoint Connector for Windows - update to 8.6.2
External References
Related Security Bulletins
- Multiple vulnerabilities in ClamAV
- Cisco Secure Endpoint Connector update for ClamAV
- Ubuntu update for clamav
- SUSE update for clamav
- SUSE update for clamav
- SUSE update for clamav
- Fedora EPEL 8 update for clamav
- Fedora EPEL 9 update for clamav
- Fedora 43 update for clamav
- Fedora EPEL 10.3 update for clamav