Input validation error in ClamAV - CVE-2026-20244

 

Input validation error in ClamAV - CVE-2026-20244

Published: July 1, 2026


Vulnerability identifier: #VU136665
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20244
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper size checks in the DMG parser when parsing a crafted DMG file on 32-bit builds. A remote attacker can provide a specially crafted file to cause a denial of service.

Only 32-bit scanner builds are affected.


Affected software

ClamAV
Secure Endpoint Connector for Mac
Secure Endpoint Connector for Linux
Secure Endpoint Connector for Windows
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Fedora
Basesystem Module
openSUSE Leap
Ubuntu
clamav
clamav (Ubuntu package)
libfreshclam4-debuginfo
clamav-docs-html
libclammspack0
libfreshclam4
clamav-debugsource
clamav-milter-debuginfo
clamav-milter
libclamav12-debuginfo
libclamav12
clamav-debuginfo
clamav-devel
libclammspack0-debuginfo

How to mitigate CVE-2026-20244

Install security update from vendor's website.

ClamAV - addressed in versions 1.4.5, 1.5.3
clamav - addressed in versions 1.4.6-1.el8, 1.4.6-1.el9, 1.4.6-1.el10_3, 1.4.6-1.fc43
clamav (Ubuntu package) - addressed in versions 1.5.3+dfsg-0ubuntu0.22.04.2, 1.5.3+dfsg-0ubuntu0.24.04.1, 1.5.3+dfsg-0ubuntu0.26.04.1
libfreshclam4-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-docs-html - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclammspack0 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libfreshclam4 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-debugsource - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-milter-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-milter - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclamav12-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclamav12 - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
clamav-devel - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
libclammspack0-debuginfo - addressed in versions 1.5.3-3.56.1, 1.5.3-150400.13.8.1, 1.5.3-150600.18.28.1
Secure Endpoint Connector for Mac - update to 1.27.2
Secure Endpoint Connector for Linux - update to 1.29.0
Secure Endpoint Connector for Windows - update to 8.6.2

External References

Related Security Bulletins