Out-of-bounds write in ClamAV - CVE-2026-20345
Published: August 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to read or write beyond a stack-allocated partition entry.
The vulnerability exists due to out-of-bounds read and out-of-bounds write in GPT partition name conversion when parsing partition names. A remote attacker can provide a crafted GPT structure to read or write beyond a stack-allocated partition entry.