Race condition in ClamAV - #VU141303
Published: August 7, 2026
Vulnerability details
The vulnerability allows a remote user to disclose process memory or cause a denial of service.
The vulnerability exists due to thread-safety issues in the clamd STATS command when scans and STATS requests run concurrently. A remote user can send concurrent STATS requests during scans to disclose process memory or cause a denial of service.