USN-8788-1: ClamAV vulnerabilities
ClamAV contains multiple denial-of-service vulnerabilities allowing remote crashes via crafted archive and document files.
Ubuntu Security Notice USN-8788-1 addresses multiple denial-of-service vulnerabilities in the ClamAV antivirus engine. The flaws (CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345) are triggered by improper handling of certain zip, PESpin, GPT, and PDF files, allowing remote attackers to crash the service. The vulnerabilities affect ClamAV versions prior to the patched release.
- Multiple denial-of-service vulnerabilities in ClamAV archive handling.
- Remote attackers can crash ClamAV by sending crafted zip, PESpin, GPT, or PDF files.
- Patches available in Ubuntu security update USN-8788-1.
Vulnerabilities mentionedAll →
- CVE-2026-203377.5<1%A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected devicepublished +1 related
- CVE-2026-203397.5<1%A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded…
It was discovered that ClamAV incorrectly handled certain zip archive files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20337, CVE-2026-20338) It was discovered that ClamAV incorrectly handled certain PESpin files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20339) It was discovered that ClamAV incorrectly handled certain GPT files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20345) It was discovered that ClamAV incorrectly handled certain PDF files. A remote attacker…
This source does not provide full text. Read it at ubuntu.com.