Back Linuxsecurity Ubuntu 26.04 ClamAV Important Denial Of Service Vulnerabilities USN-8517
Several security issues were fixed in ClamAV. Software Description: - clamav: Anti-virus utility for Unix Details: It was discovered that ClamAV incorrectly handled certain PE files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20213, CVE-2026-20214, CVE-2026-20217) It was discovered that ClamAV incorrectly handled certain 7z archive files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20215) It was discovered that ClamAV incorrectly handled extraction limits for certain InstallShield archives. A remote attacker could possibly use this issue to cause ClamAV to use excessive resources, leading to a denial of service. (CVE-2026-20216) It was discovered that ClamAV incorrectly handled certain ALZ archive files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20243) I... Read the Full Advisory
Several security issues were fixed in ClamAV.
Software Description:
- clamav: Anti-virus utility for Unix
It was discovered that ClamAV incorrectly handled certain PE files. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2026-20213, CVE-2026-20214,
It was discovered that ClamAV incorrectly handled certain 7z archive
files. A remote attacker could possibly use this issue to cause ClamAV to
crash, resulting in a denial of service. (CVE-2026-20215)
It was discovered that ClamAV incorrectly handled extraction limits for
certain InstallShield archives. A remote attacker could possibly use this
issue to cause ClamAV to use excessive resources, leading to a denial of
service. (CVE-2026-20216)
It was discovered that ClamAV incorrectly handled certain ALZ archive
files. A remote attacker could possibly use this issue to cause ClamAV to
crash, resulting in a denial of service. (CVE-2026-20243)
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS clamav 1.5.3+dfsg-0ubuntu0.26.04.1 Ubuntu 24.04 LTS clamav 1.5.3+dfsg-0ubuntu0.24.04.1 Ubuntu 22.04 LTS clamav 1.5.3+dfsg-0ubuntu0.22.04.2 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes.
CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216,
CVE-2026-20217, CVE-2026-20243, CVE-2026-20244
Ubuntu Security Notice USN-8517-1
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
