Denial of Service Vulnerabilities in ClamAV Affect Fedora 43 and 44

Denial of Service Vulnerabilities in ClamAV Affect Fedora 43 and 44

First seen 12 Aug 2026, 02:41 UTC Linuxsecurity 99% similarity 60.6

Article Content

Browse articles
ThreatCluster

Fedora has released patches addressing multiple Denial of Service vulnerabilities in ClamAV, affecting versions 1.4.5 and 1.4.6. The vulnerabilities include CVE-2026-20031, CVE-2026-20216, and CVE-2026-20215, which can be exploited via crafted files, leading to service disruptions. The issues were reported on August 10, 2026, and are linked to improper error handling in the software's CSS module and crafted InstallShield files. Users are advised to update their systems using the 'dnf' update program. The vulnerabilities primarily impact Linux systems running Fedora 43 and 44. Immediate action is recommended to mitigate potential service outages.

Key Points: • Multiple Denial of Service vulnerabilities in ClamAV affect Fedora 43 and 44. • Key CVEs include CVE-2026-20031 and CVE-2026-20216, which can disrupt services. • Users are urged to apply patches immediately using the 'dnf' update program.

ThreatCluster AI How this analysis works

Timeline

2026-03-04
CVE-2026-20031 published
CVE-2026-20031 details improper error handling in ClamAV's CSS module, leading to potential DoS.
Linuxsecurity
2026-07-01
CVE-2026-20215 published
CVE-2026-20215 describes a DoS vulnerability via crafted 7z files in ClamAV.
Linuxsecurity
2026-07-01
CVE-2026-20216 published
CVE-2026-20216 outlines a DoS vulnerability via crafted InstallShield files in ClamAV.
Linuxsecurity
2026-08-10
Patches released for Fedora 43 and 44
Fedora released updates to address the identified DoS vulnerabilities in ClamAV.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story