Multiple ClamAV Vulnerabilities Lead to Denial of Service Risks

Multiple ClamAV Vulnerabilities Lead to Denial of Service Risks

First seen 8 Jul 2026, 17:25 UTC LinuxsecurityUbuntulaunchpad.netubuntu.com 84% similarity 70.5

Article Content

Browse articles
ThreatCluster

On July 1, 2026, several vulnerabilities affecting ClamAV were disclosed, including issues with PE files, 7z archives, and InstallShield files that could lead to denial of service (DoS) attacks. The vulnerabilities are identified as CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, and CVE-2026-20244. Affected systems include various Ubuntu and openSUSE versions running ClamAV. Attackers could exploit these vulnerabilities remotely, potentially causing crashes or excessive resource usage in the antivirus software. Users are advised to update their systems to mitigate these risks. The vulnerabilities have been confirmed and patches are available for various distributions. As of July 8, 2026, the situation remains critical for users who have not yet applied the updates.

Key Points: • ClamAV vulnerabilities could lead to denial of service attacks. • Seven CVEs were published on July 1, 2026, affecting multiple file types. • Users are urged to update their systems to prevent exploitation.

ThreatCluster AI

Timeline

2026-07-01
Multiple ClamAV vulnerabilities disclosed
Seven vulnerabilities were published, affecting PE files, 7z archives, and InstallShield files, leading to potential DoS attacks.
Ubuntu
2026-07-01
CVE-2026-20213 published
Out-of-bounds write vulnerability in PE files during scanning could lead to crashes.
Linuxsecurity
2026-07-01
CVE-2026-20214 published
Out-of-bounds write vulnerability in FSG files during scanning could lead to crashes.
Linuxsecurity
2026-07-01
CVE-2026-20215 published
Out-of-bounds write vulnerability in 7z files during scanning could lead to crashes.
Linuxsecurity
2026-07-01
CVE-2026-20216 published
Denial of service vulnerability due to improper handling of temporary resources during InstallShield file scanning.
Linuxsecurity
2026-07-01
CVE-2026-20217 published
Out-of-bounds write vulnerability in PESpin files during scanning could lead to crashes.
Linuxsecurity
2026-07-01
CVE-2026-20243 published
Out-of-bounds write vulnerability in ALZ files during scanning could lead to crashes.
Linuxsecurity
2026-07-01
CVE-2026-20244 published
Integer overflow and denial of service vulnerability in DMG files during scanning.
Linuxsecurity

Community

Browse all →