Skip to content
Multiple ClamAV Vulnerabilities Lead to Denial of Service Risks

Multiple ClamAV Vulnerabilities Lead to Denial of Service Risks

First seen 8 Jul 2026, 17:25 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •July 9, 2026 at 14:42 UTC
  • •ClamAV vulnerabilities could lead to denial of service attacks.
  • •Seven CVEs were published on July 1, 2026, affecting multiple file types.
  • •Users are urged to update their systems to prevent exploitation.

On July 1, 2026, several vulnerabilities affecting ClamAV were disclosed, including issues with PE files, 7z archives, and InstallShield files that could lead to denial of service (DoS) attacks. The vulnerabilities are identified as CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, and CVE-2026-20244. Affected systems include various Ubuntu and openSUSE versions running ClamAV. Attackers could exploit these vulnerabilities remotely, potentially causing crashes or excessive resource usage in the antivirus software. Users are advised to update their systems to mitigate these risks. The vulnerabilities have been confirmed and patches are available for various distributions. As of July 8, 2026, the situation remains critical for users who have not yet applied the updates.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2026-07-01
Multiple ClamAV vulnerabilities disclosed
Seven vulnerabilities were published, affecting PE files, 7z archives, and InstallShield files, leading to potential DoS attacks.
Ubuntu
2026-07-01
CVE-2026-20213 published
Out-of-bounds write vulnerability in PE files during scanning could lead to crashes.
Linuxsecurity
2026-07-01
CVE-2026-20214 published
Out-of-bounds write vulnerability in FSG files during scanning could lead to crashes.
Linuxsecurity
2026-07-01
CVE-2026-20215 published
Out-of-bounds write vulnerability in 7z files during scanning could lead to crashes.
Linuxsecurity
2026-07-01
CVE-2026-20216 published
Denial of service vulnerability due to improper handling of temporary resources during InstallShield file scanning.
Linuxsecurity
2026-07-01
CVE-2026-20217 published
Out-of-bounds write vulnerability in PESpin files during scanning could lead to crashes.
Linuxsecurity
2026-07-01
CVE-2026-20243 published
Out-of-bounds write vulnerability in ALZ files during scanning could lead to crashes.
Linuxsecurity
2026-07-01
CVE-2026-20244 published
Integer overflow and denial of service vulnerability in DMG files during scanning.
Linuxsecurity

More articles in this cluster (10)

Following this threat?

Track Ubuntu and CVE-2026-20213 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed