CVE-2026-20345: ClamAV GPT File Format Processing Memory Corruption Vulnerability
A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper handling of an endian conversion operation, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted GPT file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20345?
The severity of CVE-2026-20345 is rated as high with a score of 7.5.
How do I fix CVE-2026-20345?
To fix CVE-2026-20345, update ClamAV to the latest version that addresses the memory corruption vulnerability.
What impact does CVE-2026-20345 have on my system?
CVE-2026-20345 can potentially lead to a denial of service condition due to memory corruption on an affected device.
Who is affected by CVE-2026-20345?
Users of ClamAV who utilize the GPT file format parser are affected by CVE-2026-20345.
Can CVE-2026-20345 be exploited remotely?
Yes, CVE-2026-20345 can be exploited by an unauthenticated remote attacker.