CVE-2026-20346: ClamAV PDF File Format Processing Memory Corruption Vulnerability
A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PDF files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20346?
The severity of CVE-2026-20346 is rated high with a score of 7.5.
How do I fix CVE-2026-20346?
To fix CVE-2026-20346, ensure that you update ClamAV to the latest version where the vulnerability has been addressed.
What impact does CVE-2026-20346 have on my system?
CVE-2026-20346 can lead to a denial of service condition or memory corruption that may allow further impacts on affected devices.
Who can exploit CVE-2026-20346?
CVE-2026-20346 can be exploited by an unauthenticated, remote attacker.
What type of software does CVE-2026-20346 affect?
CVE-2026-20346 affects ClamAV, specifically its PDF file format parser.