CVE-2026-20347: ClamAV Mach-O File Format Processing Memory Corruption Vulnerability
A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in Mach-O files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit this vulnerability by submitting a crafted Mach-O file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20347?
CVE-2026-20347 has a high severity rating of 7.5.
How do I fix CVE-2026-20347?
Fix CVE-2026-20347 by updating to the latest version of ClamAV that addresses this vulnerability.
What type of attack can CVE-2026-20347 enable?
CVE-2026-20347 can enable an unauthenticated remote attacker to cause a Denial of Service (DoS) condition or potentially other impacts through memory corruption.
What software is affected by CVE-2026-20347?
CVE-2026-20347 affects the ClamAV software.
When was CVE-2026-20347 published?
CVE-2026-20347 was published on August 7, 2026.