/00 — boot sequence

Hello.

Article

ClamAV Vulnerability Patch: ZIP Parser DoS With Public PoCs

August 11, 2026•6 min read
ClamAV CVE-2026-20337 CVE-2026-20338 Antivirus Denial of Service

Introduction

Cisco shipped ClamAV vulnerability patches on August 7, 2026 with the 1.5.4 and 1.4.6 security releases. The update fixes eight CVEs plus several non-CVE defects, including two high-severity flaws in the ZIP archive parser, CVE-2026-20337 and CVE-2026-20338, that let an unauthenticated remote attacker crash the scanning process. Cisco's PSIRT confirmed that proof-of-concept exploit code is publicly available, so teams running ClamAV 1.5.0 through 1.5.3 should plan an upgrade this week.

ClamAV is the open-source antivirus engine used by mail gateways, file upload services, Lambda-style scanning functions, and countless Docker images. A crash in the scanner does not give an attacker code execution, but it quietly removes malware detection from the pipeline. For email filtering and user-file scanning workloads, that is a real gap.

Vulnerability Details

Both flaws live in the ZIP archive parser that runs while ClamAV indexes the contents of a compressed archive.

CVE-2026-20337 is an out-of-bounds write caused by improper boundary checks. The ClamAV project describes the root cause as ZIP catalogue capacity tracking that could write beyond a heap allocation while indexing local file headers. It carries a CVSS 3.1 score of 7.5 with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, and is classified under CWE-120 (buffer copy without checking size of input).

CVE-2026-20338 is an invalid free that results from improper memory handling. During scanning, the parser merges ZIP catalogue records and the ownership handling of those records can trigger a double-free. It also scores 7.5 with the same network vector, and maps to CWE-415 (double free).

Both issues require nothing more than a crafted ZIP file submitted for scanning. No authentication, no user interaction, low attack complexity, and the impact is a terminated ClamAV process.

CVEFlawRoot CauseCVSSScope
CVE-2026-20337Out-of-bounds writeZIP catalogue capacity tracking7.5ClamAV 1.5.0 to 1.5.3
CVE-2026-20338Double freeZIP catalogue record ownership7.5ClamAV 1.5.0 to 1.5.3

The Rest of the Patch Release

The 1.5.4 and 1.4.6 releases also fixed six more CVEs, several of which go back much further:

  • CVE-2026-20345: an indexing error while converting GPT partition names could read or write beyond a stack-allocated partition entry. Affects 0.98.2 through 1.5.3.
  • CVE-2026-20339: an integer overflow in the PESpin unpacker could allocate an undersized buffer and write past it while rebuilding a PE file. Affects 0.90 through 1.5.3.
  • CVE-2026-20346: an integer underflow in the PDF parser could crash the scanner on a malformed hex string. Affects 1.4.5 and earlier plus 1.5.0 through 1.5.3.
  • CVE-2026-20347: undefined behavior and integer overflow in the Mach-O parser. Same affected range as CVE-2026-20346.
  • CVE-2026-20348: XAR parser size handling could request an excessive allocation or exceed scan limits while decompressing a malformed table of contents. Affects 0.98.1 through 1.5.3.
  • CVE-2025-8088: the bundled UnRAR library now rejects path separators in NTFS alternate data stream names, preventing extraction outside ClamAV's temporary scan directory on Windows.

Beyond the CVEs, 1.5.4 fixes thread-safety issues in the clamd STATS command that could disclose process memory or crash the daemon when scans and STATS requests run concurrently. It also fixes an OpenSSL library-context leak in FIPS environments and upgrades the Rust crossbeam-epoch dependency to resolve RUSTSEC-2026-0204.

Impact Assessment

Cisco's advisory rates the security impact high for Windows platforms, because Windows runs the ClamAV scanning process in a privileged security context. The same crash on Linux and macOS deployments matters less from a privilege standpoint, but the scanning outage itself is service-wide regardless of OS.

The risk profile matters most for on-premises email gateways and user-upload scanning services, where an unauthenticated sender can submit attachments. In those deployments, a single crafted ZIP file can knock out malware detection until the scanner is restarted. For Docker-based ClamAV usage, note that the image may restart cleanly but repeated submissions can hold the scan pipeline down.

Cisco's PSIRT has no evidence the flaws have been exploited in the wild. The public PoC availability changes that calculus, and Cisco's record is worth remembering: CISA has tagged 95 Cisco vulnerabilities as actively exploited since November 2021.

Affected Systems

The two ZIP parser CVEs affect ClamAV versions 1.5.0, 1.5.1, 1.5.2, and 1.5.3. The fix landed in 1.5.4. The remaining CVEs also affect the 1.4.x branch and, in several cases, versions back to 0.90, so the 1.4.6 release matters for anyone still on the older line.

Cisco Secure Endpoint Connector for Windows, Linux, and Mac embeds ClamAV and is affected. The company says there are no workarounds for the two ZIP parser flaws, and plans to ship updated Secure Endpoint Connector builds later in August.

Mitigation and Patching

The fix is a version bump, not a config change. Upgrade to ClamAV 1.5.4, or 1.4.6 if you are on the 1.4 branch. Packages are available from the ClamAV downloads page, the GitHub releases page, and Docker Hub under clamav/clamav and clamav/clamav-debian.

bash

After upgrading, restart the scanning service so the new binary takes effect:

bash

If you rely on the Secure Endpoint Connector, watch for the August update from Cisco. In the meantime, treat submissions from untrusted sources with extra care, and check that your scan queue has a timeout and restart policy so a crashed worker does not stall the whole pipeline. Verify the running version with clamscan --version and confirm it reports 1.5.4 or 1.4.6.

Detection

There is no reliable signature that distinguishes a malicious ZIP from a legitimate one before scanning, since the flaw triggers on malformed archive structure. The practical detection signal is operational: a ClamAV process that keeps terminating on archive scans, or a clamd daemon that exits under load.

  • Monitor clamd health checks. A crash loop on the scanner is the primary indicator.
  • Watch for scanner exit codes and restart counts in your container orchestrator or systemd journal.
  • Keep an eye on scan queue depth. If submissions back up and the worker dies repeatedly, investigate the recent ZIP files in the queue.
  • For on-premises gateways, review firewall and mail logs for repeated submissions of archive attachments from the same sender.

Frequently Asked Questions

Does this ClamAV vulnerability affect Linux servers?

The crash affects all platforms, but Cisco rates the security impact high only on Windows because that is where the scanning process runs in a privileged security context. On Linux the service outage is the main concern.

How do I update ClamAV?

Upgrade to 1.5.4 (or 1.4.6 on the older branch) from the ClamAV downloads page, GitHub releases, or Docker Hub. Then restart the clamav-daemon service or redeploy the container.

Is ClamAV still worth using for malware scanning?

Yes. ClamAV remains the standard open-source engine for mail and file scanning, and the project ships fixes quickly. The August releases show an active maintenance process, with credits going to GitHub Security Lab researchers and independent reporters.

Do the ZIP parser bugs work on attachments sent through email?

An attacker needs to get a crafted ZIP file scanned. Email attachments are a plausible delivery path for any deployment that scans inbound mail, which is why the PoC availability matters for gateway operators.

Why did the 1.4.6 release include older fixes?

Several of the patched CVEs affect versions back to 0.90, and the project backported the fixes to both supported branches so long-tail deployments can move off vulnerable code in one step.

Key Takeaways

  • ClamAV 1.5.4 and 1.4.6 fix eight CVEs, including two high-severity ZIP parser flaws with public PoCs.
  • CVE-2026-20337 (out-of-bounds write) and CVE-2026-20338 (double free) are unauthenticated, network-reachable, and score 7.5.
  • No in-the-wild exploitation has been observed, but public PoC code changes the risk picture.
  • Windows deployments carry the higher security impact because the scanner runs privileged there.
  • Update to 1.5.4 or 1.4.6 and watch for the Secure Endpoint Connector update later this month.

Sources: BleepingComputer, ClamAV blog, GHSA-rhg3-hwfw-hp7p, GHSA-xw98-8fcm-j8x7, Cisco advisory

Automated Transmission

This entry was synthesized and populated dynamically using native API integrations.

Resources & Links