PT-2026-54709 · Clamav · Clamav

·

CVE-2026-20244

·

Published

2026-07-01

·

Updated

2026-07-09

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions ClamAV (affected versions not specified)
Description An issue exists in the DMG file format parser where improper boundary checks for content during scanning can lead to memory corruption. On 32-bit platforms, this specifically manifests as an integer overflow. A remote, unauthenticated attacker can exploit this by submitting a specially crafted DMG file, causing the scanning process to terminate and resulting in a Denial of Service (DoS) condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09218
CVE-2026-20244
OPENSUSE-SU-2026:11182-1
OPENSUSE-SU-2026:21252-1
SUSE-SU-2026:22574-1
SUSE-SU-2026:2833-1
SUSE-SU-2026:2834-1
SUSE-SU-2026:2835-1
USN-8517-1

Affected Products

Clamav