Vulnerabilities · 71 days ago

ClamAV Parsers Carry Decades-Old Memory Risks

ClamAV’s file inspection code is part of the attack surface. A crafted archive, executable, or DMG can trip a parser bug during scanning and crash the scanner or corrupt memory, so gateways and endpoint tools that rely on ClamAV inherit risk from the security control itself.

Cisco shipped ClamAV 1.5.3 and 1.4.5 to fix seven parser flaws: CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, and CVE-2026-20244. The bugs sit in packer, archive, and DMG code, and some traces back to 2004 and 2005. One fix also hardens quarantine handling against TOCTOU races in clamscan, clamdscan, and clamonacc.

CVEs in this update

7 CVEs

Across azl3 clamav 1.5.2-3 on Azure Linux 3.0.

0 critical · 7 high · 0 medium · 0 low

0 in CISA KEV · 0 with EPSS above 1%

Highest severity: CVE-2026-20213 · 7.5 HIGH

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-07-06

Editions

Related stories