ClamAV Parsers Carry Decades-Old Memory Risks

ClamAV’s file inspection code is part of the attack surface. A crafted archive, executable, or DMG can trip a parser bug during scanning and crash the scanner or corrupt memory, so gateways and endpoint tools that rely on ClamAV inherit risk from the security control itself. Cisco shipped ClamAV 1.5.3 and 1.4.5 to fix seven parser flaws: CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, and CVE-2026-20244. The bugs sit in packer, archive, and DMG code, and some traces back to 2004 and 2005. One fix also hardens quarantine handling against TOCTOU races in clamscan, clamdscan, and clamonacc.

Part of the PlainSec briefing for 2026-07-06

Sources