Logo
vulnerabilityCVE-2026-20215
Name
CVE-2026-20215
Source
NVD ( link)Debian ( link)
Description
A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in 7z files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains 7z content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
clamav
Exploitable

Vulnerability Ratings#


7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
1.5.4
Not Affected
openwrt
master
1.4.3-r2
Exploitable
openwrt
openwrt-25.12
1.4.3-r2
Exploitable