Logo
vulnerabilityCVE-2026-20243
Name
CVE-2026-20243
Source
NVD ( link)Debian ( link)
Description
A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in ALZ files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains ALZ content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
clamav
Exploitable

Vulnerability Ratings#


7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.0.9
Not Affected
buildroot
master
1.5.4
Not Affected
openwrt
openwrt-25.12
1.4.3-r2
Exploitable