EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

USN-8788-1: ClamAV vulnerabilities

Official source
EudorIA operational summary

What it means

Priority 60/100

ClamAV, un'utilità antivirus per Unix, presenta diverse vulnerabilità che permettono a un attaccante remoto di causare un denial of service. Le vulnerabilità interessano file ZIP, PESpin, GPT, PDF, Mach-O e XAR. La patch è disponibile per diverse versioni di ClamAV. L'attacco non è sfruttato attivamente in rete.

Why it matters

Le vulnerabilità di ClamAV possono portare a un denial of service, compromettendo la protezione antivirus e la continuità operativa. Le PMI italiane dipendono spesso da ClamAV per la sicurezza dei loro sistemi, rendendo questa vulnerabilità particolarmente rilevante.

MITRE ATT&CKT1562 · Impair Defenses *
Brief generato da un modello locale EudorIA (qwen3:8b@workstation-gpu) a partire dal testo della fonte. Verificare sulla fonte prima di decisioni operative; le tecniche con * sono inferite dal modello. La fonte presenta informazioni parziali e non fornisce dettagli completi sull'attacco o sull'exploit noto.

Estratto della fonte usato dal modello

Your submission was sent successfully! Close Thank you for contacting us. A member of our team will be in touch shortly. Close You have successfully unsubscribed! Close Thank you for signing up for our newsletter! In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team. Close Your preferences have been successfully updated. Close notification Please try again or file a bug report. Close USN-8788-1: ClamAV vulnerabilities Several security issues were fixed in ClamAV. clamav - Anti-virus utility for Unix It was discovered that ClamAV incorrectly handled certain zip archive files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. ( CVE-2026-20337 , CVE-2026-20338 ) It was discovered that ClamAV incorrectly handled certain PESpin files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. ( CVE-2026-20339 ) It was discovered that ClamAV incorrectly handled certain GPT files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. ( CVE-2026-20345 ) It was discovered that ClamAV incorrectly handled certain PDF files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of... It was discovered that ClamAV incorrectly handled certain zip archive files. A remote attacker could possibly use this issue to cause ClamAV to

Potential operational benefits

  • Riduzione della superficie esposta a vulnerabilità note.
  • Miglioramento della resilienza contro attacchi di denial of service.
  • Aumento della conformità alle normative di sicurezza.
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementMonitoraggio / SIEMFirewall NGFW / IPSSegmentazione di rete
AudienceITSOC
Information centre

Translation in progress

Ubuntu Security

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

It was discovered that ClamAV incorrectly handled certain zip archive files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20337, CVE-2026-20338) It was discovered that ClamAV incorrectly handled certain PESpin files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20339) It was discovered that ClamAV incorrectly handled certain GPT files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20345) It was discovered that ClamAV incorrectly handled certain PDF files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20346) It was discovered that ClamAV incorrectly handled certain Mach-O files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20347) It was discovered that ClamAV incorrectly handled certain XAR files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20348)

Source
Ubuntu Security Notices
Publishing entity
Ubuntu Security
Entity type
vendor security
Area
Global
Original language
en · translation in preparation
Publication
21/09/2026 14:05
MITRE ATT&CK
T1562
CVE
CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, CVE-2026-20348
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source