Description
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.

This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate as a result of a memory double-free, resulting in a DoS condition on the affected software.
Published: 2026-08-07
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A weakness in the zip archive parser of ClamAV causes a memory double‑free when a crafted zip file is processed during scanning. The resulting crash terminates the ClamAV scanning process, causing a denial of service that affects the entire scanning infrastructure of the host. An attacker can exploit this flaw remotely without authentication by submitting a malicious zip file to any endpoint that invokes the ClamAV engine.

Affected Systems

This vulnerability impacts Cisco Secure Endpoint products that embed the ClamAV engine for threat detection. The advisory does not specify which product or software versions are affected, so any installation that relies on the vulnerable ClamAV component is at risk until the vendor publishes a fix.

Risk and Exploitability

The CVSS base score of 7.5 indicates high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no public exploitation records at present. Nevertheless, the attack can be performed with remote, unauthenticated access, and a successful exploit will unconditionally bring down the scanning service, potentially exposing the system to further attacks or impairing security monitoring. Because the failure involves a double‑free, it is unlikely to provide privilege escalation or data exposure, but it does create an operational impact that could be critical in high‑security environments.

Generated by OpenCVE AI on August 7, 2026 at 17:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Cisco Secure Endpoint or ClamAV patch that addresses the double‑free issue.
  • If a patch is not yet available, restrict external network traffic to the ClamAV scanning API, especially from untrusted sources, or isolate the scanning service behind a firewall.
  • Maintain continuous log monitoring for abnormal process termination or crash events involving the ClamAV scanner, and set up alerts to notify administrators immediately.

Generated by OpenCVE AI on August 7, 2026 at 17:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate as a result of a memory double-free, resulting in a DoS condition on the affected software.
Title ClamAV ZIP File Format Processing Memory Corruption Vulnerability
Weaknesses CWE-415
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-07T18:12:13.836Z

Reserved: 2025-10-08T11:59:15.413Z

Link: CVE-2026-20338

cve-icon Vulnrichment

Updated: 2026-08-07T18:12:10.347Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T18:00:04Z

Weaknesses