Description
A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.

This vulnerability is due to improper handling of an endian conversion operation, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted GPT file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Published: 2026-08-07
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in ClamAV’s GPT file format parser allows an attacker to trigger an out‑of‑bounds buffer write during an endian conversion operation. The resulting memory corruption can terminate the ClamAV scanning process, producing a denial‑of‑service condition on the affected device.

Affected Systems

Cisco Secure Endpoint devices that use ClamAV for malware scanning are impacted. No specific vulnerable ClamAV or Cisco Secure Endpoint version numbers are identified in the advisory, so all devices that incorporate the built‑in ClamAV component may be exposed.

Risk and Exploitability

The CVSS score of 7.5 signals high severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. It can be exploited remotely by any unauthenticated user who can provide a malicious GPT file to the scanner. Successful exploitation results in the ClamAV process terminating and a temporary denial of service.

Generated by OpenCVE AI on August 7, 2026 at 18:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Cisco Secure Endpoint to the latest release that contains the ClamAV GPT parser fix, or apply the vendor‑provided patch if available.
  • If a patch cannot be applied immediately, restrict the file types that the ClamAV engine accepts and consider disabling GPT file scanning if it is not essential.
  • Continuously monitor ClamAV logs and system stability for abrupt crashes or repeated scan failures, and investigate any suspicious GPT file uploads.

Generated by OpenCVE AI on August 7, 2026 at 18:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper handling of an endian conversion operation, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted GPT file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Title ClamAV GPT File Format Processing Memory Corruption Vulnerability
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-07T16:42:46.329Z

Reserved: 2025-10-08T11:59:15.413Z

Link: CVE-2026-20345

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T18:30:03Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow