Description
A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.

This vulnerability is due to improper boundary checks for content in PDF files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Published: 2026-08-07
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in ClamAV’s PDF file parser, where improper boundary checks allow an attacker to craft a malicious PDF that triggers a buffer over‑read. This can cause the ClamAV scanning process to terminate or corrupt memory, resulting in a denial‑of‑service condition on the victim device. The problem is an out‑of‑bounds buffer read, identified as CWE‑125.

Affected Systems

The affected environment is Cisco Secure Endpoint, which incorporates ClamAV into its antivirus functionality. Specific product versions are not listed, so any instance of Cisco Secure Endpoint that contains the vulnerable ClamAV component may be affected.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity risk, while the EPSS metric is not available and there is no KEV listing, implying limited public exploit data. An attacker only needs to deliver a carefully crafted PDF to a system that runs the ClamAV scanner; no authentication is required. If successful, the attacker can crash the scanner, leading to a denial of service of the antivirus service and potentially affecting the overall security posture due to reduced protection.

Generated by OpenCVE AI on August 7, 2026 at 17:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Cisco Secure Endpoint to a version that includes a patched ClamAV implementation.
  • Disable PDF scanning in the ClamAV configuration if file‑scanning of PDFs is not required in your environment.
  • Monitor system logs for anomalous ClamAV crashes and test the patch in a staging environment before wide deployment.

Generated by OpenCVE AI on August 7, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PDF files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Title ClamAV PDF File Format Processing Memory Corruption Vulnerability
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-07T18:12:29.718Z

Reserved: 2025-10-08T11:59:15.413Z

Link: CVE-2026-20346

cve-icon Vulnrichment

Updated: 2026-08-07T18:12:26.382Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T17:30:16Z

Weaknesses