Description
A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.

This vulnerability is due to improper boundary checks for content in Mach-O files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit this vulnerability by submitting a crafted Mach-O file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Published: 2026-08-07
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Mach‑O file format parser of ClamAV can lead to a denial‑of‑service condition when a crafted Mach‑O file is scanned. The vulnerability stems from missing boundary checks that cause an out‑of‑bounds memory read (CWE‑125). An attacker who can supply a malicious file to the ClamAV scanning process can trigger the crash, terminating the service and making the affected system unavailable for legitimate scans.

Affected Systems

The vulnerability affects devices running Cisco Secure Endpoint that include the ClamAV engine. Specific version information is not provided in the advisory, but the issue is present in all versions of the included ClamAV library that lack the patch.

Risk and Exploitability

The CVSS score is 7.5, indicating a high severity threat. The EPSS score is not available, but the fact that the problem is unauthenticated and remote means an attacker could potentially exploit it from the network. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to deliver a crafted Mach‑O file to the machine; no additional prerequisites or privileged access are required beyond the ability to submit a file for scanning.

Generated by OpenCVE AI on August 7, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Cisco Secure Endpoint update that addresses the ClamAV boundary‑check flaw.
  • If a new patch is not yet available, consider disabling or blocking Mach‑O file scanning on the affected system until remedial software is released.
  • Monitor ClamAV logs for abnormal termination events and ensure that only trusted or signed files are queued for scanning.
  • Review and tighten permission settings on directories that receive user‑supplied files to reduce the likelihood that an attacker can inject malicious Mach‑O files.

Generated by OpenCVE AI on August 7, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in Mach-O files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit this vulnerability by submitting a crafted Mach-O file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Title ClamAV Mach-O File Format Processing Memory Corruption Vulnerability
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-07T16:42:29.284Z

Reserved: 2025-10-08T11:59:15.413Z

Link: CVE-2026-20347

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T17:30:16Z

Weaknesses