The ClamAV project reports:
- CVE-2026-20345: indexing error while converting GPT partition
names could read or write beyond a stack-allocated partition
entry.
- CVE-2026-20339: integer overflow in the PESpin unpacker could
allocate an undersized buffer and write beyond it.
- CVE-2026-20346: integer underflow in the PDF parser could
cause a crash while reading a malformed hex string.
- CVE-2026-20347: undefined behavior and integer overflow in
the Mach-O parser could cause a crash on a malformed
file.
- CVE-2026-20348: XAR parser size handling could request an
excessive allocation or exceed scan limits.
- CVE-2025-8088: path separators in NTFS alternate data stream
names in the bundled UnRAR library could lead to extraction
outside the temporary scan directory.
- CVE-2026-20217: PESpin unpacker cleanup path could free
pointers into the scanned file buffer and crash the
scanner.
- CVE-2026-20213: integer overflow in PE rebuild size
calculations could lead to a heap buffer overflow write.
- CVE-2026-20216: InstallShield archive extraction limit bypass
could exhaust temporary storage.
- CVE-2026-20214: FSG unpacker loop underflow could write past
the section array.
- CVE-2026-20243: ALZ parser size handling bugs could abort the
scanner.
- CVE-2026-20215: 7z parser substream count overflow could
write past under-allocated metadata arrays.
- CVE-2026-20244: 32-bit DMG parser size checks could crash
32-bit scanner builds.
- Thread-safety issues in the clamd STATS command could
disclose process memory or crash the daemon.