Denial of Service Vulnerability in ClamAV Zip Archive Parser
CVE-2026-20338
7.5HIGH
What is CVE-2026-20338?
A flaw in the zip archive parser of ClamAV allows remote, unauthenticated attackers to trigger a Denial of Service condition. This vulnerability arises from improper memory management during the processing of zip file contents, particularly when scanning. An attacker can exploit this flaw by submitting a specially crafted zip file, potentially leading to a memory double-free scenario. This can cause the ClamAV scanning engine to terminate unexpectedly, impacting the software's reliability and accessibility.
Affected Version(s)
Cisco Secure Endpoint 7.0.5
Cisco Secure Endpoint 6.2.19
Cisco Secure Endpoint 7.3.3