ClamAV GPT Parser OOB Buffer Write leading to DoS
CVE-2026-20345 Published on August 7, 2026
ClamAV GPT File Format Processing Memory Corruption Vulnerability
A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device.
This vulnerability is due to improper handling of an endian conversion operation, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted GPT file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Vulnerability Analysis
CVE-2026-20345 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Type
What is a Stack Overflow Vulnerability?
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CVE-2026-20345 has been classified to as a Stack Overflow vulnerability or weakness.
Products Associated with CVE-2026-20345
Want to know whenever a new CVE is published for Cisco Secure Endpoint? stack.watch will email you.
Affected Versions
Cisco Secure Endpoint:- Version 1.12.3 is affected.
- Version 1.8.0 is affected.
- Version 1.11.1 is affected.
- Version 1.12.4 is affected.
- Version 1.10.0 is affected.
- Version 1.12.0 is affected.
- Version 1.8.1 is affected.
- Version 1.10.1 is affected.
- Version 1.10.2 is affected.
- Version 1.12.2 is affected.
- Version 1.6.0 is affected.
- Version 1.9.0 is affected.
- Version 1.7.0 is affected.
- Version 1.12.1 is affected.
- Version 1.12.6 is affected.
- Version 1.8.4 is affected.
- Version 1.11.0 is affected.
- Version 1.9.1 is affected.
- Version 1.12.5 is affected.
- Version 2.0.2 is affected.
- Version 1.1.0 is affected.
- Version 1.14.0 is affected.
- Version 2.4.0 is affected.
- Version 1.15.2 is affected.
- Version 1.16.0 is affected.
- Version 1.21.0 is affected.
- Version 1.22.2 is affected.
- Version 1.24.5 is affected.
- Version 1.19.0 is affected.