{"id":"AZL-95441","summary":"CVE-2026-20348 affecting package clamav 1.5.3-1","details":"A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device.\r\n\r\nThis vulnerability is due to improper boundary checks for content in XAR files during scanning. An attacker could exploit this vulnerability by submitting a crafted file that contains XAR content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.","modified":"2026-08-31T05:26:27Z","published":"2026-08-07T17:17:03Z","upstream":["CVE-2026-20348"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20348"}],"affected":[{"package":{"name":"clamav","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/clamav"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.5.3-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95441.json"}}],"schema_version":"1.9.0"}