{"id":"AZL-95444","summary":"CVE-2026-20345 affecting package clamav 1.5.3-1","details":"A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device.\r\n\r\nThis vulnerability is due to improper handling of an endian conversion operation, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted GPT file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.","modified":"2026-08-31T05:26:27Z","published":"2026-08-07T17:17:03Z","upstream":["CVE-2026-20345"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20345"}],"affected":[{"package":{"name":"clamav","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/clamav"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.5.3-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95444.json"}}],"schema_version":"1.9.0"}