{"id":"AZL-95447","summary":"CVE-2026-20347 affecting package clamav 1.5.3-1","details":"A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device.\r\n\r\nThis vulnerability is due to improper boundary checks for content in Mach-O files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit this vulnerability by submitting a crafted Mach-O file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.","modified":"2026-08-31T05:26:27Z","published":"2026-08-07T17:17:03Z","upstream":["CVE-2026-20347"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20347"}],"affected":[{"package":{"name":"clamav","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/clamav"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.5.3-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95447.json"}}],"schema_version":"1.9.0"}