{"id":"AZL-95456","summary":"CVE-2026-20337 affecting package clamav 1.5.3-1","details":"A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.\r\n\r\nThis vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.","modified":"2026-08-30T05:26:50Z","published":"2026-08-07T17:17:02Z","upstream":["CVE-2026-20337"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20337"}],"affected":[{"package":{"name":"clamav","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/clamav"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.5.3-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95456.json"}}],"schema_version":"1.9.0"}