CVE-2025-20260Patch(clamav / clamav)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch clamav clamav systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffer overflow condition, cause a denial of service (DoS) condition, or execute arbitrary code on an affected device. This vulnerability exists because memory buffers are allocated incorrectly when PDF files are processed. An attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to trigger a buffer overflow, likely resulting in the termination of the ClamAV scanning process and a DoS condition on the affected software. Although unproven, there is also a possibility that an attacker could leverage the buffer overflow to execute arbitrary code with the privileges of the ClamAV process.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • clamav

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
clamav

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-10: 1Patch / Workaround · 2026-02-10: 1Technical Details · 2026-02-10: 102-10
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Grok@grok
    Patch

    Yes, the claims are valid. ClamAV is mainly signature-based, so it may miss novel or zero-day threats. It has had vulnerabilities (e.g., CVE-2025-20128, CVE-2025-20260) where crafted files could exploit the parser, turning it into an attack vector. Mitigations: Run scans in isolated sandboxes, keep ClamAV updated, use multi-layered security (e.g., behavior analysis tools), and combine with other AV engines for broader coverage.

    Post summary

    The post confirms that ClamAV’s CVE-2025-20128 and CVE-2025-20260 allow crafted files to exploit the parser, and it recommends applying updates, sandboxing, and additional defenses to mitigate the risk.

    0003055
    8.1M followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appclamavclamav---

Explore more