What is CVE-2026-20339?
This vulnerability exists in the PESpin file format parser of ClamAV. A remote unauthenticated attacker could exploit improper boundary checks to cause memory corruption, leading to a denial of service (DoS) condition on an affected device. Updating ClamAV to the latest patched version is strongly recommended.
Azərbaycanca: Bu zəiflik ClamAV antivirus proqramının PESpin fayl formatı parserində aşkarlanıb. Uzaqdan autentifikasiya olunmamış hücumçu, xüsusi hazırlanmış fayl vasitəsilə memory corruption yaradaraq xidmət rəddi (DoS) şəraitinə səbəb ola bilər. Təsirə məruz qalmış cihazlarda ClamAV-ı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
In which component of ClamAV was CVE-2026-20339 found?
This vulnerability exists in the PESpin file format parser of ClamAV.
What outcome can an attacker achieve by exploiting CVE-2026-20339?
A remote unauthenticated attacker could cause memory corruption, leading to a denial of service (DoS) condition on an affected device.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.