What is CVE-2026-20348?
A vulnerability in the XAR file format parser of ClamAV allows an unauthenticated remote attacker to cause memory corruption on an affected device. This can be exploited to trigger a denial-of-service (DoS) condition or potentially other expanded impacts. Users should update ClamAV to the latest available version.
Azərbaycanca: Bu, ClamAV antivirus proqramının XAR fayl formatını emal edən parserində aşkar edilmiş zəiflikdir. Uzaqdan autentifikasiya olunmamış hücumçuya təsirə məruz qalmış qurğuda yaddaş korrupsiyası vasitəsilə xidmət dayandırılması (DoS) və ya digər potensial təsirlər yaratmağa imkan verir. İstifadəçilərə ClamAV-ı ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
What does CVE-2026-20348 in ClamAV's XAR file parser allow a remote attacker to do?
This vulnerability allows an unauthenticated remote attacker to cause memory corruption on an affected device, which can lead to a denial-of-service (DoS) condition or other potential expanded impacts.
What is the recommended mitigation for CVE-2026-20348?
Users are advised to update ClamAV to the latest available version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.