<Vulnerability name="CVE-2026-20216">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-07-01T16:27:51</PublicDate>
    <Bugzilla id="2496115" url="https://bugzilla.redhat.com/show_bug.cgi?id=2496115" xml:lang="en:us">
ClamAV: ClamAV: Denial of Service via crafted InstallShield file
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-770</CWE>
    <Details xml:lang="en:us" source="Mitre">
A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.

This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a crafted InstallShield file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process and temporarily consume available system resources, resulting in a DoS condition on the affected software.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in ClamAV's InstallShield file format parser. An unauthenticated, remote attacker could exploit this vulnerability by submitting a specially crafted InstallShield file for scanning. This improper handling of temporary resources during file scanning could lead to the termination of the ClamAV scanning process and temporary consumption of system resources, resulting in a Denial of Service (DoS) condition on the affected device.
    </Details>
    <Statement xml:lang="en:us">
ClamAV, when deployed in Red Hat environments, is often used for scanning untrusted files. This Important flaw allows an unauthenticated, remote attacker to cause a denial of service by submitting a specially crafted InstallShield file. Successful exploitation can lead to the ClamAV scanning process terminating and consuming system resources, impacting the availability of the scanning service.
    </Statement>
    <Mitigation xml:lang="en:us">
To reduce the risk of denial of service, deploy ClamAV within a sandboxed environment to contain potential resource exhaustion. Additionally, exercise caution when processing untrusted InstallShield files, and restrict their sources to trusted origins where possible.
    </Mitigation>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-20216
https://nvd.nist.gov/vuln/detail/CVE-2026-20216
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR
    </References>
</Vulnerability>