<Vulnerability name="CVE-2026-20244">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-07-01T16:28:27</PublicDate>
    <Bugzilla id="2496095" url="https://bugzilla.redhat.com/show_bug.cgi?id=2496095" xml:lang="en:us">
clamav: ClamAV: Denial of Service via crafted DMG file
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-190</CWE>
    <Details xml:lang="en:us" source="Mitre">
A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device.

This vulnerability is due to improper boundary checks for content in DMG files during scanning, which may result in an integer overflow on 32-bit platforms only. An attacker could exploit this vulnerability by submitting a crafted file that contains DMG content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in ClamAV's DMG file format parser. An unauthenticated, remote attacker can exploit this vulnerability by submitting a specially crafted DMG file for scanning. Improper boundary checks during the scanning process can lead to an integer overflow, primarily affecting 32-bit platforms. A successful exploit could cause the ClamAV scanning process to terminate, resulting in a Denial of Service (DoS) condition.
    </Details>
    <Statement xml:lang="en:us">
This Important denial-of-service flaw in ClamAV's DMG file parser primarily impacts 32-bit Red Hat environments. Remote, unauthenticated attackers can trigger a service disruption by submitting a crafted DMG file for scanning, leading to the ClamAV process terminating. This is critical for systems relying on ClamAV for continuous threat detection.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-20244
https://nvd.nist.gov/vuln/detail/CVE-2026-20244
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR
    </References>
</Vulnerability>