CVE-2026-20216

Description

A flaw was found in ClamAV's InstallShield file format parser. An unauthenticated, remote attacker could exploit this vulnerability by submitting a specially crafted InstallShield file for scanning. This improper handling of temporary resources during file scanning could lead to the termination of the ClamAV scanning process and temporary consumption of system resources, resulting in a Denial of Service (DoS) condition on the affected device.

Statement

ClamAV, when deployed in Red Hat environments, is often used for scanning untrusted files. This Important flaw allows an unauthenticated, remote attacker to cause a denial of service by submitting a specially crafted InstallShield file. Successful exploitation can lead to the ClamAV scanning process terminating and consuming system resources, impacting the availability of the scanning service.

Mitigation

To reduce the risk of denial of service, deploy ClamAV within a sandboxed environment to contain potential resource exhaustion. Additionally, exercise caution when processing untrusted InstallShield files, and restrict their sources to trusted origins where possible.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)

When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.

Frequently Asked Questions

Want to get errata notifications? Sign up here.