Bug 2373726 (CVE-2025-20260) - CVE-2025-20260 clamav: ClamAV PDF Scanning Buffer Overflow Vulnerability
Summary: CVE-2025-20260 clamav: ClamAV PDF Scanning Buffer Overflow Vulnerability
Keywords:
Status: NEW
Alias: CVE-2025-20260
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2373744 2373746 2373747 2373749 2373750 2373752 2373753 2373756 2373757 2373745 2373748 2373751 2373754 2373755
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-06-18 18:01 UTC by OSIDB Bzimport
Modified: 2025-06-18 19:53 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-06-18 18:01:13 UTC
A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffer overflow condition, cause a denial of service (DoS) condition, or execute arbitrary code on an affected device.

This vulnerability exists because memory buffers are allocated incorrectly when PDF files are processed. An attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to trigger a buffer overflow, likely resulting in the termination of the ClamAV scanning process and a DoS condition on the affected software. Although unproven, there is also a possibility that an attacker could leverage the buffer overflow to execute arbitrary code with the privileges of the ClamAV process.


Note You need to log in before you can comment on or make changes to this bug.