CVE-2022-20792

high
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
8.0

Description

A vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an authenticated, local attacker to crash ClamAV at database load time, and possibly gain code execution. The vulnerability is due to improper bounds checking that may result in a multi-byte heap buffer overwflow write. An attacker could exploit this vulnerability by placing a crafted CDB ClamAV signature database file in the ClamAV database directory. An exploit could allow the attacker to run code as the clamav user.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2022-20792.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2022-20792

OS impact

OSVersionStatusFixed in
arch archfixed0.105.0-1
debian debianbookwormfixed0.103.6+dfsg-1
debian debianbullseyefixed0.103.6+dfsg-0+deb11u1
debian debianforkyfixed0.103.6+dfsg-1
debian debiansidfixed0.103.6+dfsg-1
debian debiantrixiefixed0.103.6+dfsg-1
suse slesaffected

References

Verify integrity in audit chain (admin only). AS-IS.