CVE-2026-20217 is a memory-corruption vulnerability in ClamAV's PESpin executable unpacker and file-format processing. Improper validation of PESpin content during scanning can cause an out-of-bounds buffer write. The affected cleanup path may also free pointers that reference the scanned-file buffer, causing the scanner to crash. The issue affects ClamAV 1.5.2, 1.4.4, and earlier versions, including code paths present since 2005.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a full reproduction bundle for a ZendTo 6.15-8 to ClamAV remote code execution chain, plus a separate default-profile privilege-escalation continuation from clamav to root. It is not a framework module; the main exploit logic lives in poc/zendto_6_15_8_stock_clamav_rce.py, with poc/zendto_clamav_to_root_smarty_privesc.py implementing the optional second stage. The repository also includes Dockerized lab infrastructure, exact target-profile verification scripts, and a large third_party research/build tree used to generate malformed PE/RTF/XLM carriers and compiled shared-object payloads. The primary exploit capability is unauthenticated or low-friction web-driven code execution against ZendTo’s upload/scanning workflow by abusing stock savechunk.php/upload behavior and a ClamAV/libclamav parsing bug chain centered on PESpin/RTF state corruption. The Python PoC builds crafted ZIP/PE/RTF inputs, stages a DSO, triggers ClamAV scanning, and obtains execution as the clamav account. It supports two execution paths: a known-module-base libclamav-only ROP/memfd loader, and a probabilistic restart/resample mode that only needs the 4-bit libclamav page nibble and uses a relative-format bridge into libclamav’s own snprintf/dlopen path. Post-exploitation, the payload writes results either into ZendTo claim/download data or into an AuthData-backed anonymous result channel retrievable over HTTPS. The optional second-stage exploit abuses installer-default filesystem permissions and root cron behavior in ZendTo. After gaining code execution as clamav (which is in group www-data in the tested profile), the privesc helper stages a PHP armer via unauthenticated savechunk.php, atomically swaps /var/zendto/templates_c with a crafted clone using renameat2(RENAME_EXCHANGE), waits for stock root cron to execute cleanup.php, and causes root to include attacker-controlled compiled Smarty PHP before restoring the original directory and publishing a JSON result. This yields caller-selected command execution as root when the exact DAC/cron/Smarty/ext4/PHP-FFI conditions hold. Repository structure: poc/ contains the operational exploit drivers; scripts/ contains setup, verification, lab token mint/revoke, and reset helpers; target/entrypoint.sh and docker-compose.yml enforce an exact Debian 12/ZendTo/ClamAV runtime profile; docs/ contains extensive audit notes on ASLR, oracle attempts, relative-format bridging, and the Smarty root bridge; third_party/installer-runtime/clamav-pespin and oracle-hunt contain the lower-level builders and C payload sources for malformed carriers, ROP compatibility checks, and DSO constructors. Overall, this is a real exploit repository with reproducible lab packaging, exact-environment gating, and operational payloads rather than a mere detector or write-up.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A bug in ClamAV's PESpin unpacker cleanup path that can free pointers into the scanned file buffer and crash the scanner.
A Cisco-addressed vulnerability affecting the listed Cisco products, but no further technical details are provided in the content.
A ClamAV vulnerability in the PESpin unpacker cleanup path that could free pointers into the scanned file buffer and crash the scanner.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.