ANT-2026-8DRZW7VM · cisco-talos/clamav

integer-overflow high

CVE-2026-20215 GHSA-6gff-7f37-2v35

Severity Claude high · Security research firm high · Maintainer high

Discovered by Claude Mythos Preview

REPORT

Anthropic's analysis, sealed at approval. Disclosure to the maintainer was performed by Trail of Bits.

ANT-2026-8DRZW7VM: Integer overflow in 7z SubStreams count leading to heap buffer overflow

An integer overflow when computing the SubStreams count in the 7z archive parser results in an undersized allocation and subsequent heap buffer overflow.

Target

Project: ClamAV
Location: libclamav/7z/7zIn.c:SzReadSubStreamsInfo (7zIn.c:771)
Discovery: static analysis — not yet dynamically reproduced

Reproduction

This finding was identified by static analysis and has not yet been dynamically reproduced. A trigger input is not included.

[No reproducer or sanitizer output attached — request from security-cvd@anthropic.com if needed.]

Acknowledgement

This vulnerability was discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. Please direct questions to security-cvd@anthropic.com and reference ANT-2026-8DRZW7VM.


Reference: ANT-2026-8DRZW7VM
Anthropic CVD Policy: https://www.anthropic.com/coordinated-vulnerability-disclosure

SECURITY RESEARCH FIRM ANALYSIS

Triage and disclosure were performed by Trail of Bits.

Verdict
true positive
Severity
high
ADVISORY

https://github.com/Cisco-Talos/clamav/commit/a0b1531c6368347a79c15fb69d508171c55cc8cf

TIMELINE

Dates from discovery through public reveal.

  1. 2026-03-29 Reported to tracker
  2. 2026-04-09 Sent to maintainer
  3. 2026-05-07 Patch released
  4. 2026-05-07 Maintainer acknowledged
  5. 2026-07-20 Publicly revealed
PROVENANCE

SHA-3-512 hash:

67ced60afd5a1e4a42149c7ab50f3c46bf4db111cb82f29c246c6a1e74f7644512439a18d8fa6b6a3bd1d3f13b5f4282d8195e21a3a4a5b4e57029947237f85f

Committed 2026-04-09 11:49 PT

Revealed 2026-07-20 22:20 PT

Verify (download preimage.json)

Show preimage JSON
{
  "ant_id": "ANT-2026-8DRZW7VM",
  "bug_class": "Integer Overflow",
  "claude_severity": "high",
  "commit_sha": null,
  "created_at": "2026-03-29T20:42:42+00:00",
  "description": "An integer overflow when computing the SubStreams count in the 7z archive parser results in an undersized allocation and subsequent heap buffer overflow.",
  "discovered_at": null,
  "location": null,
  "poc_sha256": null,
  "preimage_version": 1,
  "project": "ClamAV",
  "reproduction": null,
  "technical_details": null,
  "title": "Integer overflow in 7z SubStreams count leading to heap buffer overflow",
  "vendor_severity": "high"
}