ANT-2026-8DRZW7VM · cisco-talos/clamav
integer-overflow high
CVE-2026-20215 GHSA-6gff-7f37-2v35
Severity Claude high · Security research firm high · Maintainer high
Discovered by Claude Mythos Preview
Anthropic's analysis, sealed at approval. Disclosure to the maintainer was performed by Trail of Bits.
ANT-2026-8DRZW7VM: Integer overflow in 7z SubStreams count leading to heap buffer overflow
An integer overflow when computing the SubStreams count in the 7z archive parser results in an undersized allocation and subsequent heap buffer overflow.
Target
Project: ClamAV
Location: libclamav/7z/7zIn.c:SzReadSubStreamsInfo (7zIn.c:771)
Discovery: static analysis — not yet dynamically reproduced
Reproduction
This finding was identified by static analysis and has not yet been dynamically reproduced. A trigger input is not included.
[No reproducer or sanitizer output attached — request from security-cvd@anthropic.com if needed.]
Acknowledgement
This vulnerability was discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. Please direct questions to security-cvd@anthropic.com and reference ANT-2026-8DRZW7VM.
Reference: ANT-2026-8DRZW7VM
Anthropic CVD Policy: https://www.anthropic.com/coordinated-vulnerability-disclosure
Triage and disclosure were performed by Trail of Bits.
- Verdict
- true positive
- Severity
- high
https://github.com/Cisco-Talos/clamav/commit/a0b1531c6368347a79c15fb69d508171c55cc8cf
Dates from discovery through public reveal.
- 2026-03-29 Reported to tracker
- 2026-04-09 Sent to maintainer
- 2026-05-07 Patch released
- 2026-05-07 Maintainer acknowledged
- 2026-07-20 Publicly revealed
SHA-3-512 hash:
67ced60afd5a1e4a42149c7ab50f3c46bf4db111cb82f29c246c6a1e74f7644512439a18d8fa6b6a3bd1d3f13b5f4282d8195e21a3a4a5b4e57029947237f85f
Committed 2026-04-09 11:49 PT
Revealed 2026-07-20 22:20 PT
Verify (download preimage.json)
Show preimage JSON
{
"ant_id": "ANT-2026-8DRZW7VM",
"bug_class": "Integer Overflow",
"claude_severity": "high",
"commit_sha": null,
"created_at": "2026-03-29T20:42:42+00:00",
"description": "An integer overflow when computing the SubStreams count in the 7z archive parser results in an undersized allocation and subsequent heap buffer overflow.",
"discovered_at": null,
"location": null,
"poc_sha256": null,
"preimage_version": 1,
"project": "ClamAV",
"reproduction": null,
"technical_details": null,
"title": "Integer overflow in 7z SubStreams count leading to heap buffer overflow",
"vendor_severity": "high"
}