ANT-2026-VVPEMVDE · cisco-talos/clamav

integer-overflow high

CVE-2026-20213 GHSA-rjvx-x4g3-vr6w

Severity Claude high · Security research firm high · Maintainer high

Discovered by Claude Mythos Preview

REPORT

Anthropic's analysis, sealed at approval. Disclosure to the maintainer was performed by Trail of Bits.

ANT-2026-VVPEMVDE: Integer overflow in PE rebuild section size summation in Aspack unpacker

An integer overflow occurs when summing section sizes during PE rebuild in the Aspack unpacker.

Target

Project: ClamAV
Location: libclamav/rebuildpe.c:cli_rebuildpe_align (lines ~140-144)
Discovery: static analysis — not yet dynamically reproduced

Reproduction

This finding was identified by static analysis and has not yet been dynamically reproduced. A trigger input is not included.

[No reproducer or sanitizer output attached — request from security-cvd@anthropic.com if needed.]

Acknowledgement

This vulnerability was discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. Please direct questions to security-cvd@anthropic.com and reference ANT-2026-VVPEMVDE.


Reference: ANT-2026-VVPEMVDE
Anthropic CVD Policy: https://www.anthropic.com/coordinated-vulnerability-disclosure

SECURITY RESEARCH FIRM ANALYSIS

Triage and disclosure were performed by Trail of Bits.

Verdict
true positive
Severity
high
ADVISORY

https://github.com/Cisco-Talos/clamav/commit/ca39e3843b47f298c3315996df30cf937c20c4ee

TIMELINE

Dates from discovery through public reveal.

  1. 2026-03-29 Reported to tracker
  2. 2026-04-09 Sent to maintainer
  3. 2026-05-07 Patch released
  4. 2026-05-07 Maintainer acknowledged
  5. 2026-07-20 Publicly revealed
PROVENANCE

SHA-3-512 hash:

89125e041730615a2fff06ae6e0eff4b40b6408d111f17abde7f218c7f212abf26dd07500ce51127eac4875d6d9bbc7c8a90e37310611e2c394c3aea90d93723

Committed 2026-04-09 11:49 PT

Revealed 2026-07-20 22:25 PT

Verify (download preimage.json)

Show preimage JSON
{
  "ant_id": "ANT-2026-VVPEMVDE",
  "bug_class": "Integer Overflow",
  "claude_severity": "high",
  "commit_sha": null,
  "created_at": "2026-03-29T20:42:41+00:00",
  "description": "An integer overflow occurs when summing section sizes during PE rebuild in the Aspack unpacker.",
  "discovered_at": null,
  "location": null,
  "poc_sha256": null,
  "preimage_version": 1,
  "project": "ClamAV",
  "reproduction": null,
  "technical_details": null,
  "title": "Integer overflow in PE rebuild section size summation in Aspack unpacker",
  "vendor_severity": "high"
}