ANT-2026-VVPEMVDE · cisco-talos/clamav
integer-overflow high
CVE-2026-20213 GHSA-rjvx-x4g3-vr6w
Severity Claude high · Security research firm high · Maintainer high
Discovered by Claude Mythos Preview
Anthropic's analysis, sealed at approval. Disclosure to the maintainer was performed by Trail of Bits.
ANT-2026-VVPEMVDE: Integer overflow in PE rebuild section size summation in Aspack unpacker
An integer overflow occurs when summing section sizes during PE rebuild in the Aspack unpacker.
Target
Project: ClamAV
Location: libclamav/rebuildpe.c:cli_rebuildpe_align (lines ~140-144)
Discovery: static analysis — not yet dynamically reproduced
Reproduction
This finding was identified by static analysis and has not yet been dynamically reproduced. A trigger input is not included.
[No reproducer or sanitizer output attached — request from security-cvd@anthropic.com if needed.]
Acknowledgement
This vulnerability was discovered by Claude, Anthropic's AI assistant, and triaged by the Anthropic security team in collaboration with Anthropic Research. Please direct questions to security-cvd@anthropic.com and reference ANT-2026-VVPEMVDE.
Reference: ANT-2026-VVPEMVDE
Anthropic CVD Policy: https://www.anthropic.com/coordinated-vulnerability-disclosure
Triage and disclosure were performed by Trail of Bits.
- Verdict
- true positive
- Severity
- high
https://github.com/Cisco-Talos/clamav/commit/ca39e3843b47f298c3315996df30cf937c20c4ee
Dates from discovery through public reveal.
- 2026-03-29 Reported to tracker
- 2026-04-09 Sent to maintainer
- 2026-05-07 Patch released
- 2026-05-07 Maintainer acknowledged
- 2026-07-20 Publicly revealed
SHA-3-512 hash:
89125e041730615a2fff06ae6e0eff4b40b6408d111f17abde7f218c7f212abf26dd07500ce51127eac4875d6d9bbc7c8a90e37310611e2c394c3aea90d93723
Committed 2026-04-09 11:49 PT
Revealed 2026-07-20 22:25 PT
Verify (download preimage.json)
Show preimage JSON
{
"ant_id": "ANT-2026-VVPEMVDE",
"bug_class": "Integer Overflow",
"claude_severity": "high",
"commit_sha": null,
"created_at": "2026-03-29T20:42:41+00:00",
"description": "An integer overflow occurs when summing section sizes during PE rebuild in the Aspack unpacker.",
"discovered_at": null,
"location": null,
"poc_sha256": null,
"preimage_version": 1,
"project": "ClamAV",
"reproduction": null,
"technical_details": null,
"title": "Integer overflow in PE rebuild section size summation in Aspack unpacker",
"vendor_severity": "high"
}