On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in Clam AntiVirus (ClamAV) versions 0.103.4, 0.103.5, 0.104.1, and 0.104.2 could allow an authenticated, local attacker to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade clamav | Oct 1, 2024 | May 4, 2022 |
| Amazon_linux | — | Upgrade clamav | Aug 5, 2022 | May 4, 2022 |
| Amazon_linux_2023 | — | Upgrade clamav-libUpgrade clamav-debuginfoUpgrade clamav-updateUpgrade clamav-lib-debuginfoUpgrade clamavUpgrade clamav-filesystemUpgrade clamav-milter-debuginfoUpgrade clamdUpgrade clamav-develUpgrade clamav-dataUpgrade clamav-debugsourceUpgrade clamav-milterUpgrade clamd-debuginfoUpgrade clamav-update-debuginfo | Feb 17, 2025 | May 4, 2022 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 4, 2022 |
| Debian | — | Upgrade clamav | Jun 6, 2022 | May 4, 2022 |
| Freebsd | — | Upgrade clamav-ltsUpgrade clamav | Nov 4, 2022 | May 19, 2022 |
| Gentoo Linux | — | Upgrade app-antivirus/clamav. | Oct 2, 2023 | May 4, 2022 |
| Suse | — | Upgrade clamav-develUpgrade libclamav9Upgrade libfreshclam2Upgrade clamav | Oct 26, 2022 | May 4, 2022 |
| Ubuntu | — | Upgrade clamav (Ubuntu Pro)Upgrade clamav | May 18, 2022 | May 4, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub