---
title: "CVE-2020-37167\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2020-37167?format=md
keywords: index, follow
---

# CVE-2020-37167

Publication date 12 February 2026

Last updated 4 March 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**8.4 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2020-37167?format=md#impact-score)

Toggle side navigation

## Description

ClamAV versions prior to 0.103.0-rc contain a vulnerability in function
name processing through the ClamBC bytecode interpreter that allows
attackers to manipulate bytecode function names. Attackers can exploit the
weak input validation in function name encoding to potentially execute
malicious bytecode or cause unexpected behavior in the ClamAV engine.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2020-37167?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| clamav | 25.10 questing | Not affected |
| 24.04 LTS noble | Not affected |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Fixed 0.103.2+dfsg-0ubuntu0.20.04.1  Ubuntu Pro |
| 18.04 LTS bionic | Fixed 0.103.2+dfsg-0ubuntu0.18.04.1  Ubuntu Pro |
| 16.04 LTS xenial | Fixed 0.103.2+dfsg-0ubuntu0.16.04.1  Ubuntu Pro |
| 14.04 LTS trusty | Fixed 0.103.2+dfsg-0ubuntu0.14.04.1+esm1  Ubuntu Pro |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2020-37167?format=md#patch-details)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## Notes

---

### [leosilva](https://launchpad.net/~leosilva)

Building ClamAV requires rust compiler >= 1.61
releases as bionic, xenial and trusty are not
covered by that version of rustc. ClamAV
new versions can't build in these releases
anymore.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| clamav | * Upstream:   [cd2f297](https://github.com/Cisco-Talos/clamav/commit/cd2f2975b93277de7f74464d48adb378375a305f) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

8.4 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.4 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-37167)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-37167)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2020-37167)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2020-37167)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2020-37167>
* <https://www.exploit-db.com/exploits/47687>
* <https://www.vulncheck.com/advisories/clamav-clambc-clambc-executable-regular-expression>
