[clamav-users] Question About MaxFileSize

Paul Kosinski clamav-users at iment.com
Sat Jun 10 03:07:40 UTC 2023


You are right. But more than that, merely *reading* a file will exercise such code. I wonder if anybody has devised a file which exploits such a kernel bug? (Shudder.)

After I wrote my objection, I realized that to be even more safe, one should scan removable disks at the block level before mounting them. But given the capacity these days of even USB thumb drives, this approach is pretty much impractical. Beside, what looks like a USB thumb drive might actually act as a USB keyboard! (In fact, I think somebody built a prototype.)


On Fri, 09 Jun 2023 18:15:39 -0700
Kenneth Porter <shiva at sewingwitch.com> wrote:

> Filesystems are also files, interpreted by kernel-level filesystem drivers. 
> Some filesystems have a compression feature. Scanning ANY file exercises 
> such code.


More information about the clamav-users mailing list