CVE-2026-6042

Published: April 13, 2026Last modified: April 17, 2026

Description

A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 4-byte Decoder. Performing a manipulation results in inefficient algorithmic complexity. The attack must be initiated from a local position. To fix this issue, it is recommended to deploy a patch.

Severity score breakdown

ParameterValue
Base score3.3
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactLOW
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux25 LTSmusl-defaultFixed (1.2.5-r15)
musl-perfFixed (1.2.5-r16)
Streammusl-defaultFixed (1.2.6-r2)
musl-perfFixed (1.2.6-r2)
Hardened Containers25 LTSmusl-defaultFixed (1.2.5-r15)
musl-perfFixed (1.2.5-r16)
Streammusl-defaultFixed (1.2.6-r2)
musl-perfFixed (1.2.6-r2)

References

ON THIS PAGE