CVE-2026-6042
Published: April 13, 2026Last modified: April 17, 2026
Description
A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 4-byte Decoder. Performing a manipulation results in inefficient algorithmic complexity. The attack must be initiated from a local position. To fix this issue, it is recommended to deploy a patch.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 3.3 |
| Attack Vector | LOCAL |
| Attack complexity | LOW |
| Privileges required | LOW |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | NONE |
| Integrity impact | NONE |
| Availability impact | LOW |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 25 LTS | musl-default | Fixed (1.2.5-r15) |
| musl-perf | Fixed (1.2.5-r16) | ||
| Stream | musl-default | Fixed (1.2.6-r2) | |
| musl-perf | Fixed (1.2.6-r2) | ||
| Hardened Containers | 25 LTS | musl-default | Fixed (1.2.5-r15) |
| musl-perf | Fixed (1.2.5-r16) | ||
| Stream | musl-default | Fixed (1.2.6-r2) | |
| musl-perf | Fixed (1.2.6-r2) |