CVE-2026-4046

Published: March 31, 2026Last modified: April 22, 2026

Description

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSglibcFixed (2.37.0-r23)
25 LTSglibcFixed (2.39.0-r8)
StreamglibcFixed (2.39.0-r9)
Hardened Containers23 LTSglibcFixed (2.37.0-r23)
25 LTSglibcNot affected (2.39.0-r2)
StreamglibcNot affected (2.37.0-r0)

References

ON THIS PAGE