CVE 7.5 HIGH

iconv crash due to assertion failure with untrusted input_CVE-2026-4046

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.



This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.

Basic Information

ID CVE-2026-4046
Source glibc
Published Mar 30, 2026 at 17:16
Modified Mar 30, 2026 at 17:37

Affected Product

Vendor The GNU C Library
Product glibc
Version 2.3.3
Affected Versions The GNU C Library glibc 2.3.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.