CVE-2025-26519

musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write vulnerability when an attacker can trigger iconv conversion of untrusted EUC-KR text to UTF-8.
Configurations

Configuration 1 (hide)

cpe:2.3:a:musl-libc:musl:*:*:*:*:*:*:*:*

History

10 Dec 2025, 20:03

Type Values Removed Values Added
First Time Musl-libc
Musl-libc musl
Summary
  • (es) musl libc 0.9.13 a 1.2.5 antes de 1.2.6 tiene una vulnerabilidad de escritura fuera de los límites cuando un atacante puede activar la conversión iconv de texto EUC-KR no confiable a UTF-8.
CPE cpe:2.3:a:musl-libc:musl:*:*:*:*:*:*:*:*
References () https://git.musl-libc.org/cgit/musl/commit/?id=c47ad25ea3b484e10326f933e927c0bc8cded3da - () https://git.musl-libc.org/cgit/musl/commit/?id=c47ad25ea3b484e10326f933e927c0bc8cded3da - Patch
References () https://git.musl-libc.org/cgit/musl/commit/?id=e5adcd97b5196e29991b524237381a0202a60659 - () https://git.musl-libc.org/cgit/musl/commit/?id=e5adcd97b5196e29991b524237381a0202a60659 - Patch
References () https://www.openwall.com/lists/oss-security/2025/02/13/2 - () https://www.openwall.com/lists/oss-security/2025/02/13/2 - Mailing List, Mitigation, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2025/02/13/2 - () http://www.openwall.com/lists/oss-security/2025/02/13/2 - Mailing List, Mitigation, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2025/02/13/3 - () http://www.openwall.com/lists/oss-security/2025/02/13/3 - Mailing List, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2025/02/13/4 - () http://www.openwall.com/lists/oss-security/2025/02/13/4 - Mailing List, Mitigation, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2025/02/13/5 - () http://www.openwall.com/lists/oss-security/2025/02/13/5 - Mailing List, Mitigation, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2025/02/14/5 - () http://www.openwall.com/lists/oss-security/2025/02/14/5 - Mailing List, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2025/02/14/6 - () http://www.openwall.com/lists/oss-security/2025/02/14/6 - Mailing List, Third Party Advisory

14 Feb 2025, 17:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/02/14/5 -
  • () http://www.openwall.com/lists/oss-security/2025/02/14/6 -

14 Feb 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-14 04:15

Updated : 2025-12-10 20:03


NVD link : CVE-2025-26519

Mitre link : CVE-2025-26519

CVE.ORG link : CVE-2025-26519


JSON object : View

Products Affected

musl-libc

  • musl
CWE
CWE-787

Out-of-bounds Write