CVE-2026-4046

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*

History

07 Apr 2026, 18:34

Type Values Removed Values Added
First Time Gnu
Gnu glibc
CPE cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*
References () https://sourceware.org/bugzilla/show_bug.cgi?id=33980 - () https://sourceware.org/bugzilla/show_bug.cgi?id=33980 - Exploit, Issue Tracking, Patch
References () https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD - () https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD - Third Party Advisory

01 Apr 2026, 14:24

Type Values Removed Values Added
Summary
  • (es) La función iconv() en la Biblioteca C de GNU versiones 2.43 y anteriores puede colapsar debido a un fallo de aserción al convertir entradas de los conjuntos de caracteres IBM1390 o IBM1399, lo que puede ser utilizado para colapsar una aplicación de forma remota. Esta vulnerabilidad puede mitigarse trivialmente al eliminar los conjuntos de caracteres IBM1390 e IBM1399 de los sistemas que no los necesiten.

30 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 18:16

Updated : 2026-04-07 18:34


NVD link : CVE-2026-4046

Mitre link : CVE-2026-4046

CVE.ORG link : CVE-2026-4046


JSON object : View

Products Affected

gnu

  • glibc
CWE
CWE-617

Reachable Assertion