The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.
This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.
References
| Link | Resource |
|---|---|
| https://inbox.sourceware.org/libc-announce/76814edf-cf7f-47ec-979d-2dce0a2c76bf@gotplt.org/T/#u | |
| https://sourceware.org/bugzilla/show_bug.cgi?id=33980 | Exploit Issue Tracking Patch |
| https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD | Third Party Advisory |
Configurations
History
20 Apr 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
07 Apr 2026, 18:34
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://sourceware.org/bugzilla/show_bug.cgi?id=33980 - Exploit, Issue Tracking, Patch | |
| References | () https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD - Third Party Advisory | |
| First Time |
Gnu
Gnu glibc |
|
| CPE | cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* |
01 Apr 2026, 14:24
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
30 Mar 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-30 18:16
Updated : 2026-04-20 22:16
NVD link : CVE-2026-4046
Mitre link : CVE-2026-4046
CVE.ORG link : CVE-2026-4046
JSON object : View
Products Affected
gnu
- glibc
CWE
CWE-617
Reachable Assertion
