This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 30 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 30 Mar 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 30 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them. | |
| Title | iconv crash due to assertion failure with untrusted input | |
| Weaknesses | CWE-617 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: glibc
Published:
Updated: 2026-03-30T17:37:52.633Z
Reserved: 2026-03-12T10:12:32.994Z
Link: CVE-2026-4046
Updated: 2026-03-30T17:35:44.684Z
Status : Received
Published: 2026-03-30T18:16:19.573
Modified: 2026-03-30T18:16:19.573
Link: CVE-2026-4046
No data.
OpenCVE Enrichment
No data.