The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.
This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.
References
Configurations
No configuration.
History
30 Mar 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-30 18:16
Updated : 2026-03-30 18:16
NVD link : CVE-2026-4046
Mitre link : CVE-2026-4046
CVE.ORG link : CVE-2026-4046
JSON object : View
Products Affected
No product.
CWE
CWE-617
Reachable Assertion
