CVE-2021-3326
published 2021-01-27CVE-2021-3326: The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.09%
86.3th percentile
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | glibc | < glibc 2.31-10 (bookworm) | glibc 2.31-10 (bookworm) |
| fujitsu | m10-1_firmware | < xcp2410 | xcp2410 |
| fujitsu | m10-1_firmware | < xcp3110 | xcp3110 |
| fujitsu | m10-4_firmware | < xcp2410 | xcp2410 |
| fujitsu | m10-4_firmware | < xcp3110 | xcp3110 |
| fujitsu | m10-4s_firmware | < xcp2410 | xcp2410 |
| fujitsu | m10-4s_firmware | < xcp3110 | xcp3110 |
| fujitsu | m12-1_firmware | < xcp2410 | xcp2410 |
| fujitsu | m12-1_firmware | < xcp3110 | xcp3110 |
| fujitsu | m12-2_firmware | < xcp2410 | xcp2410 |
| fujitsu | m12-2_firmware | < xcp3110 | xcp3110 |
| fujitsu | m12-2s_firmware | < xcp2410 | xcp2410 |
| fujitsu | m12-2s_firmware | < xcp3110 | xcp3110 |
| gnu | glibc | <= 2.32.0 | — |
| gnu | glibc | >= 0 < 2.31-10 | 2.31-10 |
| gnu | glibc | >= 0 < 2.31-10 | 2.31-10 |
| gnu | glibc | >= 0 < 2.31-10 | 2.31-10 |
| gnu | glibc | >= 0 < 2.31-10 | 2.31-10 |
| gnu | glibc | >= 0 < 2.27-3ubuntu1.5 | 2.27-3ubuntu1.5 |
| gnu | glibc | >= 0 < 2.31-0ubuntu9.7 | 2.31-0ubuntu9.7 |
| gnu | glibc | >= 0 < 2.23-0ubuntu11.3+esm2 | 2.23-0ubuntu11.3+esm2 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | glibc-2.28-17.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
vendor_oracle5.9HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
glibc vulnerabilities
osv·2022-10-25·CVSS 7.5
CVE-2021-3326 [HIGH] glibc vulnerabilities
glibc vulnerabilities
Jan Engelhardt, Tavis Ormandy, and others discovered that the GNU C Library
iconv feature incorrectly handled certain input sequences. An attacker
could possibly use this issue to cause the GNU C Library to hang or crash,
resulting in a denial of service. (CVE-2021-3326)
It was discovered that the GNU C Library nscd daemon incorrectly handled
certain netgroup lookups. An attacker could possibly use this issue to
cause the GNU C Library to crash, resulting in a denial of service.
(CVE-2021-35942)
GHSA
GHSA-w279-vhxx-7qx8: The iconv function in the GNU C Library (aka glibc or libc6) 2
ghsa_unreviewed·2022-05-24
CVE-2021-3326 [HIGH] CWE-617 GHSA-w279-vhxx-7qx8: The iconv function in the GNU C Library (aka glibc or libc6) 2
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.
OSV
glibc vulnerabilities
osv·2022-03-01·CVSS 5.9
CVE-2016-10228 [MEDIUM] glibc vulnerabilities
glibc vulnerabilities
Jan Engelhardt, Tavis Ormandy, and others discovered that the GNU C Library
iconv feature incorrectly handled certain input sequences. An attacker
could possibly use this issue to cause the GNU C Library to hang or crash,
resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS
and Ubuntu 20.04 LTS. (CVE-2016-10228, CVE-2019-25013, CVE-2020-27618,
CVE-2020-29562, CVE-2021-3326)
Jason Royes and Samuel Dytrych discovered that the GNU C Library
incorrectly handled signed comparisons on ARMv7 targets. A remote attacker
could use this issue to cause the GNU C Library to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-6096)
It was discovered that the
OSV
CVE-2021-3326: The iconv function in the GNU C Library (aka glibc or libc6) 2
osv·2021-01-27·CVSS 7.5
CVE-2021-3326 [HIGH] CVE-2021-3326: The iconv function in the GNU C Library (aka glibc or libc6) 2
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
CISA ICS
Siemens SIMATIC S7-1500 TM MFP BIOS
cisa_ics·2023-06-15·CVSS 5.9
[MEDIUM] Siemens SIMATIC S7-1500 TM MFP BIOS
ICS Advisory
##
Siemens SIMATIC S7-1500 TM MFP BIOS
Release DateJune 15, 2023
Alert CodeICSA-23-166-10
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 TM MFP
- Vulnerabilities: Improper Input Validation, Out-of-bounds Read, Use After Free, Out-of-bounds Write, Infinite Loop, Reachable Assertion, Off-by-one Error, Incorrect Default Permissions, Double Fr
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2022-10-25·CVSS 7.5
CVE-2021-3326 [HIGH] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
Jan Engelhardt, Tavis Ormandy, and others discovered that the GNU C Library
iconv feature incorrectly handled certain input sequences. An attacker
could possibly use this issue to cause the GNU C Library to hang or crash,
resulting in a denial of service. (CVE-2021-3326)
It was discovered that the GNU C Library nscd daemon incorrectly handled
certain netgroup lookups. An attacker could possibly use this issue to
cause the GNU C Library to crash, resulting in a denial of service.
(CVE-2021-35942)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2022-03-01·CVSS 5.9
CVE-2021-3999 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
Jan Engelhardt, Tavis Ormandy, and others discovered that the GNU C Library
iconv feature incorrectly handled certain input sequences. An attacker
could possibly use this issue to cause the GNU C Library to hang or crash,
resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS
and Ubuntu 20.04 LTS. (CVE-2016-10228, CVE-2019-25013, CVE-2020-27618,
CVE-2020-29562, CVE-2021-3326)
Jason Royes and Samuel Dytrych discovered that the GNU C Library
incorrectly handled signed comparisons on ARMv7 targets. A remote attacker
could use this issue to cause the GNU C Library to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubunt
Oracle
Oracle Oracle Communications Risk Matrix: SEPP (glibc) — CVE-2021-3326
vendor_oracle·2022-01-15·CVSS 5.9
CVE-2021-3326 [HIGH] Oracle Oracle Communications Risk Matrix: SEPP (glibc) — CVE-2021-3326
Oracle Oracle Communications Risk Matrix: SEPP (glibc) vulnerability
CVE: CVE-2021-3326
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Red Hat
glibc: Assertion failure in ISO-2022-JP-3 gconv module related to combining characters
vendor_redhat·2021-01-27·CVSS 7.5
CVE-2021-3326 [HIGH] CWE-617 glibc: Assertion failure in ISO-2022-JP-3 gconv module related to combining characters
glibc: Assertion failure in ISO-2022-JP-3 gconv module related to combining characters
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.
A flaw was found in glibc's iconv() functionality. This flaw allows an attacker capable of supplying a crafted sequence of characters to an application using iconv() to convert from ISO-2022-JP-3 to cause an assertion failure. The highest threat from this vulnerability is to system availability.
Statement: Exploitation of this flaw would cause the application to halt execution. It relies on processing untrusted input in the ISO-2022-JP-3 encoding or
Microsoft
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier when processing invalid input sequences in the ISO-2022-JP-3 encoding fails an assertion in the code path and aborts the p
vendor_msrc·2021-01-12·CVSS 7.5
CVE-2021-3326 [HIGH] CWE-617 The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier when processing invalid input sequences in the ISO-2022-JP-3 encoding fails an assertion in the code path and aborts the p
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier when processing invalid input sequences in the ISO-2022-JP-3 encoding fails an assertion in the code path and aborts the program potentially resulting in a denial of service.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to a
Debian
CVE-2021-3326: glibc - The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, w...
vendor_debian·2021·CVSS 7.5
CVE-2021-3326 [HIGH] CVE-2021-3326: glibc - The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, w...
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.
Scope: local
bookworm: resolved (fixed in 2.31-10)
bullseye: resolved (fixed in 2.31-10)
forky: resolved (fixed in 2.31-10)
sid: resolved (fixed in 2.31-10)
trixie: resolved (fixed in 2.31-10)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2021/01/28/2https://lists.debian.org/debian-lts-announce/2022/10/msg00021.htmlhttps://security.gentoo.org/glsa/202107-07https://security.netapp.com/advisory/ntap-20210304-0007/https://sourceware.org/bugzilla/show_bug.cgi?id=27256https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=7d88c6142c6efc160c0ee5e4f85cde382c072888https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttp://www.openwall.com/lists/oss-security/2021/01/28/2https://lists.debian.org/debian-lts-announce/2022/10/msg00021.htmlhttps://security.gentoo.org/glsa/202107-07https://security.netapp.com/advisory/ntap-20210304-0007/https://sourceware.org/bugzilla/show_bug.cgi?id=27256https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=7d88c6142c6efc160c0ee5e4f85cde382c072888https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.html
2021-01-27
Published