CVE-2026-4046
published 2026-03-30CVE-2026-4046: The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.38%
30.4th percentile
The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.
This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | — | — |
| gnu | glibc | <= 2.43 | — |
| the_gnu_c_library | glibc | 2.3.3 – 2.43 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
glibc: glibc: Denial of Service via iconv() function with specific character sets
vendor_redhat·2026-03-30·CVSS 7.5
CVE-2026-4046 [HIGH] CWE-617 glibc: glibc: Denial of Service via iconv() function with specific character sets
glibc: glibc: Denial of Service via iconv() function with specific character sets
The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.
This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.
A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS).
Statement: The availability impac
Debian
CVE-2026-4046: glibc - The iconv() function in the GNU C Library versions 2.43 and earlier may crash du...
vendor_debian·2026·CVSS 7.5
CVE-2026-4046 [HIGH] CVE-2026-4046: glibc - The iconv() function in the GNU C Library versions 2.43 and earlier may crash du...
The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
VulDB
GNU C Library up to up to 2.43 iconv assertion (Nessus ID 304363 / WID-SEC-2026-0918)
vuldb·2026-04-22·CVSS 7.5
CVE-2026-4046 [HIGH] GNU C Library up to up to 2.43 iconv assertion (Nessus ID 304363 / WID-SEC-2026-0918)
A vulnerability was found in GNU C Library up to up to 2.43. It has been declared as problematic. This impacts the function iconv. Executing a manipulation can lead to reachable assertion.
This vulnerability is registered as CVE-2026-4046. It is possible to launch the attack remotely. No exploit is available.
GHSA
GHSA-g7c4-wv7q-gcc6: The iconv() function in the GNU C Library versions 2
ghsa_unreviewed·2026-03-30
CVE-2026-4046 [HIGH] CWE-617 GHSA-g7c4-wv7q-gcc6: The iconv() function in the GNU C Library versions 2
The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.
This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.
OSV
CVE-2026-4046: The iconv() function in the GNU C Library versions 2
osv·2026-03-30·CVSS 7.5
CVE-2026-4046 [HIGH] CVE-2026-4046: The iconv() function in the GNU C Library versions 2
The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-4046 zig: glibc: Denial of Service via iconv() function with specific character sets [fedora-all]
bugzilla·2026-03-30·CVSS 7.5
CVE-2026-4046 [HIGH] CVE-2026-4046 zig: glibc: Denial of Service via iconv() function with specific character sets [fedora-all]
CVE-2026-4046 zig: glibc: Denial of Service via iconv() function with specific character sets [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
The Zig compiler and standard library do not make use of iconv.
---
*** Bug 2453211 has been marked as a duplicate of this bug. ***
Bugzilla
CVE-2026-4046 glibc: glibc: Denial of Service via iconv() function with specific character sets
bugzilla·2026-03-30·CVSS 7.5
CVE-2026-4046 [HIGH] CVE-2026-4046 glibc: glibc: Denial of Service via iconv() function with specific character sets
CVE-2026-4046 glibc: glibc: Denial of Service via iconv() function with specific character sets
The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.
This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.
Bugzilla
CVE-2026-4046 zig: glibc: Denial of Service via iconv() function with specific character sets [epel-all]
bugzilla·2026-03-30·CVSS 7.5
CVE-2026-4046 [HIGH] CVE-2026-4046 zig: glibc: Denial of Service via iconv() function with specific character sets [epel-all]
CVE-2026-4046 zig: glibc: Denial of Service via iconv() function with specific character sets [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
*** This bug has been marked as a duplicate of bug 2453213 ***
Bugzilla
CVE-2026-4046 glibc: glibc: Denial of Service via iconv() function with specific character sets [fedora-all]
bugzilla·2026-03-30·CVSS 7.5
CVE-2026-4046 [HIGH] CVE-2026-4046 glibc: glibc: Denial of Service via iconv() function with specific character sets [fedora-all]
CVE-2026-4046 glibc: glibc: Denial of Service via iconv() function with specific character sets [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
As upstream CNA, the severity of "High" seems excessive even in the general case. The only impact here is a DoS and it can easily be mitigated by (in the Red Hat context) dropping the glibc-gconv-extra package or minimally disabling the two gconv errant plugins; those converters are not in common use anyway.
---
The top-level security bug 2453117 is set to "Medium" severity. I'm adjusting this to match.
Wiz
CVE-2026-4046 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-4046 [MEDIUM] CVE-2026-4046 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4046 :
Linux Debian vulnerability analysis and mitigation
The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.
This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.
Source : NVD
## 7.5
Score
Published March 30, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Debian
Linux Red Hat
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 16.4
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
glibc-langp
2026-03-30
Published