Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6042

Опубликовано: 10 апр. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 4-byte Decoder. Performing a manipulation results in inefficient algorithmic complexity. The attack must be initiated from a local position. To fix this issue, it is recommended to deploy a patch.

A flaw was found in musl libc, specifically within the iconv function of the GB18030 4-byte Decoder component. A local attacker can exploit this vulnerability by performing a specific manipulation, leading to inefficient algorithmic complexity. This can result in a Denial of Service (DoS) due to excessive resource consumption, impacting system availability.

Отчет

A MODERATE flaw in musl libc's iconv function, specifically within the GB18030 4-byte Decoder, allows a local attacker to trigger a Denial of Service. This vulnerability arises from inefficient algorithmic complexity when processing specific manipulations. Red Hat Enterprise Linux does not use musl libc as its default C library, limiting direct impact to environments or applications that explicitly utilize musl libc.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1050
https://bugzilla.redhat.com/show_bug.cgi?id=2457266musl libc: GB18030 4-byte Decoder: musl libc: Denial of Service via inefficient algorithmic complexity in iconv

EPSS

Процентиль: 15%
0.00236
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
4 месяца назад

A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 4-byte Decoder. Performing a manipulation results in inefficient algorithmic complexity. The attack must be initiated from a local position. To fix this issue, it is recommended to deploy a patch.

CVSS3: 3.3
nvd
4 месяца назад

A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 4-byte Decoder. Performing a manipulation results in inefficient algorithmic complexity. The attack must be initiated from a local position. To fix this issue, it is recommended to deploy a patch.

CVSS3: 3.3
debian
4 месяца назад

A security flaw has been discovered in musl libc up to 1.2.6. Affected ...

CVSS3: 3.3
github
4 месяца назад

A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 4-byte Decoder. Performing a manipulation results in inefficient algorithmic complexity. The attack must be initiated from a local position. To fix this issue, it is recommended to deploy a patch.

EPSS

Процентиль: 15%
0.00236
Низкий

5.5 Medium

CVSS3