PT-2026-31904 · Musl Libc · Musl Libc
CVSS v3.1
8.1
High
| Vector | AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
musl libc versions up to 1.2.6
Description
A security flaw exists in the
iconv function within the GB18030 4-byte Decoder component of musl libc, specifically in the file src/locale/iconv.c. A manipulation of this function leads to inefficient algorithmic complexity. The attack requires local access.Recommendations
Deploy a patch to address this issue.
Fix
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Musl Libc