PT-2026-56240 · Gnu+3 · Wget+3

·

CVE-2026-58471

·

Published

2026-07-07

·

Updated

2026-09-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU Wget versions prior to 1.25.0 commit c2640fe
Description A heap buffer overflow occurs in the convert fname() function within src/url.c. This issue is triggered when a server-supplied filename requires character set conversion and the output buffer is too small during iconv E2BIG reallocation. The reallocation logic miscalculates the remaining space, allowing a remote attacker to cause memory corruption via a maliciously crafted server response. iconv E2BIG is an error code indicating that the output buffer is too small to hold the converted string.
Recommendations Update to the version containing commit c2640fe.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:62142
ALSA-2026:62143
ALSA-2026:62144
CVE-2026-58471
ECHO-333A-02B0-5DAC
JLSEC-2026-1160
OESA-2026-3152
OPENSUSE-SU-2026:11252-1
OPENSUSE-SU-2026:21665-1
RHSA-2026:62142
RHSA-2026:62143
SUSE-SU-2026:23053-1
SUSE-SU-2026:23163-1
SUSE-SU-2026:23297-1
SUSE-SU-2026:23326-1
SUSE-SU-2026:3148-1
SUSE-SU-2026:3206-1
USN-8543-1

Affected Products

Linuxmint
Rocky Linux
Ubuntu
Wget