PT-2026-78313 · Iconv+1 · Iconv+1

·

CVE-2026-58082

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iconv(3) (affected versions not specified)
Description The ISO-2022 encoding module uses a stack buffer sized to MB LEN MAX (6 bytes) for intermediate character output. Because certain ISO-2022 variants can require up to 10 bytes per character, conversions may trigger a stack buffer overflow of up to four bytes. Applications using the iconv(3) function to convert untrusted input to or from these affected encodings are susceptible to this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58082

Affected Products

Freebsd
Iconv