Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-58081Critical buffer overflow in iconv (glibc)

Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters. An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules.

View on NVD

Analysis

Vulnerabilidad crítica en iconv (componente de glibc) que permite un desbordamiento de búfer al procesar ciertas codificaciones como UTF-7 o HZ. Cualquier aplicación que convierta datos de usuarios externos mediante iconv podría estar en riesgo de ejecución remota de código.

Relevant roles

BackendciberseguridadLinuxDockerCC++

Severity

Score: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-122

EPSS

Probability of exploitation (next 30 days): 0.0021 (0.2%)
Percentile: 11.5%
EPSS: 2026-08-26

Technical description

Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters. An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules.

Published: 8/19/2026, 8:17:12 AM
Last modified: 8/26/2026, 6:16:42 PM

References

HomeEventsBlogResourcesCoursesTeam