Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-58081Desbordamiento de búfer crítico en iconv (glibc)

Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters. An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules.

Ver en NVD

Análisis

Vulnerabilidad crítica en iconv (componente de glibc) que permite un desbordamiento de búfer al procesar ciertas codificaciones como UTF-7 o HZ. Cualquier aplicación que convierta datos de usuarios externos mediante iconv podría estar en riesgo de ejecución remota de código.

Roles relevantes

BackendciberseguridadLinuxDockerCC++

Severidad

Puntaje: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-122

EPSS

Probabilidad de explotación (próx. 30 días): 0.0021 (0.2%)
Percentil: 11.5%
EPSS: 2026-08-26

Descripción técnica

Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters. An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules.

Publicada: 19/8/2026, 8:17:12
Última modificación: 26/8/2026, 18:16:42

Referencias

InicioEventosBlogRecursosCursosEquipo