{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/the-gnu-c-library--2.44/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-4046"},{"cvss":7.5,"id":"CVE-2026-4437"},{"cvss":5.4,"id":"CVE-2026-4438"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["The GNU C Library \u003c 2.44"],"_cs_severities":["high"],"_cs_tags":["glibc","iconv","denial-of-service","crash","cve-2026-4046"],"_cs_type":"advisory","_cs_vendors":["GNU"],"content_html":"\u003cp\u003eThe GNU C Library (glibc) is a fundamental component of many Linux systems, providing core functionalities for applications. A vulnerability, CVE-2026-4046, exists within the \u003ccode\u003eiconv()\u003c/code\u003e function in glibc versions 2.43 and earlier. This flaw can be triggered when the library attempts to convert character sets from IBM1390 or IBM1399. If an application utilizes \u003ccode\u003eiconv()\u003c/code\u003e to process potentially malicious input from these character sets, it could lead to an assertion failure and subsequent crash. This vulnerability has a CVSS v3.1 score of 7.5 and may allow a remote attacker to cause a denial of service. While the vulnerability itself is within glibc, the impact is on applications which call the vulnerable function. Mitigation involves removing the vulnerable character sets from systems that do not need them.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker crafts malicious input data using the IBM1390 or IBM1399 character sets.\u003c/li\u003e\n\u003cli\u003eThe attacker delivers the malicious input to a vulnerable application (e.g., via a network socket, file upload, or other means).\u003c/li\u003e\n\u003cli\u003eThe vulnerable application receives the attacker-controlled input.\u003c/li\u003e\n\u003cli\u003eThe application calls the \u003ccode\u003eiconv()\u003c/code\u003e function from the GNU C Library to convert the malicious input.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eiconv()\u003c/code\u003e attempts to convert the IBM1390 or IBM1399 input.\u003c/li\u003e\n\u003cli\u003eAn assertion failure occurs within the \u003ccode\u003eiconv()\u003c/code\u003e function due to the crafted input.\u003c/li\u003e\n\u003cli\u003eThe application process terminates abruptly due to the assertion failure.\u003c/li\u003e\n\u003cli\u003eThe application becomes unavailable, resulting in a denial-of-service condition.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-4046 can cause applications using the vulnerable \u003ccode\u003eiconv()\u003c/code\u003e function to crash. This can lead to a denial-of-service condition, impacting application availability and potentially disrupting business operations. The severity of the impact depends on the criticality of the affected application and the scope of its usage. Although the exact number of affected applications is unknown, any application relying on glibc's \u003ccode\u003eiconv()\u003c/code\u003e function for character set conversion, especially when handling external input, is potentially at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the recommended mitigation of removing the IBM1390 and IBM1399 character sets from systems that do not require them. This can be done by modifying the glibc configuration files (reference: CVE-2026-4046 description).\u003c/li\u003e\n\u003cli\u003eMonitor application logs for crashes related to \u003ccode\u003eiconv()\u003c/code\u003e function calls when handling IBM1390 or IBM1399 character sets.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u003ccode\u003eDetect Iconv Crash\u003c/code\u003e to identify potential exploitation attempts based on application crash logs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-25T15:45:17Z","date_published":"2026-03-30T18:16:19Z","id":"https://feed.craftedsignal.io/briefs/2026-03-glibc-iconv-crash/","summary":"A vulnerability in the iconv() function of the GNU C Library (versions 2.43 and earlier) can cause a crash due to an assertion failure when handling IBM1390 or IBM1399 character sets, potentially leading to remote application denial-of-service.","title":"GNU C Library iconv() Function Assertion Failure (CVE-2026-4046)","url":"https://feed.craftedsignal.io/briefs/2026-03-glibc-iconv-crash/"}],"language":"en","title":"CraftedSignal Threat Feed - The GNU C Library \u003c 2.44","version":"https://jsonfeed.org/version/1.1"}