Bug 2519413 (CVE-2026-58081) - CVE-2026-58081 iconv: iconv: Heap-based buffer overflow in encoding modules
Summary: CVE-2026-58081 iconv: iconv: Heap-based buffer overflow in encoding modules
Keywords:
Status: NEW
Alias: CVE-2026-58081
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-19 07:32 UTC by OSIDB Bzimport
Modified: 2026-08-24 14:30 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-19 07:32:08 UTC
Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters.

An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules.


Note You need to log in before you can comment on or make changes to this bug.