CVE-2026-6042

LOW

musl libc GB18030 4-byte Decoder iconv.c iconv algorithmic complexity

Title source: cna

Description

A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 4-byte Decoder. Performing a manipulation results in inefficient algorithmic complexity. The attack must be initiated from a local position. To fix this issue, it is recommended to deploy a patch.

Scores

CVSS v3 3.3
EPSS 0.0001
EPSS Percentile 2.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-404 CWE-407
Status published
Products (7)
musl/libc 1.2.0
musl/libc 1.2.1
musl/libc 1.2.2
musl/libc 1.2.3
musl/libc 1.2.4
musl/libc 1.2.5
musl/libc 1.2.6
Published Apr 10, 2026
Tracked Since Apr 10, 2026