Description
A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 4-byte Decoder. Performing a manipulation results in inefficient algorithmic complexity. The attack must be initiated from a local position. To fix this issue, it is recommended to deploy a patch.
Problem types
Inefficient Algorithmic Complexity
Product status
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
Timeline
| 2026-04-09: | Advisory disclosed |
| 2026-04-09: | VulDB entry created |
| 2026-04-09: | VulDB entry last update |
Credits
0x001 (VulDB User)
0x001 (VulDB User)
References
www.openwall.com/lists/oss-security/2026/04/09/19
vuldb.com/vuln/356620 (VDB-356620 | musl libc GB18030 4-byte Decoder iconv.c iconv algorithmic complexity)
vuldb.com/vuln/356620/cti (VDB-356620 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/796352 (Submit #796352 | musl libc musl 0.8.0 - 1.2.6 Inefficient Algorithmic Complexity)
www.openwall.com/lists/oss-security/2026/04/02/10
www.openwall.com/lists/oss-security/2026/04/03/2