Reachable assertion in GNU C Library (glibc) - CVE-2026-4046

 

Reachable assertion in GNU C Library (glibc) - CVE-2026-4046

Published: September 11, 2026


Vulnerability identifier: #VU148984
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-4046
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a reachable assertion in the iconv function when processing specially crafted input using the IBM1390 or IBM1399 character sets. A remote attacker can supply malicious input remotely to cause a denial of service.


Affected software

GNU C Library (glibc)
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME
SUSE Linux Enterprise Server 11
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Live Patching
openSUSE Leap
openEuler
glibc-livepatches-debuginfo
glibc-livepatches
glibc-livepatches-debugsource
glibc-debugsource
glibc-devel
glibc
glibc-profile
glibc-devel-32bit
glibc-debuginfo
glibc-locale-32bit
glibc-html
glibc-debuginfo-32bit
glibc-i18ndata
glibc-info
glibc-32bit
nscd
glibc-locale
glibc-profile-32bit
glibc-benchtests
glibc-help
nss_modules
libnsl
glibc-nss-devel
glibc-locale-source
glibc-debugutils
glibc-compat-2.17
glibc-common
glibc-all-langpacks
glibc-locale-archive

How to mitigate CVE-2026-4046

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

glibc-livepatches-debuginfo - addressed in versions 0.4-150400.3.16.1, 0.4-150600.8.5.1, 0.4-150700.10.7.1
glibc-livepatches - addressed in versions 0.4-150400.3.16.1, 0.4-150600.8.5.1, 0.4-150700.10.7.1
glibc-livepatches-debugsource - addressed in versions 0.4-150400.3.16.1, 0.4-150600.8.5.1, 0.4-150700.10.7.1
glibc-debugsource - update to 2.11.3-17.110.55.1
glibc-devel - update to 2.11.3-17.110.55.1
glibc - update to 2.11.3-17.110.55.1
glibc-profile - update to 2.11.3-17.110.55.1
glibc-devel-32bit - update to 2.11.3-17.110.55.1
glibc-debuginfo - update to 2.11.3-17.110.55.1
glibc-locale-32bit - update to 2.11.3-17.110.55.1
glibc-html - update to 2.11.3-17.110.55.1
glibc-debuginfo-32bit - update to 2.11.3-17.110.55.1
glibc-i18ndata - update to 2.11.3-17.110.55.1
glibc-info - update to 2.11.3-17.110.55.1
glibc-32bit - update to 2.11.3-17.110.55.1
nscd - update to 2.11.3-17.110.55.1
glibc-locale - update to 2.11.3-17.110.55.1
glibc-profile-32bit - update to 2.11.3-17.110.55.1
glibc-benchtests - update to 2.28-123
glibc-help - addressed in versions 2.28-123, 2.34-175, 2.38-101
nss_modules - addressed in versions 2.28-123, 2.34-175, 2.38-101
nscd - addressed in versions 2.28-123, 2.34-175, 2.38-101
libnsl - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-nss-devel - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-locale-source - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-devel - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-debugutils - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-debugsource - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-compat-2.17 - addressed in versions 2.28-123, 2.34-175
glibc-common - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-all-langpacks - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-debuginfo - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-locale-archive - addressed in versions 2.34-175, 2.38-101

External References

Related Security Bulletins