Reachable assertion in GNU C Library (glibc) - CVE-2026-4046
Published: September 11, 2026
Vulnerability identifier: #VU148984
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-4046
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a reachable assertion in the iconv function when processing specially crafted input using the IBM1390 or IBM1399 character sets. A remote attacker can supply malicious input remotely to cause a denial of service.
Affected software
GNU C Library (glibc)
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME
SUSE Linux Enterprise Server 11
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Live Patching
openSUSE Leap
openEuler
glibc-livepatches-debuginfo
glibc-livepatches
glibc-livepatches-debugsource
glibc-debugsource
glibc-devel
glibc
glibc-profile
glibc-devel-32bit
glibc-debuginfo
glibc-locale-32bit
glibc-html
glibc-debuginfo-32bit
glibc-i18ndata
glibc-info
glibc-32bit
nscd
glibc-locale
glibc-profile-32bit
glibc-benchtests
glibc-help
nss_modules
libnsl
glibc-nss-devel
glibc-locale-source
glibc-debugutils
glibc-compat-2.17
glibc-common
glibc-all-langpacks
glibc-locale-archive
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME
SUSE Linux Enterprise Server 11
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Live Patching
openSUSE Leap
openEuler
glibc-livepatches-debuginfo
glibc-livepatches
glibc-livepatches-debugsource
glibc-debugsource
glibc-devel
glibc
glibc-profile
glibc-devel-32bit
glibc-debuginfo
glibc-locale-32bit
glibc-html
glibc-debuginfo-32bit
glibc-i18ndata
glibc-info
glibc-32bit
nscd
glibc-locale
glibc-profile-32bit
glibc-benchtests
glibc-help
nss_modules
libnsl
glibc-nss-devel
glibc-locale-source
glibc-debugutils
glibc-compat-2.17
glibc-common
glibc-all-langpacks
glibc-locale-archive
How to mitigate CVE-2026-4046
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
glibc-livepatches-debuginfo - addressed in versions 0.4-150400.3.16.1, 0.4-150600.8.5.1, 0.4-150700.10.7.1
glibc-livepatches - addressed in versions 0.4-150400.3.16.1, 0.4-150600.8.5.1, 0.4-150700.10.7.1
glibc-livepatches-debugsource - addressed in versions 0.4-150400.3.16.1, 0.4-150600.8.5.1, 0.4-150700.10.7.1
glibc-debugsource - update to 2.11.3-17.110.55.1
glibc-devel - update to 2.11.3-17.110.55.1
glibc - update to 2.11.3-17.110.55.1
glibc-profile - update to 2.11.3-17.110.55.1
glibc-devel-32bit - update to 2.11.3-17.110.55.1
glibc-debuginfo - update to 2.11.3-17.110.55.1
glibc-locale-32bit - update to 2.11.3-17.110.55.1
glibc-html - update to 2.11.3-17.110.55.1
glibc-debuginfo-32bit - update to 2.11.3-17.110.55.1
glibc-i18ndata - update to 2.11.3-17.110.55.1
glibc-info - update to 2.11.3-17.110.55.1
glibc-32bit - update to 2.11.3-17.110.55.1
nscd - update to 2.11.3-17.110.55.1
glibc-locale - update to 2.11.3-17.110.55.1
glibc-profile-32bit - update to 2.11.3-17.110.55.1
glibc-benchtests - update to 2.28-123
glibc-help - addressed in versions 2.28-123, 2.34-175, 2.38-101
nss_modules - addressed in versions 2.28-123, 2.34-175, 2.38-101
nscd - addressed in versions 2.28-123, 2.34-175, 2.38-101
libnsl - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-nss-devel - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-locale-source - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-devel - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-debugutils - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-debugsource - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-compat-2.17 - addressed in versions 2.28-123, 2.34-175
glibc-common - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-all-langpacks - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-debuginfo - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-locale-archive - addressed in versions 2.34-175, 2.38-101
glibc-livepatches - addressed in versions 0.4-150400.3.16.1, 0.4-150600.8.5.1, 0.4-150700.10.7.1
glibc-livepatches-debugsource - addressed in versions 0.4-150400.3.16.1, 0.4-150600.8.5.1, 0.4-150700.10.7.1
glibc-debugsource - update to 2.11.3-17.110.55.1
glibc-devel - update to 2.11.3-17.110.55.1
glibc - update to 2.11.3-17.110.55.1
glibc-profile - update to 2.11.3-17.110.55.1
glibc-devel-32bit - update to 2.11.3-17.110.55.1
glibc-debuginfo - update to 2.11.3-17.110.55.1
glibc-locale-32bit - update to 2.11.3-17.110.55.1
glibc-html - update to 2.11.3-17.110.55.1
glibc-debuginfo-32bit - update to 2.11.3-17.110.55.1
glibc-i18ndata - update to 2.11.3-17.110.55.1
glibc-info - update to 2.11.3-17.110.55.1
glibc-32bit - update to 2.11.3-17.110.55.1
nscd - update to 2.11.3-17.110.55.1
glibc-locale - update to 2.11.3-17.110.55.1
glibc-profile-32bit - update to 2.11.3-17.110.55.1
glibc-benchtests - update to 2.28-123
glibc-help - addressed in versions 2.28-123, 2.34-175, 2.38-101
nss_modules - addressed in versions 2.28-123, 2.34-175, 2.38-101
nscd - addressed in versions 2.28-123, 2.34-175, 2.38-101
libnsl - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-nss-devel - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-locale-source - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-devel - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-debugutils - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-debugsource - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-compat-2.17 - addressed in versions 2.28-123, 2.34-175
glibc-common - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-all-langpacks - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-debuginfo - addressed in versions 2.28-123, 2.34-175, 2.38-101
glibc-locale-archive - addressed in versions 2.34-175, 2.38-101
External References
Related Security Bulletins
- Denial of service in GNU C Library
- openEuler 24.03 LTS update for glibc
- openEuler 22.03 LTS SP4 update for glibc
- openEuler 20.03 LTS SP4 update for glibc
- openEuler 24.03 LTS SP3 update for glibc
- openEuler 24.03 LTS SP1 update for glibc
- SUSE update for glibc-livepatches
- SUSE update for glibc-livepatches
- SUSE update for glibc-livepatches
- SUSE update for glibc