← Back to browse · API

CVE-2024-2961

Severity
HIGH
CVSS
7.3
EPSS
0.8833
Risk score
60.12
CISA KEV
No
PoC
Yes
Published
2024-04-17
Modified
2026-07-14
First seen
2026-08-07
Aliases
EUVD-2024-27902, GHSA-22Q4-F5R6-3XQW
Products
The GNU C Library:glibc 2.1.93 <2.40
Sources
github d944ef99e750bb00e41055e6|CVE-2024-2961
euvd EUVD-2024-27902

Description

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.

References