Impact
The iconv() routine in GNU C Library versions 2.43 and earlier may crash with an assertion failure when an attacker supplies data encoded in the IBM1390 or IBM1399 character sets. Exploiting this flaw allows a remote attacker to cause the target application to terminate abruptly, resulting in a denial of service. The weakness is a type of assertion fault (CWE‑617).
Affected Systems
This issue impacts systems that ship glibc 2.43 or earlier. Any Linux distribution or other OS that uses an affected libc version is subject to the vulnerability. The flaw does not appear in newer releases such as 2.44 and later.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high severity level, while the EPSS score of less than 1 % shows that current exploitation likelihood is low. The vulnerability is not presently listed in the CISA KEV catalog, suggesting no widespread active exploitation yet. The attack can be carried out remotely by feeding malicious input into iconv, thereby triggering the crash.
OpenCVE Enrichment