Impact
Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in glibc versions 2.3 through 2.44 may result in the converter making no progress, causing the calling application to hang. Some sequences decode to two code points; when the output buffer can hold only the first, the converter stores the second as pending, returns E2BIG, but never clears that pending character. On the next call it repeatedly emits the pending character without consuming more input, looping forever. This behavior can be triggered by attacker‑controlled input with a small output buffer, leading to a denial of service. The issue is identified as a classic infinite‑loop bug (CWE-835).
Affected Systems
The vulnerability affects glibc versions 2.3 through 2.44, which are present in many Linux distributions and other Unix‑like operating systems that ship the library. EPSS score is below 1% and the CVE is not listed in the CISA KEV catalog. The vulnerability is triggered by attacker‑controlled input when an application invokes the SHIFT_JISX0213 conversion routine with a small output buffer, potentially allowing a remote attacker to induce an infinite loop that hangs the application. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate impact, reflecting application‑level denial of service with limited scope. EPSS below 1% suggests exploitation is unlikely, yet it is inferred that the vulnerability could be leveraged via any component that passes unvalidated text to glibc’s iconv for SHIFT_JISX0213 conversion. The CVE is not currently in the CISA KEV catalog, so no widespread exploitation has been documented. Attackers need to supply crafted SHIFT_JISX0213 sequences and ensure the target processes use a small output buffer; if achieved, the infinite loop will consume CPU and freeze the process, but it does not provide privilege escalation.
OpenCVE Enrichment
Ubuntu USN