Description
Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.

Some SHIFT_JISX0213 sequences decode to two code points. If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call. The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used. The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489.
Published: 2026-09-15
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch ASAP
AI Analysis

Impact

Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in glibc versions 2.3 through 2.44 may result in the converter making no progress, causing the calling application to hang. Some sequences decode to two code points; when the output buffer can hold only the first, the converter stores the second as pending, returns E2BIG, but never clears that pending character. On the next call it repeatedly emits the pending character without consuming more input, looping forever. This behavior can be triggered by attacker‑controlled input with a small output buffer, leading to a denial of service. The issue is identified as a classic infinite‑loop bug (CWE-835).

Affected Systems

The vulnerability affects glibc versions 2.3 through 2.44, which are present in many Linux distributions and other Unix‑like operating systems that ship the library. EPSS score is below 1% and the CVE is not listed in the CISA KEV catalog. The vulnerability is triggered by attacker‑controlled input when an application invokes the SHIFT_JISX0213 conversion routine with a small output buffer, potentially allowing a remote attacker to induce an infinite loop that hangs the application. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate impact, reflecting application‑level denial of service with limited scope. EPSS below 1% suggests exploitation is unlikely, yet it is inferred that the vulnerability could be leveraged via any component that passes unvalidated text to glibc’s iconv for SHIFT_JISX0213 conversion. The CVE is not currently in the CISA KEV catalog, so no widespread exploitation has been documented. Attackers need to supply crafted SHIFT_JISX0213 sequences and ensure the target processes use a small output buffer; if achieved, the infinite loop will consume CPU and freeze the process, but it does not provide privilege escalation.

Generated by OpenCVE AI on September 17, 2026 at 18:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade glibc to a version that includes the fix for SHIFT_JISX0213 conversion (for example, glibc 2.45 or later).
  • If an upgrade is not immediately possible, enforce validation or sanitization of external text before passing it to iconv or other conversion routines to prevent malformed sequences from triggering the loop.
  • Implement resource limits or watchdog mechanisms around text conversion calls so that an infinite loop cannot tie up system resources; for example, set a timeout on iconv calls or run conversion in a separate process with strict CPU limits.

Generated by OpenCVE AI on September 17, 2026 at 18:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8737-1 GNU C Library vulnerabilities
Ubuntu USN Ubuntu USN USN-8737-2 GNU C Library vulnerabilities
History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text. Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang. Some SHIFT_JISX0213 sequences decode to two code points. If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call. The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used. The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489.
Title glibc: Non-progress DoS in SHIFT_JISX0213 -&gt SHIFT_JISX0213 decoding may hang on crafted input
References

Mon, 31 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Gnu
Gnu glibc
Vendors & Products Gnu
Gnu glibc

Tue, 25 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text.
Title glibc: Non-progress DoS in SHIFT_JISX0213 -&gt
Weaknesses CWE-835
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: glibc

Published:

Updated: 2026-09-15T12:26:33.285Z

Reserved: 2026-08-20T12:24:17.417Z

Link: CVE-2026-77117

cve-icon Vulnrichment

Updated: 2026-09-15T12:26:27.547Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T11:17:12.063

Modified: 2026-09-18T18:17:47.257

Link: CVE-2026-77117

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-25T08:36:10Z

Links: CVE-2026-77117 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')