CVE Database
/

CVE-2024-2961

Back to search

CVE-2024-2961

Published: Apr 17, 2024

Modified: May 12, 2026

PUBLISHED

Description

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.

VendorProductVersions

The GNU C Library

glibc

affected
2.1.93 - < 2.40

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now