Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters.
An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules.
References
| Link | Resource |
|---|---|
| https://security.freebsd.org/advisories/FreeBSD-SA-26:49.iconv.asc | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-19 08:17
Updated : 2026-08-31 19:02
NVD link : CVE-2026-58081
Mitre link : CVE-2026-58081
CVE.ORG link : CVE-2026-58081
JSON object : View
Products Affected
freebsd
- freebsd
CWE
CWE-122
Heap-based Buffer Overflow
