CVE-2026-4046Disclosure(gnu / glibc)

MEDIUMCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch gnu glibc systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-617

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • glibc

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-31); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
glibc

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-31: 1Mentions · 2026-05-02: 1Mentions · 2026-06-20: 1PoC Mentioned / Linked · 2026-06-20: 1Exploit Tool / Code · 2026-06-20: 1Patch / Workaround · 2026-06-20: 1Technical Details · 2026-03-31: 1Technical Details · 2026-05-02: 1Technical Details · 2026-06-20: 103-3105-0206-20
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-311
General1
2026-05-021
Disclosure1
2026-06-201
Disclosure1
Full discourse3 posts
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    🛡️ CVE-2026-4046 no glibc: falha no iconv() permite derrubar aplicações remotamente via IBM1390/1399. Aprenda a verificar, corrigir e mitigar no #SUSE Linux com comandos práticos e script de automação. Saiba mais: -> https://tinyurl.com/2j2a4ruw https://t.co/cqQ0MLc8Mm

    Post summary

    The tweet announces CVE‑2026‑4046, a glibc iconv() flaw causing remote application crashes on IBM1390/1399, and offers verification and mitigation scripts as a response.

    1000053
    1.5K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-4046 impacts glibc in 26 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/486 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new high‑severity CVE (CVE‑2026‑4046) impacting glibc in AWS Lambda base images has been identified, with technical details linked to a GitHub issue.

    0000031
    32 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4046 The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character s… https://www.cve.org/CVERecord?id=CVE-2026-4046

    Post summary

    The entry provides an informational disclosure of a crash vulnerability in iconv() for GNU C Library 2.43 and earlier, with no PoC, exploit, active exploitation, or patch mentioned.

    00000146
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnuglibc---

Explore more