CVE-2026-80489: EUC_JISX0213 decoding may hang on crafted input

Published Aug 27, 2026
·
Updated

Converting crafted EUCJISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.

Some EUCJISX0213 sequences decode to two code points. If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call. The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUCJISX0213 character set is affected, which is not commonly used. The related defect in SHIFTJISX0213 converter is tracked separately as CVE-2026-77117.

Other sources

EUCJISX0213 decoding may hang on crafted input

— Microsoft

Non-progress DoS in SHIFTJISX0213 -> UCS-4 conversion state <br/> handling (iconvdata/shiftjisx0213.c): crafted input can cause repeated <br/> emission of a buffered code point without further input consumption, <br/> leading to persistent retry churn and denial of service in callers <br/> converting untrusted text.<br/> Requirements to exploit: An attacker must be able to supply text that an <br/> application converts from SHIFTJISX0213 to UCS-4, trigger a 2-byte <br/> sequence that expands through jisx0213toucscombining, and have the <br/> caller retry after E2BIG with the same conversion state once only enough <br/> output space remains for the first of the two emitted code points. <br/> Applications that never use this conversion path, or that abort on repeated <br/> no-progress E2BIG, are not practically exposed.<br/>

— Red Hat

Affected Software

1 affected componentFixes available
debian/glibc<=2.36-9+deb12u14, <=2.36-9+deb12u7, <=2.41-12+deb13u4
2.43-5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/glibc to a version that resolves this vulnerability.

    Fixed in 2.43-5

Event History

Aug 27, 2026
Data Sourced
via Red Hat·08:51 AM
DescriptionSeverityAffected Software
Sep 10, 2026
Data Sourced
via Ubuntu·05:33 PM
RemedyDescriptionSeverityAffected Software
Sep 13, 2026
Data Sourced
via Debian·05:36 PM
DescriptionAffected Software
Sep 15, 2026
CVE Published
via MITRE·10:51 AM
Data Sourced
via MITRE·10:51 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:17 AM
DescriptionSeverityWeakness
Sep 16, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which applications are practically exposed?

Applications are practically exposed only if they convert attacker-controlled text from SHIFT_JISX0213 to UCS-4. They must also retry conversion after E2BIG while retaining the same conversion state.

2

What input and runtime conditions are required to trigger the denial of service?

The input must trigger a two-byte sequence that expands through __jisx0213_to_ucs_combining. After E2BIG, the caller must provide enough output space for only the first of the two emitted code points and retry with the unchanged state.

3

Are applications that use other character conversions affected?

No. Applications that never use the SHIFT_JISX0213-to-UCS-4 conversion path are not practically exposed.

4

What can be done if an update cannot be applied immediately?

Ensure conversion callers detect repeated E2BIG responses with no input progress and abort rather than repeatedly retrying. This prevents the persistent retry churn described by the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203