https://seclists.org/oss-sec/2026/q2/14: [libc musl] - Algorithmic complexity DoS in iconv GB18030 decoder
Published Apr 2, 2026
·Updated
Affected Software
1 affected component
musl musl libc>=0.8.0<=1.2.6
Frequently Asked Questions
1
What is the severity of CVE-2026-XXXX?
The severity of CVE-2026-XXXX is classified as a high risk vulnerability.
2
How do I fix CVE-2026-XXXX?
To fix CVE-2026-XXXX, update to the latest version of musl libc that addresses this algorithmic complexity DoS issue.
3
What systems are affected by CVE-2026-XXXX?
CVE-2026-XXXX affects all systems using musl libc's iconv() implementation that includes the GB18030 4-byte decoder.
4
Can CVE-2026-XXXX lead to service downtime?
Yes, CVE-2026-XXXX can lead to service downtime by causing a denial of service through resource exhaustion.
5
Is there a workaround for CVE-2026-XXXX until a fix is applied?
There is no documented workaround for CVE-2026-XXXX, so it is recommended to apply the fix as soon as possible.