LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-58081

freebsd · freebsd

Published
CVSS9.8
Severitycritical
WeaknessCWE-122
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters. An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-58081

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-58081.